Google Workspace SCIM Bridge
Configure the Bridge platform to automatically provide, update and disable platform accounts for Google Workspace users through SCIM synchronization.
This guide guides you through setting the Bridge platform to automatically sync users from Google Workspace to the platform via SCIM.
Prerequisites
Section entitled ‘Prerequisites’- Google Workspace administrator access (to create OAuth credentials)
- the platform organization administrator access
- A Google Cloud Project with Admin API SDK
How It Works
Posts Tagged ‘how it works’Google Workspace Bridge connects to the admin directory API Google using OAuth2, retrieves your organization’s user directory and synchronizes it with the platform via the SCIM endpoint.
- New usersCreate platform accounts for users found in Google Workspace
- Updated users: Syncs attribute changes (name, title, department, etc.)
- Removed usersDisable platform accounts for users who are no longer in Google Workspace
- Excluded usersSkips users you have explicitly excluded by email
Mapped Attributes
Title: Mapped Attributes| Google Workspace Field | SCIM Attribute |
|---|---|
| Primary email | userName, emails |
| Display name | displayName |
| First name | name.givenName |
| Last name | name.familyName |
| Suspended status | active |
| Job title | title |
| Type of employee | userType |
| Department | enterprise:department |
| Cost center | enterprise:costCenter |
| Employee ID | enterprise:employeeNumber |
| Manager email | enterprise:manager |
| Language | preferredLanguage |
Step 1: Create Google OAuth Credentials
Step 1: Create Google OAuth Credentials-
Mergeţi la Google Cloud Console
-
Select or create a project for platform integration
-
Go to APIs & Services > Enabled APIs & Services
-
Click + Activation ofAPIand services and allow Admin SDK API
-
Go to APIs & Services > Credentials
-
Click + Create Credentials > OAuth client ID
-
Configure the OAuth consent screen if prompted:
Field Value App name Probo SCIM BridgeUser support email Your admin email Scopes https://www.googleapis.com/auth/admin.directory.user.readonly -
Crearea ID-ului clientului OAuth:
Field Value Application type Web applicationName Probo SCIM BridgeAuthorized redirect URIs https://your-probo-domain.com/api/console/v1/connectors/complete -
Save the Client ID and Client Secret
Step 2: Configuring the bridge on the platform
Step 2: Configure the Bridge in the Platform-
Log in to the platform as an organization administrator
-
Go to Organization Settings > Authentication > Auto-Provisioning
-
Click Add Connector and select Google Workspace
-
Enter your OAuth credentials:
Field Value Client ID ID-ul clientului Google OAuth Client Secret Clientul dvs. Google OAuth Secret -
Click Authorize to complete the OAuth stream – you will be redirected to Google to grant access
-
After authorization, the Bridge connector will appear as Pending
Step 3: Configure Exclusions (Optional)
Section titled “Step 3: Configure Exclusions (Optional)”If you have service accounts, shared mailboxes or other users that should not be provided on the platform:
- In the Bridge Connector settings, access Excluded Users
- Add user email addresses to exclude (insensitive case)
- Click Save
Excluded users will be ignored during synchronization.If an excluded user was previously envisaged, it will be removed in the next synchronization cycle.
Step 4: Verify Synchronization
“Step 4: Verify Synchronization”Once Bridge is set up, it will begin to synchronize in its regular schedule (approximately every 30 seconds for surveys, with a synchronization time of 5 minutes).
- Go to Organization Settings > Authentication > Auto-Provisioning
- Check the state of the bridge - it should pass from Pending to Syncing Şi apoi la Active
- Go to People to verify users have been provisioned
- Check the Event Log for detailed sync activity
Setting a User’s Role
Section “Setting a User’s Role”the platform membership roles (Owner, Adminand so on) are assigned in People or mapped with SAML Role Attribute. SCIM creates people as Employee by default.
Separately, synchronizing a job title and job type helps the platform assign policies and perform meaningful access assessments.Without these profile fields, a user can still register, but it is harder to evaluate for access with the least privileges.
Google Workspace synchronizes two relevant fields with the platform via the SCIM bridge:
- Job title User position (e.g. Software Engineer, Financial Manager, IT Administrator)
- Type of employee Their type of employment (e.g. Full-time, Part-time, Internal, Contractor, Freelance)
- In the Google Admin console, go to Directory → Users
- Select the user you want to update.
- Open User information → Employee information
- Set the Job title Field to User Position
- Set the Type of employee field to their employment type
- Click Save
- At the next synchronization, both values appear on the user profile on the platform.
Troubleshooting
Section “Troubleshooting”Bridge Stuck in “Pending”
Title: Bridge Stuck in “Pending”- CauseOAuth authorization has not been completed or the token has expired
- Solution: Re-authorize the Google Workspace connector by clicking Authorize again
Bridge in “Failed” State
“Bridge in ‘Failed’ State”- Cause: A synchronization error occurred (network problem, API rate limit, invalid credentials)
- Solution: Check the event log for error details. The bridge will automatically resume with exponential downgrading. If the problem persists after 10 consecutive failures, the bridge will be disabled – solve the underlying problem and activate it manually.
Users Not Appearing
“Users Not Appearing”- CauseThe Google OAuth application domain may not include directory access or users are in an organizational unit that is not visible to the administrator account
- SolutionCheck if the admin API SDK is enabled and the OAuth consent screen includes the domain ___ZBT_I18N_RUNTIME_BLOCK_197__
Stale Users Not Deactivated
“Stale Users Not Deactivated”- CauseUsers may be in the exclusion list or synchronization has not yet completed a full cycle
- Solution: Check the exclusion list and wait for the next synchronization cycle. Each synchronization processes up to 500 users per page in Google Workspace.
OAuth Token Expired
Section entitled “OAuth Token Expired”- Cause: The refresh token has been revoked or has expired
- SolutionBridge automatically refreshes OAuth tokens, but if the refresh token itself is revoked (for example, the user has removed access to the app in Google), you will need to re-authorize.
Combining with SSO
Section entitled ‘Combining with SSO’For the best experience, combine SCIM Bridge Provisioning with SAML SSO:
- SCIM Bridge user life cycle management – automatic creation and deactivation of accounts
- SAML SSO Manages authentication – users log in with Google credentials
This means that users automatically get platform accounts when they join your organization and lose access when they leave, without the need for manual account management.