# Cis Gworkspace 4.1.2.2

> Ensure User account recovery is enabled

- Skill: `cyberstrikeus/cis-gworkspace-4-1-2-2` (Agent Skill)
- Install (CLI): `npx skillmds@latest add cyberstrikeus/cis-gworkspace-4-1-2-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/cyberstrikeus/cis-gworkspace-4-1-2-2/raw
- Safety review: PASS (external: skill-scanner PASS, skillspector PASS)
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: cyberstrikeus (https://skillmd.com/u/cyberstrikeus)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/cyberstrikeus/cis-gworkspace-4-1-2-2

---


# 4.1.2.2 Ensure User account recovery is enabled

## Profile Applicability

- Enterprise Level 1

## Description

This option allows non-Super Admin users to recover access to their accounts if their password has been forgotten.

The option is not available if either _Single Sign On_ or _Password Sync_ is in use.

## Rationale

Allowing users to recover access to their accounts when they have forgotten their passwords reduces the number of support tickets generated by users, and reduces the amount of down time spent waiting on the account recovery process to initiate and complete.

## Impact

The potential impact to users being allowed to recover their accounts includes:

1. The user is now empowered to reset their passwords.
2. The user will no longer need to call a helpdesk or open a support ticket to regain access to their account.

An organization that allows users to recover their account will realize less time spent by administrative staff working on these tasks.

## Audit

To verify this setting via the Google Workspace Admin Console:

1. Log in to `https://admin.google.com` as an administrator.
2. Select `Security`.
3. Select `User account recovery`
4. Verify `Allow users and non-super admins to recover their account` is checked.

## Remediation

To configure this setting via the Google Workspace Admin Console:

1. Log in to `https://admin.google.com` as an administrator.
2. Select `Security`.
3. Select `User account recovery`
4. Select either the pencil icon or the setting itself.
5. Set `Allow users and non-super admins to recover their account` to checked.
6. Select `Save`.

## Default Value

`Allow users and non-super admins to recover their account` is `OFF`

