domainwidedelegation.comStart free

Use cases → Admin and governance

Standardise user profile photos across the domain

Enforce consistent user profile photos by updating them in bulk via a delegated service account, ensuring uniform branding and compliance.

Who it is forIT administrators responsible for user identity, branding and compliance across a Workspace domain.
APIsAdmin SDK
Typical scopesadmin.directory.user

The problem

Inconsistent user profile photos undermine corporate branding and can introduce compliance risks, especially when users upload personal or inappropriate images. Manually policing or updating photos is error-prone and doesn't scale.

How it works

  1. Prepare the standardised photo assets, ensuring they meet Google's format and size requirements.
  2. Fetch the list of users via the Admin SDK Directory API.
  3. Iterate through each user, updating their photo using the service account with domain-wide delegation.
  4. Log successes and failures for auditing and troubleshooting.

What changes

All users display the approved photo, supporting a consistent brand presence in Gmail, Calendar and Contacts.

The trap in this one. The Admin SDK's photo update endpoint does not invalidate cached images instantly. Users may see their old photo for up to 48 hours in some Google services, even though the API call succeeded. This leads to false reports of failure or confusion among end users and support staff, especially if the process is re-run unnecessarily before caches expire.

Watch it explained

“Google Workspace (G Suite) Custom Attribute Creation | Collaboration Kernel” — Collaboration Kernel on YouTube. Third-party video, included because it covers this ground well. We are not affiliated with the channel.

Questions people ask

How long does it take for updated photos to show everywhere?

Propagation is not immediate. Most Google services update within a few hours, but some caches (notably in Gmail and Contacts) can persist for up to 48 hours.

What happens if a user is suspended or deleted during the update?

The API returns a specific error for suspended or deleted accounts, which should be logged and handled separately to avoid retries or false alarms.

Want this built?

This is a pattern we run in production. We will set up the delegation and build this on top of it — $500 per hour, most of it working the same day.

Talk to us Or read the setup guide

Related use cases

Audit which third-party apps can read your mail

List every OAuth grant across the domain and find the retired tools still holding access.

Automate joiners, movers and leavers

Create accounts, set group membership, provision Drive and hand over mailboxes without a manual checklist.

Continuously verify your delegation still works

A scheduled probe that proves every API still answers under every tenant, before a customer finds out otherwise.