Use the Google Workspace Integration in the Enterprise Portal (Preview)

The final step in creating a secure and consistent connection between JumpCloud and Google Workspace is syncing data between the two platforms. This article outlines the steps you need to take to import or export data between JumpCloud and Google Workspace.

Prerequisites:

  • A JumpCloud administrator account
  • JumpCloud Device Package or higher
  • A Google Workspace Cloud Directory integration authorized and active in JumpCloud
  • You have read through the considerations for Get Started: Google Workspace Integration
  • You have reviewed the attribute considerations and configured your desired user attributes per Configure the Google Workspace Integration
  • An alternative method has been setup for 2-Step Verification, like a phone number

Associating JumpCloud users with Google Workspace

After you authorize syncing for your Google Workspace directory, you can specify users and groups to manage from JumpCloud by associating them to that Google Workspace directory. Users can be given access to a Google Workspace directory either directly or through a user group.

Prerequisites:

  • An authorized and activated Google Workspace directory.
  • Ensure that any users or groups, either preexisting or new, follow Google's naming guidelines.

Considerations:

  • When you remove a user from a Google Workspace directory in JumpCloud, either directly or by removing them from all User Groups that disconnects them from the Google Workspace directory, the user is immediately suspended in Google Workspace and any existing Google sessions expire. After they’re disconnected, the user is unable to log in to any Google Workspace resources that are connected to that directory.
  • Don’t add a Google Workspace directory more than once in JumpCloud. If you authorize sync for the same Google Workspace directory more than once, users that are connected to multiple instances of the same Google Workspace directory in JumpCloud could be suspended if you remove them from one of the instances. You can avoid this by deactivating the sync for duplicate Google Workspace directories. 

To connect JumpCloud users to a Google Workspace directory

From Identity Management > Users

  1. Log in to the EP.

Important:

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Identity Management > Users.
  2. Select a user to view their details.
  3. Select the Directories tab.
  4. Select the Google Workspace directory to which you want to connect the user.
  5. Click Save User. Synchronization will be initiated.
     

From Identity Management > User Groups

  1. From the JumpCloud EP, go to Identity Management > User Groups.
  2. Select a user group to view their details.
  3. Select the Directories tab
  4. Select the Google Workspace directory to which you want users in the user group to be synced and have access.
  5. Select the Users tab.
  6. Check the box next to each user you want added to the group. 
  7. Click Save Group. Synchronization is initiated.

Tip:

You can also connect a user or user group from the Google Workspace Cloud Directory configuration page. Navigate to Cloud Directories, select the Google Workspace Directory, select the Users or User Groups tab, then select the user(s) or user group(s) you want to give access to the Workspace directory and click save.

Post connection behavior

After you connect a user to a Google Workspace directory

  • If the user didn’t previously exist in Google Workspace and the email sent as the PrimaryEmail matches a Google Workspace directory domain, a new, active user account is provisioned to Google Workspace 

Note:

The Domains configuration for the integration will determine what happens If the user’s company email domain does not match the Google Workspace directory domain or the list of configured domains. See Configuring Domain(s).

  • If the user resets their JumpCloud password, it's synced to Google Workspace. When set, existing sessions to Google Workspace apps expire, and the user must log in again.
  • After you connect a user to a Google Workspace directory, the flow differs slightly for staged and active users:
    • Staged user flow: A staged user is a user in a ‘staged' user state with a password status of either ‘password pending' or 'active’. 
      • Staged users who do not already exist in the Google Workspace directory will not have access to Google Workspace until you change their user state to active and a password is set in JumpCloud. They will not receive welcome or activation emails until they are in an 'active’ user state.
      • Staged users who already exist in the Google Workspace directory will remain active in that directory and will continue to have access. See Manage User States for more information about user states.
    • Active user flow: An active user is a user in an 'active' user state, has a password, and that password status is set to 'active'. After you add an active user to your Google Workspace directory in JumpCloud, the user receives an email that tells them which directory they’ve been added to and to synchronize their password by logging in to their User Portal.

After you connect a group to a Google Workspace Directory

  • If you enabled Google Workspace group management  and no distribution group with a matching email exists in Google Workspace, a distribution group is created in Google Workspace, and the JumpCloud group name and description are synced to the new Google Workspace distribution group.
  • If you changed a user group’s membership in JumpCloud, the changes are synced to Google.
Back to Top

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case