Skip to main content

Organisation administration · Public

Connect Google Workspace

Link an enterprise tenant to Google, see directory match status on members, and provision accounts when you have manage access.

Google Workspace connection is available for enterprise tenants. It links ONE members with Google directory users so administrators can see whether people exist in the workspace and, when permitted, provision accounts.

Before connecting

You need:

If Google rejects the connection or the signed-in admin belongs to a different domain, ONE records the error on the connection page.

Requirement Notes
Enterprise tenant Google Workspace connection is not available for personal tenants.
Workspace domain ONE suggests the tenant email domain when it has one.
Google administrator Sign in with an admin from the Workspace domain.
Tenant permission connections:google opens the page. connections:google:manage allows sync and provisioning actions.

Connect

Open IAM → Google Workspace. Confirm the domain and choose Sign in with Google. After Google returns to ONE, the first sync runs automatically.

ONE stores the connected admin email, granted scopes, connection status, last sync time, and the last error when one exists.

Sync members

Sync compares tenant members against Google users. A member can match by primary email or by a secondary email saved on their ONE profile.

Use Sync Now after changing a directory outside ONE.

Result Meaning
Matched The member exists in Google Workspace.
Suspended The member exists, but Google marks the account as suspended.
Missing ONE did not find a matching Google user.

Provision from ONE

When the connection is active and the administrator has manage access, member creation and member editing can also create or update the matching Google user. Use this only when ONE should be the place where that person is added.

English