How to Restrict Google Services for Different Teams

How to Restrict Google Services for Different Teams

Not every team in your organization needs access to every Google service. Your sales team probably doesn’t need Google Sites. Your finance team may not need Google Chat. Giving everyone the same access by default is one of the most common mistakes Pakistani businesses make when setting up Google Workspace.

The good news: you can restrict Google services by team using Organizational Units (OUs) and service-level access controls in the Admin Console. No third-party tools required.

This guide shows you exactly how to do it, step by step.

What Are Google Workspace Marketplace Apps?

What Does "Restricting Google Services for Teams" Mean?

In Google Workspace, every service — Gmail, Drive, Meet, Chat, Sites, Chrome sync, and more — can be turned on or off for specific groups of users. This is different from managing third-party app permissions; here, you’re controlling access to Google’s own core apps.

Restricting services means:

  • Turning a service ON for one team and OFF for another
  • Limiting a service to “read-only” or partial access where supported
  • Applying different settings for departments, contractors, interns, or branch offices

This is done through Organizational Units, which act like folders for your users. Each OU can have its own service settings, separate from the rest of the company.

One thing to keep in mind: OUs inherit settings from their parent OU. If you restrict a service at a top-level OU, every child OU underneath it inherits that same restriction unless you specifically override it at the child level. This is why settings sometimes “don’t work as expected” — the change was made at the wrong level of the hierarchy.

Some advanced controls also vary by edition. Features like granular Drive sharing restrictions or Chat data loss prevention are available on Business Plus and Enterprise plans, but may be limited or unavailable on Business Starter.

When Should You Restrict Services by Team?

Restricting services isn’t about limiting productivity — it’s about matching access to actual job needs. Common scenarios in Pakistani organizations include:

  • HR and Finance teams who shouldn’t have Google Sites or Currents enabled, since they handle sensitive data and don’t need public-facing tools
  • Factory or field staff in manufacturing or logistics businesses who only need Gmail and Google Drive, not the full suite
  • Interns and contractors who need Gmail but shouldn’t have access to company-wide Drive sharing or Google Chat
  • Software houses that want engineering teams to use Chat and Meet freely, while keeping marketing on a lighter service set
  • Schools and NGOs that want to give students or volunteers a restricted version of Workspace, separate from staff accounts

If you’ve ever thought “why does this department have access to that?” — this is the fix.

Step-by-Step: Restrict Google Services for a Team

Step 1: Create an Organizational Unit for the Team
  1. Sign in to admin.google.com with a Super Admin account
  2. Go to Directory > Organizational Units
  3. Click the + icon to create a new OU (e.g., “Finance Team” or “Field Staff”)
  4. Choose a parent OU if the team sits under a larger department

If your teams are already organized into OUs, skip to Step 2.

Step 2: Move Users into the Correct OU
  1. Go to Directory > Users
  2. Select the users belonging to that team (you can filter by department if user profiles are set up)
  3. Click More options > Change organizational unit
  4. Choose the OU you created and confirm

Users inherit whatever service settings are applied to their OU, unless a more specific setting overrides it.

Step 3: Restrict Services for That OU
  1. Go to Apps > Google Workspace
  2. You’ll see a list of services: Gmail, Drive and Docs, Meet, Chat, Sites, Groups for Business, and others
  3. Click on the service you want to restrict (for example, Sites)
  4. On the left panel, select the OU you created
  5. Set the service status to OFF or ON, depending on the team’s needs
  6. Click Save

Repeat this for each service you want to control per team.

Google notes that changes can take up to 24 hours to fully apply across all users, though most changes reflect within minutes. Keep this in mind before assuming a setting isn’t working.

Step 4: Apply Additional Access Controls (Optional)

For services that support it, you can go further than ON/OFF:

  • Drive and Docs: Restrict external sharing or link sharing for specific OUs under Apps > Google Workspace > Drive and Docs > Sharing settings
  • Chat: Limit external messaging for certain teams under Apps > Google Workspace > Google Chat
  • Meet: Restrict recording or live streaming permissions per OU

This lets you fine-tune access rather than just switching services fully on or off.

Step 5: Test the Settings

Ask a user from the restricted OU to sign in and confirm the service is hidden or limited as expected.

When to Use Configuration Groups Instead of OUs

Organizational Units work well when your teams map cleanly to a hierarchy. But if you need to apply the same service settings to a specific set of users who sit across different departments — for example, “all team leads” or “everyone on a client project” — creating extra OUs for this gets messy fast.

For these cases, Google Workspace supports configuration groups. Instead of moving users into a new OU, you apply service settings directly to a Google Group. If a user belongs to more than one configuration group, the group with the highest priority (set by you in the Admin Console) determines their settings.

Use configuration groups when:

  • The access rule follows a role or project, not a department
  • You don’t want to restructure your existing OU hierarchy
  • A small number of users across multiple OUs need the same exception

Stick with OU-based restrictions when the access rule matches your actual department structure — it’s simpler to manage long-term.

Best Practices for Restricting Services by Team

  • Start broad, then narrow down. Begin with department-level OUs before creating overly specific sub-groups.
  • Document your OU structure. Keep a simple spreadsheet showing which OU maps to which team and what services are restricted — this saves time during audits or staff changes.
  • Review access every quarter. Teams change. A department that didn’t need Google Chat last year might need it now.
  • Use nested OUs for exceptions. If most of a department is restricted but one person needs an extra service, create a child OU for that person instead of changing the parent OU.
  • Combine with group-based settings for cases where access depends on role rather than department (for example, “Team Leads” across multiple departments).

Common Mistakes to Avoid

  • Restricting services at the top-level OU. This affects your entire domain, not just one team. Always apply changes at the specific team’s OU.
  • Forgetting to move new hires into the correct OU. New users often default to the top-level OU and inherit unrestricted access until manually reassigned.
  • Confusing service restrictions with app permissions. Restricting a Google service (like Drive) is different from managing third-party app access — the two are configured in separate sections of the Admin Console.
  • Restricting Gmail without a transition plan. If you’re removing Gmail access for a team, make sure they have an alternative communication method before switching it off.
  • Not testing before rolling out company-wide. Apply changes to one OU first and confirm everything works before repeating it across other teams.

Common Mistakes to Avoid

If you’ve chosen the allowlist option:

  1. Go to the Marketplace apps section and open the allowlist management screen
  2. Click Add app to allowlist
  3. Search for the app by name or paste its Marketplace URL
  4. Review the permissions it requests (see the scope guidance below)
  5. Approve the app

Once allowlisted, users across the domain (or a selected organizational unit) can install that app without needing individual admin approval each time.

FAQs

Yes. Create a child OU containing just that user, or place them in a small group and apply group-based settings where supported.

No. Turning a service off prevents users in that Organizational Unit from accessing the service. Existing data is typically preserved unless it is removed through separate retention or deletion policies.

OU-based service restrictions are available on all standard Google Workspace editions, including Business Starter, Standard, and Plus. Some granular sharing controls may vary by plan.

Most changes apply within minutes, though Google states it can take up to 24 hours in some cases.

Yes. Since restrictions are tied to OUs, an admin can simply move the user's account or update the OU setting when access needs to change.

Summary

Restricting Google services by team keeps your Workspace organized, secure, and aligned with how your business actually operates. Using Organizational Units, you can control exactly which services each department, branch, or role has access to — without affecting the rest of your domain.

Start by mapping out your teams, group them into OUs, and apply service restrictions one department at a time. Review the setup periodically as your organization grows.

AF

Asher Feroze
Author | CreativeON Team
I’ve worked in various roles at CreativeON, including Manager Operations, Manager Marketing, and Level 2 Client Support. These days, I focus on helping people like you understand our products — whether it’s Domains, Dedicated Servers, VPS, Cloud Hosting, or Google Workspace — in simple, practical language.
Making Tech Simple for Businesses