Skip to main content

Suspend or Archive Google Workspace Users

Google Workspace guide

Choose the appropriate account state for temporary access restrictions or permanent departures, then automate the change with NIM.

Use suspension to temporarily block access while retaining the user's account and existing Workspace license. Use archiving for a departed user whose data must remain available under your retention policy. In NIM, these are separate boolean attributes on the Google user update mapping: suspended and archived.

Compare suspension and archivingDirect link to Compare suspension and archiving

ConsiderationSuspendArchive
Typical purposeTemporary leave, a security incident, or a gap between assignments.Long-term retention after a permanent departure.
User sign-inBlocked.Blocked.
Existing dataRemains associated with the account.Remains associated with the account.
LicensingKeeps the existing Workspace license; suspension does not reduce its billing.Uses Archived User licensing, subject to edition and subscription availability.
New mailAdministrator-suspended accounts cannot receive new mail or calendar invitations.New mail and calendar invitations are blocked.
Returning userClear suspension when access should resume.Unarchive with an available matching Workspace license, then verify suspension and license assignment.

See Google's guidance on suspending users and preserving departed users' data.

A common offboarding sequence is to suspend the account when access must end, complete the data handoff, and archive it when the retention requirements are established. Archiving is a distinct account state; it is not necessary to keep setting both attributes to true.

Before you beginDirect link to Before you begin

  • Configure the Google Workspace connection, test it, and collect the user data.
  • Confirm that the Google connector exposes suspended and archived on the user update function.
  • Identify the authoritative departure or temporary-leave condition and the Google user ID for each person.
  • Confirm Archived User eligibility and available licenses for your edition. Education editions include Archived User licenses; paid editions and billing plans have different purchasing options.
  • Confirm Vault licensing, retention rules, and holds before changing a user whose data must be retained.

Google documents current licensing and account-state behavior in Archive former employee accounts. Archived data counts toward pooled storage, and the active license can become available for reassignment within 24 hours.

Prepare the offboarding handoffDirect link to Prepare the offboarding handoff

Arrange mail routing to an active recipient if the address must continue receiving messages. One approach is to rename the departing account and move its former address to an active user's alias; check for retained aliases and address conflicts before reusing it.

Transfer ownership of actively used Drive files, review calendar events and shared resources, and appoint replacement group owners before removing memberships. Account retention alone does not assign someone to manage that work.

Follow your security procedures for password resets, session sign-out, OAuth token and app-password revocation, managed devices, administrator roles, and group membership removal. Setting suspended or archived is not a replacement for those separate offboarding tasks.

Configure the NIM mappingDirect link to Configure the NIM mapping

1. Create the selection filterDirect link to 1. Create the selection filter

Create a filter that returns only the users eligible for the change. Include the existing Google account's id in its output.

Use separate filters for temporary suspension and permanent archiving. Where appropriate, exclude users already in the desired state. Check that users eligible for restoration cannot also match an offboarding filter.

2. Create a user update mappingDirect link to 2. Create a user update mapping

Go to Output > Mappings and add a mapping. Select your Google system, the users table, and the user update function. Give the mapping a descriptive name and select the filter from step 1.

The system name depends on your configuration; the supplied example uses Google.users/user update. See Create and manage mappings for the complete mapping workflow.

3. Map the Google account IDDirect link to 3. Map the Google account ID

Map the filter's Google account id to the target id attribute. This is required to identify the account to update; do not substitute an employee ID or another source-system identifier.

4. Set the account stateDirect link to 4. Set the account state

tip

Choose one option: suspend OR archive. Do not set both suspended and archived to true in the same mapping.

For the selected attribute, set Source to constant and enter the boolean value true. Leave the other account-state attribute unmapped:

Intended changeTarget attributeConstant value
Temporarily suspend an existing usersuspendedtrue
Archive a departed userarchivedtrue

Leave unrelated attributes unmapped unless they are intentionally part of this update. If your offboarding process suspends a user first and archives them later, use separate mappings for those stages; each mapping sets only its selected account-state attribute.

note

The attribute shown in the mapping is archived, not archive. Select the field exposed by your Google connector.

5. Add the mapping to a jobDirect link to 5. Add the mapping to a job

Create or edit a job, add a crud item, and select the new mapping. Set the operation order and an appropriate threshold, then save.

Collect current source and Google data before evaluating. On the job's Execution tab, select Evaluate and review the accounts and requested attribute changes. Start with one designated test account, verify its result, and then run the approved population.

After validation, use a sync task to schedule collection and execution at the appropriate point in your offboarding process.

Verify the resultDirect link to Verify the result

  1. Review the job results for successful user updates and investigate errors before expanding the population.
  2. Confirm the user's status in the Google Admin console.
  3. Collect Google data again and confirm the relevant suspended or archived value in NIM.
  4. Check mail routing and data handoff independently of the account-state update.
  5. For archived users, verify Archived User licensing and required Vault coverage.

Restore access and review retentionDirect link to Restore access and review retention

To restore a temporarily suspended user, use a separate restoration filter and user update mapping with suspended set to false.

To restore an archived user, first confirm an available matching Workspace license, then set archived to false. Verify the resulting account status: unarchiving returns the account to its previous state, which may be suspended. Clear suspension separately when authorized and confirm the intended license assignment through your licensing workflow.

Review archived accounts periodically against your retention policy. Google permits archived users to be deleted directly; unarchiving first is not required. Deletion removes Workspace data, including data retained by Vault, so retain accounts while applicable holds or retention requirements remain. See Google's Vault preservation guidance.