Patronum Logo
00%
Patronum Logo
menu-icon

Google Workspace User Onboarding: A Step-by-Step Guide

By Patronum

July 15, 2026

Read Time: 6 mins

To onboard a new user in Google Workspace, create their account in the Admin console, assign a license, place them in the right organizational unit so they inherit the correct settings, add them to the groups they need, and make sure 2-Step Verification applies to them. Handled deliberately, the person can sign in on day one with the right access and far less risk of over-provisioning. Here is each step.

Onboarding is really provisioning plus placement. Creating the account is the easy part. The part that saves you trouble later is putting the person in the right organizational unit and groups, because that is what decides which services, settings, and files they get. Get placement right and access is correct by default instead of patched together afterward.

The onboarding checklist

Copy this block into your ticketing system or a shared doc, assign the owner, and require a checkmark before a new hire is marked ready.

StepOwnerDone
Confirm role and manager approvalHR / Manager
Create accountIT
Assign licenseIT
Place in correct OUIT
Add required groupsIT / Manager
Add shared drives and calendarsIT
Confirm 2SV enrollmentIT / Security
Record approved third-party appsIT / Security
Enroll or confirm devicesIT
Confirm first loginManager / IT

Before you start

Confirm the new hire’s role, manager, department, start date, and approved access profile before provisioning anything. This prevents over-provisioning and gives you a documented starting point for the whole access lifecycle. Provision each person their own account: avoid shared accounts, which cannot be attributed to an individual and are hard to offboard cleanly. Also confirm an available license or automatic licensing rule before creating the account, especially on annual plans, since adding a user can increase billing on flexible plans.

1. Create the user account

In the Admin console, go to Directory, then Users, and add the new person. You can add one user at a time, add many at once from a spreadsheet, or provision automatically from an external directory, depending on your setup (Google Admin Help, “Options for adding users”). Give them a standard username format so accounts stay consistent. Create accounts before the first day where possible, because a new user can sign in right away but some Workspace services can take up to 24 hours to become fully available (Google Admin Help, “Add an account for a new user”).

[SCREENSHOT: Admin console > Directory > Users > “Add new user” dialog – SOURCE: Google Admin UI (we capture)]

2. Assign a license

A user needs a Google Workspace license to use the services. You can assign licenses manually, use automatic licensing for organizational units so anyone placed in a unit gets a license without a manual step, and, where your setup supports it, manage licensing through groups (Google Admin Help, “Assign licenses”; automatic licensing). Automatic licensing is the setting that makes onboarding scale.

3. Place them in the right organizational unit

Every user belongs to an organizational unit, and that unit determines which features and settings apply to them (Google Admin Help, “How the organizational structure works”). Put a new hire in the unit for their department or role, such as Sales or Finance, so they inherit the correct policies instead of the top-level defaults. You can move a user into a child unit at any time (Google Admin Help).

[SCREENSHOT: Admin console org tree with a user being moved into a department OU – SOURCE: Google Admin UI (we capture)]

4. Add them to the right groups

Groups are how you grant shared access cleanly. As a Groups administrator you can create groups for departments and teams and add the new user to the ones they need (Google Admin Help, “Create a group”). Adding someone to a group is far easier to track and undo later than sharing dozens of files with them individually, which matters when they eventually leave. One caveat: use Admin console groups for access and configuration decisions, not only ad hoc email lists, because only groups created in the Admin console can be used as configuration groups (Google Admin Help).

Start with the minimum groups required for the role, then add project-specific access only when approved. A simple way to keep access clean is to map each kind of access to a source rather than granting it ad hoc:

Role typeAccess source
Department accessDepartment group
Project accessProject group or shared drive membership
Admin privilegesSeparate approved admin role
App accessApproved app group or policy
Shared filesShared drive, not individual My Drive sharing

5. Make sure 2-Step Verification applies

Security should be on from day one. In the Admin console, go to Security, then Authentication, then 2-Step Verification to confirm enforcement covers the new user’s organizational unit. You can set a new-user enrollment period, from one day up to six months, so people have time to enroll a second factor before enforcement applies (Google Admin Help, “Deploy 2-Step Verification”). You must be a super administrator to change this.

6. Add apps, devices, and hand over the basics

  • Record approved third-party app access, including who approved it and what data scopes the app needs, so it can be reviewed during role changes and revoked during offboarding.
  • Enroll managed devices, or confirm your BYOD requirements, before the user starts handling company data.
  • Share the sign-in details securely and require a password change at first login.
  • Add the person to the shared drives, calendars, and distribution lists their role needs.
  • Point them to the internal resources and apps they will use.

7. Confirm first login

Onboarding is not done until the person can actually sign in and reach what they need. Confirm a successful first login and that their core apps, drives, and groups are accessible, remembering that some services can take up to 24 hours to appear (Google Admin Help).

Where onboarding goes wrong

  • Skipping the org unit. New hires land in the top-level unit and get the wrong settings, then someone fixes it by hand later.
  • Sharing files individually instead of via groups. It works today and becomes an untraceable mess at offboarding.
  • Leaving security for later. If 2-Step Verification is not enforced from the start, the gap can persist for weeks.

Onboarding and offboarding are two ends of the same job

Every access you grant on day one is something you will need to remove on the last day. The cleaner the onboarding, the cleaner the exit. Patronum automates Google Workspace onboarding and offboarding as consistent policies, so new hires get exactly the access their role needs and leavers have it all removed in the right order. For the exit side, see our Google Workspace offboarding guide.

The middle of that lifecycle matters too. When someone changes role, treat it as a mini offboarding and onboarding: remove old-role groups, shared drives, app access, and admin roles before adding the new ones. Skipping the removal half is how people accumulate access far beyond their current job.

FAQ

How do I add a new user in Google Workspace?
In the Admin console, go to Directory, then Users, and add the user individually, in bulk from a spreadsheet, or through automated provisioning (Google Admin Help).

Do I have to assign a license manually to every new user?
No. You can turn on automatic licensing for an organizational unit so anyone placed there is licensed automatically (Google Admin Help).

Why does the organizational unit matter for a new hire?
The organizational unit determines which features and settings apply to the user, so placing them correctly gives them the right access by default (Google Admin Help).

Should I add new users to groups or share files with them directly?
Use groups. Group membership is easier to grant, track, and remove later than individually shared files (Google Admin Help).

How do I make sure new users have 2-Step Verification?
Confirm enforcement covers their organizational unit under Security, then Authentication, then 2-Step Verification, and set a new-user enrollment period so they can enroll before it applies (Google Admin Help).

How early should I create a new Google Workspace user?
Create the account before the first day where possible. The user can sign in right away, but some services may take up to 24 hours to become available (Google Admin Help).

Should third-party app access be part of onboarding?
Yes. Record approved apps during onboarding, including who approved them and what data scopes they need, so they can be reviewed during role changes and revoked during offboarding.

What should IT do when someone changes role?
Treat it as a mini offboarding and onboarding: remove old-role groups, shared drives, app access, and admin roles before adding the new role’s access. This keeps access matched to the current job instead of accumulating over time.

Onboard new hires in minutes, not tickets

Manual onboarding is repetitive and easy to get half-right. See how Patronum automates Google Workspace onboarding so every new hire gets the right license, org unit, groups, and security from day one.

Sources

  • Google Admin Help, “Options for adding users”: https://support.google.com/a/answer/179832
  • Google Admin Help, “Add an account for a new user”: https://support.google.com/a/answer/33310
  • Google Admin Help, “Assign, remove, and reassign licenses”: https://support.google.com/a/answer/1727173
  • Google Admin Help, “Set automatic licensing for organizational units”: https://support.google.com/a/answer/7610656
  • Google Admin Help, “How the organizational structure works”: https://support.google.com/a/answer/4352075
  • Google Admin Help, “Move users to an organizational unit”: https://support.google.com/a/answer/182449
  • Google Admin Help, “Create a group in your organization”: https://support.google.com/a/answer/9400082
  • Google Admin Help, “Deploy 2-Step Verification”: https://support.google.com/a/answer/9176657