These users have complete management of the entire domain. Note that any Super Admin also has access to access Google Vault reports, so it's important that this role is not administered freely.
This is particularly useful if you have a few users who you would like to create and manage Groups on your domain.
This role allows management of individual users such as resetting passwords, security settings and also deleting or suspending users.
This role allows the resetting of users passwords. You can give permissions to just manage individual organisation units, so it's often a good idea to give staff the 'User Management' privileges just for the Student organisation unit.
This role allows a user to manage all of the Device management settings.
If you are working in a team of IT/Network Managers we recommend that you create a role called 'Super(ish) Admin' and enable all privileges except for Google Vault. This enable anyone assigned to that role to have full access to manage the Admin console, but can't access users emails and Drive files through Vault.