Skip to content
RansomwareBackup
recovery google workspace

How to restore a deleted Google Workspace user

A deleted Google Workspace user is restorable for 20 days from the Admin console. Here is exactly what returns, what quietly does not, and what to have in place before day 21.

If you deleted a Google Workspace user by mistake, you have 20 days to restore them from the Admin console — mail, files, calendar and settings return with the account. Past that window, Google no longer holds the data, and recovery becomes a data-reconstruction problem rather than a click.

This post covers exactly what's recoverable inside the 20-day window, the step-by-step restore, what quietly disappears even inside that window, and what to have in place so day 21 isn't a crisis.

The 20-day window (Google's built-in recovery)

When you delete a user in Google Workspace, the account isn't erased immediately. Google keeps it in a suspended state for 20 days. During that window an admin with the right role (User Management Admin or Super Admin) can restore the account from the Admin console in a single flow:

  • Mailbox contents (Gmail messages, labels, filters) come back.
  • Files the user owned in My Drive come back into their My Drive.
  • Calendar events they owned come back on their calendar.
  • Groups, licences and profile settings are restored to the state at deletion.

What's tricky is what Google doesn't put back on restore:

  • Files the user had shared — the sharing links, permission grants, and any comments others left after the deletion aren't reconstructed.
  • Content in Shared Drives — those don't get deleted when a user goes, because they're not owned by users. But if you deleted their contributions expecting the Shared Drive to hold them, verify: some file types can behave differently.
  • Aliases and delegations — the delegated-access relationships often need to be re-added by the delegate.
  • App-specific data — third-party Marketplace app data (Zoom recordings, Slack integrations, and similar) rarely survives a delete/restore round-trip.

Assume "restored" doesn't mean "identical". Have someone from the team the user reported to sanity-check their inbox and Drive folders before you close the ticket.

Step-by-step: restore in the Admin console

  1. Sign in to admin.google.com as a Super Admin or User Management Admin.
  2. Menu → DirectoryUsers.
  3. Above the user list, click the filter icon and select Recently deleted.
  4. Locate the user (searchable by name or email).
  5. Click the user, then Recover user.
  6. Choose the organisational unit to place them into (the pre-fill defaults to their previous OU — check it, especially if you restructured after the deletion).
  7. Confirm.

The account returns to active immediately. Login, mailbox and Drive access are back within minutes; some downstream systems (SSO providers, provisioning tools) can take longer to catch up.

Past the 20-day window: restoring deleted Google Workspace users the hard way

Once 20 days pass, Google no longer holds the account or its data. You have three options — none of them are the one-click flow above:

  • Google Vault (if you were licensed and had a matter or hold in place before the deletion). Vault retains a copy of Gmail and Drive under active retention policies. You can search, export, and hand the data back to a re-created user. This requires that Vault was licensed and configured before the deletion — turning it on now doesn't retroactively help.
  • Backups outside Google. If you had a third-party SaaS backup running against Google Workspace, restore from the last snapshot before the deletion. Point-in-time recovery is exactly the case backup software is built for.
  • Reconstruction from what others still have. For Gmail, mail sent to the deleted user might still be in the sender's Sent folder. For Drive, files shared out of My Drive were duplicated only if collaborators had copies made. This route is manual and rarely complete.

If none of these apply, the data is gone. This is the moment operators typically discover the shared-responsibility model in practice: Google runs the platform, but the data lifecycle — including the "we deleted someone and now we need them back" case — is a customer problem.

What "prevention" actually looks like

You cannot prevent an admin from deleting the wrong user. What you can do is compress the blast radius:

  • Suspend before you delete. For any departure that isn't clearly permanent, suspend the account. Suspended accounts keep their data indefinitely (as long as you hold a licence for them or convert to Cloud Identity). Delete only after a defined grace period has passed.
  • Turn Vault on before you need it. Vault is only useful for events after its policies were configured. Even a permissive default retention policy is better than none.
  • Run a third-party backup. A backup catching Google Workspace daily gives you a restore point that isn't bounded by Google's 20-day clock and doesn't depend on whether Vault was set up correctly at the moment of deletion. See our Google Workspace platform overview for the specifics of how that's structured — and the SaaS shared responsibility model for why "Google keeps us safe" is a misreading of the contract.
  • Log every admin action. Google's admin audit log makes it easy to identify when a delete happened and who did it — the input every recovery path needs. Retain the log beyond Google's defaults.

If you're inside the 20 days: act now

The window doesn't warn you before it closes. If a user was deleted in the last three weeks, restore them today. If the restore lands you in a "some data doesn't look right" conversation, that's your signal to fix the next deletion before it happens.

If day 21 is where you're reading this from, the recovery path depends entirely on what infrastructure you had in place before the deletion. If none of it — Vault, third-party backup — was set up, book a 20-minute assessment and we'll walk you through what your realistic options are, including whether reconstruction from downstream systems is worth the effort in your case.