jump to content

Google Workspace SCIM Bridge

Configure the Bridge platform to automatically provide, update and disable platform accounts for Google Workspace users through SCIM synchronization.

Show as Markdown

This guide guides you through setting the Bridge platform to automatically sync users from Google Workspace to the platform via SCIM.

  • Google Workspace administrator access (to create OAuth credentials)
  • the platform organization administrator access
  • A Google Cloud Project with Admin API SDK

Google Workspace Bridge connects to the admin directory API Google using OAuth2, retrieves your organization’s user directory and synchronizes it with the platform via the SCIM endpoint.

  • New usersCreate platform accounts for users found in Google Workspace
  • Updated users: Syncs attribute changes (name, title, department, etc.)
  • Removed usersDisable platform accounts for users who are no longer in Google Workspace
  • Excluded usersSkips users you have explicitly excluded by email

Mapped Attributes

Title: Mapped Attributes
Google Workspace Field SCIM Attribute
Primary email userName, emails
Display name displayName
First name name.givenName
Last name name.familyName
Suspended status active
Job title title
Type of employee userType
Department enterprise:department
Cost center enterprise:costCenter
Employee ID enterprise:employeeNumber
Manager email enterprise:manager
Language preferredLanguage

Step 1: Create Google OAuth Credentials

Step 1: Create Google OAuth Credentials
  1. Mergeţi la Google Cloud Console

  2. Select or create a project for platform integration

  3. Go to APIs & Services > Enabled APIs & Services

  4. Click + Activation ofAPIand services and allow Admin SDK API

  5. Go to APIs & Services > Credentials

  6. Click + Create Credentials > OAuth client ID

  7. Configure the OAuth consent screen if prompted:

    Field Value
    App name Probo SCIM Bridge
    User support email Your admin email
    Scopes https://www.googleapis.com/auth/admin.directory.user.readonly
  8. Crearea ID-ului clientului OAuth:

    Field Value
    Application type Web application
    Name Probo SCIM Bridge
    Authorized redirect URIs https://your-probo-domain.com/api/console/v1/connectors/complete
  9. Save the Client ID and Client Secret

Step 2: Configuring the bridge on the platform

Step 2: Configure the Bridge in the Platform
  1. Log in to the platform as an organization administrator

  2. Go to Organization Settings > Authentication > Auto-Provisioning

  3. Click Add Connector and select Google Workspace

  4. Enter your OAuth credentials:

    Field Value
    Client ID ID-ul clientului Google OAuth
    Client Secret Clientul dvs. Google OAuth Secret
  5. Click Authorize to complete the OAuth stream – you will be redirected to Google to grant access

  6. After authorization, the Bridge connector will appear as Pending

If you have service accounts, shared mailboxes or other users that should not be provided on the platform:

  1. In the Bridge Connector settings, access Excluded Users
  2. Add user email addresses to exclude (insensitive case)
  3. Click Save

Excluded users will be ignored during synchronization.If an excluded user was previously envisaged, it will be removed in the next synchronization cycle.

Step 4: Verify Synchronization

“Step 4: Verify Synchronization”

Once Bridge is set up, it will begin to synchronize in its regular schedule (approximately every 30 seconds for surveys, with a synchronization time of 5 minutes).

  1. Go to Organization Settings > Authentication > Auto-Provisioning
  2. Check the state of the bridge - it should pass from Pending to Syncing Şi apoi la Active
  3. Go to People to verify users have been provisioned
  4. Check the Event Log for detailed sync activity

the platform membership roles (Owner, Adminand so on) are assigned in People or mapped with SAML Role Attribute. SCIM creates people as Employee by default.

Separately, synchronizing a job title and job type helps the platform assign policies and perform meaningful access assessments.Without these profile fields, a user can still register, but it is harder to evaluate for access with the least privileges.

Google Workspace synchronizes two relevant fields with the platform via the SCIM bridge:

  • Job title User position (e.g. Software Engineer, Financial Manager, IT Administrator)
  • Type of employee Their type of employment (e.g. Full-time, Part-time, Internal, Contractor, Freelance)
  1. In the Google Admin console, go to Directory → Users
  2. Select the user you want to update.
  3. Open User information → Employee information
  4. Set the Job title Field to User Position
  5. Set the Type of employee field to their employment type
  6. Click Save
  7. At the next synchronization, both values appear on the user profile on the platform.

Bridge Stuck in “Pending”

Title: Bridge Stuck in “Pending”
  • CauseOAuth authorization has not been completed or the token has expired
  • Solution: Re-authorize the Google Workspace connector by clicking Authorize again

Bridge in “Failed” State

“Bridge in ‘Failed’ State”
  • Cause: A synchronization error occurred (network problem, API rate limit, invalid credentials)
  • Solution: Check the event log for error details. The bridge will automatically resume with exponential downgrading. If the problem persists after 10 consecutive failures, the bridge will be disabled – solve the underlying problem and activate it manually.

Users Not Appearing

“Users Not Appearing”
  • CauseThe Google OAuth application domain may not include directory access or users are in an organizational unit that is not visible to the administrator account
  • SolutionCheck if the admin API SDK is enabled and the OAuth consent screen includes the domain ___ZBT_I18N_RUNTIME_BLOCK_197__

Stale Users Not Deactivated

“Stale Users Not Deactivated”
  • CauseUsers may be in the exclusion list or synchronization has not yet completed a full cycle
  • Solution: Check the exclusion list and wait for the next synchronization cycle. Each synchronization processes up to 500 users per page in Google Workspace.
  • Cause: The refresh token has been revoked or has expired
  • SolutionBridge automatically refreshes OAuth tokens, but if the refresh token itself is revoked (for example, the user has removed access to the app in Google), you will need to re-authorize.

For the best experience, combine SCIM Bridge Provisioning with SAML SSO:

  1. SCIM Bridge user life cycle management – automatic creation and deactivation of accounts
  2. SAML SSO Manages authentication – users log in with Google credentials

This means that users automatically get platform accounts when they join your organization and lose access when they leave, without the need for manual account management.

Ultima actualizare: