The Admin Console controls every user, security policy, and app setting across a Workspace account. For someone new to it, the sheer number of menus can make it hard to know where to even start.

The sections that matter most early on

Directory (where users, groups, and organizational units live), Apps (where Gmail, Drive, and other service settings are configured), and Security (where 2-Step Verification and login policies live) cover the majority of day-to-day admin tasks. Everything else can generally wait until a specific need comes up.

Organizational units versus groups

These are commonly confused. An organizational unit determines which policies apply to a user and each user belongs to exactly one. A group is for distributing mail or managing access to a resource, and a user can belong to many groups at once. Getting this distinction right early avoids having to restructure things later.

Before changing a security setting

Security policy changes in the Admin Console can apply instantly and organization-wide. Before changing a policy that affects login or access, it is worth confirming exactly who it will apply to — the whole domain, or a specific organizational unit — to avoid an unplanned lockout.