certslothcertsloth
← AGWA overview

Associate Google Workspace Administrator / STUDY TOOLS

Associate Google Workspace Administrator — Quick review

Reviewed 10 October 2026. Use the linked official exam guide for your exam version. These are condensed revision notes; the topic pages provide worked distinctions and more recall practice. Google’s 2026 guides use newer Gemini Enterprise Agent Platform names while some APIs and documentation still use Vertex AI.

Memory hook: Identity → services → data rules → security → endpoints → evidence.

Version caveat: Workspace controls depend on edition, license, platform and rollout. The exam’s approximate domain weights total 101% because of rounding; do not reinterpret that as another domain.

1. Users, directory and domains — 1.1–1.5

  • A user belongs to one OU and many groups. OUs provide inherited settings; supported configuration groups provide targeted overrides. Distribution groups deliver mail, Collaborative Inbox adds assignment, security groups control supported access, dynamic groups follow attributes.
  • Directory Sync/GCDS synchronize selected identity data; SAML SSO delegates authentication. Provisioning and sign-in are separate workflows. A third-party IdP working correctly does not prove a user has been created or licensed.
  • A user alias is another address for the same identity; a secondary domain can host distinct users; a domain alias gives corresponding alternate addresses. Verify DNS ownership before activation. Avoid creating a second account merely to supply an alternate email address.
  • Offboarding sequence: check legal holds/retention and license needs → preserve/transfer owned data → suspend/revoke access → manage devices → archive/delete only under the required retention plan. Suspension, deletion, restoration and Archived User licensing have different effects.
  • Rooms/equipment are bookable resources with building, capacity/features and calendar permissions. Delegated admin roles should match the help-desk task rather than give Super Admin.

2. Gmail and collaboration — 2.1–2.7

MX routes inbound mail; SPF authorizes sender infrastructure; DKIM signs mail; DMARC tests aligned SPF or DKIM and publishes handling/reporting policy. Header evidence explains failures. Routing, compliance rules, quarantine, spam controls, forwarding and POP/IMAP each operate at different points. Delegate a mailbox rather than share credentials.

My Drive ownership follows the individual; shared-drive content belongs to the organization’s shared context. Configure external sharing, target audiences, storage quotas, labels, desktop sync and offline access separately. Calendar free/busy is less revealing than event detail; resource booking and delegated management are separate privileges. Account for event ownership and time zones during migration.

Meet access/safety, recordings, transcripts and note-taking need supported licensing and settings. Chat history, external spaces, invitations, moderation and apps affect governance. Enable Gemini and extensions for the appropriate population and examine usage reports/data terms. AppSheet builds low-code apps; Apps Script automates Workspace operations with granted scopes and accountable owners.

3. Governance and discovery — 3.1–3.5

Vault retention defines lifecycle; legal holds preserve scoped evidence; matters, search and export support discovery. Vault is not an operational backup. Do not remove required licenses or delete custodians assuming a hold will preserve everything regardless of account state.

DLP detects content and applies supported Gmail/Drive/Chat actions; capability differs by service/edition. Pilot detector matches and notifications before blocking. Trust rules define permitted sharing relationships; classification labels describe data and can feed policy. A label by itself is not every enforcement control.

Takeout enables user export; administrator Data Export supports organizational export. Data regions concern supported data location, not a blanket promise about every processing path or downloaded copy. Protect exports and audit discovery access.

4. Security and application access — 4.1–4.3

Enforce strong authentication with staged enrollment and protected recovery; prefer phishing-resistant methods where supported. Context-aware access can deny an otherwise valid login because the device/network context fails. Keep monitored emergency administration available and separate from routine work.

Marketplace/Play app availability, SSO, OAuth scopes and access to additional Google services are separate controls. An allowlisted application can still need scope review. Removing a listing does not necessarily revoke old tokens. Use session controls, token revocation and device actions as the incident requires. Security health identifies weak configuration; audit/investigation logs show activity; activity rules alert on selected events.

5. Browsers and endpoints — 5.1–5.2

Choose basic, advanced or third-party management by ownership, platform and control needs. Inventory company and BYOD devices; verify enrollment and policy sync. An account wipe removes supported work data; a device wipe can remove personal data too. Manage Chrome enrollment, user/browser policy targeting, extension allow/block/force-install and timely updates. Installing Chrome is not enrollment.

6. Diagnose and report — 6.1–6.4

Use scope → status → recent changes → logs → reproduce. Missing mail: Email Log Search, headers, Admin Toolbox DNS, routing/quarantine/user rules. Failed access: account/license/service/SSO/2SV/context policy. Missing Drive content: ownership, membership, sharing and sync. Bad Meet calls: Meet quality tool, device and network evidence. Monitor usage/storage/device reports and service-specific deletion recovery windows.

Support evidence includes impact, timestamps/time zone, affected IDs, reproduction and sanitized logs. HAR captures can include credentials and personal information. Check status, known issues and release updates before broad tenant changes.

Traps to catch

  • An alias is not a second mailbox; authentication is not provisioning.
  • A legal hold is not a user restore feature; an account wipe is not a full wipe.
  • SPF pass without alignment does not alone prove DMARC pass.

Last-pass self-check

1. How give a department durable ownership of shared files?

Use an appropriately governed shared drive rather than depending on one employee’s My Drive ownership.

2. What should happen before deleting a departing user under litigation?

Confirm holds, licensing and retention, preserve/transfer required content, then follow authorized offboarding.

3. An app is allowlisted but requests broad Drive access. Is approval complete?

No. Review OAuth scopes and applicable application-access controls separately.

4. One user misses mail. What is the first useful evidence?

Email Log Search and headers/routing context, before changing global settings.

5. A personal phone needs offboarding. Which distinction matters?

Account/work-data removal versus a full device wipe; choose the supported action appropriate to ownership and policy.

Sources

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · Directory and account lifecycle

Memory hook: An OU sets policy; a group gathers people.

Must remember

  • An organizational unit provides a hierarchy for inherited settings; groups collect members for communication, access and supported policy targeting. A user has one OU placement but can belong to many groups.
  • Provision manually, in bulk or through supported directory synchronization. GCDS/Directory Sync synchronize selected directory data; SAML SSO delegates authentication and is not itself complete account provisioning.
  • An alias gives an existing user another address; a secondary domain can contain separate users. Verify domain ownership before enabling it and plan primary-domain changes carefully.
  • Suspension blocks access while retaining the account; deletion has recovery limits; an Archived User license can retain supported former-user data. Transfer Drive ownership and address legal holds before offboarding.
  • Manage licenses, password resets, recovery settings, attributes and aliases as distinct tasks. Use staged changes and least-privileged delegated administrator roles.
  • Distribution groups deliver mail; Collaborative Inbox adds assignment/work handling; dynamic groups derive membership from attributes. Resource calendars represent rooms or equipment with buildings, features, capacity and booking permissions.

Review details

Security groups identify groups intended for access-control use; they differ from a simple mail distribution decision. Configuration groups can override supported settings for a subset of people without moving everyone into another OU, but group precedence and supported settings must be checked. A domain alias supplies alternate addresses for existing identities; a secondary domain permits distinct identities.

For migration, distinguish account provisioning from historical data migration. Importing old mail does not configure MX, enable service access or grant a license. For offboarding, verify the required legal preservation and destination ownership before taking away the license or deleting the account.

Choose under exam pressure

Requirement Choice and reason
A team needs policy exceptions Use a supported group override or a deliberate OU design.
An employee leaves during litigation Preserve required data and holds before suspension, archival or deletion.

Traps

  • Deleting an account is not a harmless way to remove a license.
  • An email alias is not a separately licensed mailbox or identity.

Practise this topic

02 · Gmail and collaboration settings

Memory hook: Route mail; scope sharing; preserve ownership.

Must remember

  • MX records direct inbound mail. SPF authorizes sending sources; DKIM signs messages; DMARC checks alignment and tells receivers how to handle failures. Start enforcement with visibility into legitimate senders.
  • Gmail routing, compliance rules, quarantine, attachment restrictions, forwarding and POP/IMAP settings solve different needs. Delegation grants mailbox access without sharing a password; migration tools move historical mail.
  • My Drive content is typically individually owned; shared drives provide team ownership. Configure external sharing, target audiences, labels, storage limits, templates, offline access and Drive for desktop according to policy.
  • Calendar sharing distinguishes free/busy visibility from event detail and management permissions. Review resource booking, delegation, unknown invitations and event ownership during personnel changes.
  • Meet access, recording, transcripts, note taking and media settings depend on edition and policy. Chat history, external spaces, invitations, apps and moderation also affect governance.
  • Test settings with a representative OU/group before applying them widely. A service enabled at organization level may still be unavailable because of licensing, user settings or more specific policy.

Choose under exam pressure

Requirement Choice and reason
Mail reaches the wrong provider Check MX and routing before changing a user password.
Files must remain with a department after staff changes A shared drive with appropriate membership.

Traps

  • SPF passing alone does not prove DMARC alignment.
  • Disabling external links does not retroactively erase every copy already exported.

Practise this topic

03 · Vault, DLP and safe AI use

Memory hook: Retain evidence; restrict leakage; label meaning.

Must remember

  • Vault supports retention, legal holds, search and export for supported services and editions. A hold preserves relevant data for a matter; retention rules govern its ordinary lifecycle. Vault is not a general operational backup service.
  • Do not delete accounts or remove required licensing while relying on retained data without checking the consequences. Validate scope, dates, custodians, export location and audit records.
  • DLP detects sensitive content using built-in detectors or custom patterns and applies supported actions. Start with audit or test rules, assess false positives, then enforce narrowly.
  • Drive trust rules control permitted sharing relationships; labels classify content and can feed policy. Classification alone does not enforce every sharing restriction.
  • Data regions address supported data placement; Takeout and administrator Data Export address different export needs. Export access, processing location and retention still need governance.
  • Enable Gemini, extensions and other AI features for appropriate users and editions, review enterprise data terms and monitor usage. AppSheet builds low-code apps; Apps Script automates Workspace tasks; both need scoped permissions and ownership.

Review details

A Vault matter organizes an investigation; a hold targets relevant custodians/data, and search/export produces evidence. Holds take precedence over ordinary retention expiry for covered data under supported account/licensing conditions. They do not let a user restore deleted mail as if Vault were a backup product.

DLP in Gmail, Drive and Chat has service/edition-specific detection and actions. Test a rule against expected allowed and blocked cases, configure understandable notifications, and monitor false positives. Classification may be user-applied, default, automated DLP-driven or supported AI classification; a label can feed enforcement but does not replace a sharing policy on its own.

Choose under exam pressure

Requirement Choice and reason
Preserve records for litigation Vault hold on the required supported data, with correct licensing.
Prevent card numbers leaving through supported channels Tested DLP rules and a clear user notification.

Traps

  • A legal hold is not the same as a user-visible restore mechanism.
  • Labels and data-region settings do not replace access control.

Practise this topic

04 · Secure identities and applications

Memory hook: Strong login, narrow admin, visible changes.

Must remember

  • Enforce strong authentication and recovery policies; prefer phishing-resistant methods such as security keys/passkeys where supported. Plan enrollment and emergency administrator recovery before enforcement.
  • Context-aware access evaluates signals such as device posture and access context. A correct password can still be insufficient when a policy condition is unmet.
  • Assign prebuilt or custom admin roles to specific duties. Reserve Super Admin for necessary work and keep emergency access monitored and protected.
  • Use audit/investigation tools, security center views, health recommendations and activity rules to identify suspicious logins, sharing and administrative changes. Correlate timestamps and users before acting.
  • SSO integration, Marketplace allowlisting and OAuth app access are separate controls. Review requested scopes, restrict high-risk applications and revoke obsolete connected-app access.
  • Session controls and forced sign-out can reduce continuing access, but incident response may also require token revocation, password changes and device actions.

Choose under exam pressure

Requirement Choice and reason
A help desk only resets passwords A delegated user-management role scoped to its responsibility.
A third-party app requests broad Drive access Review OAuth scopes and application controls before approval.

Traps

  • Two-step verification is not identical to phishing resistance.
  • Disabling an app in one catalogue may not revoke every existing token.

Practise this topic

05 · Manage browsers and devices

Memory hook: Enroll, enforce, inventory, offboard.

Must remember

  • Basic mobile management provides lighter controls; advanced management adds supported device and application controls. Choose according to ownership, platform, edition and compliance requirements.
  • Distinguish company-owned devices from BYOD. An account wipe removes managed organizational data where supported; a full device wipe has much broader impact.
  • Inventory registered devices, inspect sync/activity and respond to loss or departure through a documented offboarding process. Removing a directory account is not a substitute for all device actions.
  • Enroll Chrome browsers into management and apply policies through the intended OU/group. Separate user policy from browser/device policy when diagnosing precedence.
  • Allow, block or force-install extensions based on business need and permissions. Manage update cadence and offline capabilities without leaving browsers permanently unpatched.
  • Verify policy application on the actual endpoint. A configured policy is only useful if the device is enrolled, in scope and communicating.

Choose under exam pressure

Requirement Choice and reason
Personal phone used for work Prefer targeted work-account removal when supported and sufficient.
Mandatory approved Chrome extension Managed browser enrollment and a scoped force-install policy.

Traps

  • A full wipe can remove personal data; check ownership and supported action semantics.
  • Installing Chrome does not automatically enroll it for enterprise management.

Practise this topic

06 · Troubleshoot with evidence

Memory hook: Scope, status, logs, reproduce.

Must remember

  • First determine who, what, when and where is affected. Check the Workspace Status Dashboard before making local changes during a service incident.
  • For missing mail, trace delivery with Email Log Search and inspect headers, routing, quarantine, spam rules and user forwarding. Admin Toolbox can help inspect DNS and message authentication.
  • For access failures, separate account status, license, service enablement, password/2SV, SSO and context-aware policy. Avoid resetting unrelated controls until the failing layer is known.
  • For Drive, inspect owner, shared-drive membership, external-sharing rules, storage and desktop/offline sync. For Calendar, inspect time zones, synchronization and free/busy versus detailed permissions.
  • Use the Meet quality tool to correlate poor calls with network, device and media conditions. Review audit, usage, storage and device reports for wider patterns.
  • Record reproduction steps, exact time/time zone, affected users, error codes and relevant sanitized logs. HAR files may contain tokens or personal information; redact them before sharing with support. Recovery of deleted content has service-specific windows.

Choose under exam pressure

Requirement Choice and reason
One user cannot receive a message Trace the message before changing organization-wide mail routing.
All users suddenly fail in one service Check service health and recent tenant-wide changes.

Traps

  • A screenshot alone rarely provides enough timing and trace context.
  • HAR files are not automatically safe to post publicly.

Practise this topic

Search across every published topic.