The following are Frequently Asked Question regarding 探花大神's Google Workspace Directory Integration.
Integrating
探花大神 Utilizes OAuth to secure and persist its connection with Google to perform our integration tasks. Integrations logs detailing the Google Workspace 探花大神 OAuth connection can be seen within the Google Admin portal under the Reports > Activity Audit > OAuth Token report.
Yes, Google Workspace MFA is supported in 探花大神. 探花大神's MFA can also be used in conjunction with Google Workspace MFA if both layers are desired.
Users created via the 探花大神 / Google Workspace integration will follow the "Auto-Licensing" rules configured within the Google Workspace admin console. These settings can be seen in the "Billing" section of the Google Workspace admin console.
Within the Google admin console, all events occurring via the 探花大神 / Google Workspace integration are logged in the Reports > Admin report. Events are logged under the admin account that authorizes the OAuth connection in 探花大神. It is best practice to create a dedicated Google Workspace admin account to authorize the 探花大神 / Google Workspace OAuth connection.
When the OAuth session is deactivated in 探花大神, all users in Google will remain active and functioning. Within 探花大神, all user accounts remain active as well. All accounts will be unbound from the Google Workspace Directory. When and if the products are reactivated, the admin will need to reassociate the users to the Google Workspace Directory to re-establish the connection and ownership control of the accounts in Google.
While this was previously not a supported configuration, use of the Active Directory Bridge can indeed be used when either Google Apps or Microsoft 365 User Provisioning are enabled.
Yes, 探花大神 can manage email addresses in different domains. Need help? See the .
Yes, you can integrate multiple Google Workspace directories / accounts with 探花大神.
At this time, 探花大神 doesn't support avatar import to 探花大神 user accounts.
The Google Workspace and Microsoft 365 Directory integrations can be used together to successfully synchronize both service providers with 探花大神. The directory integrations utilize the user's email address as the unique identifier for synchronization. Due to this architecture, your domain records may need to be mapped so that the same email address is used between all service providers. For more information refer to the follow vendor-specific documentation:
Importing
Upon import, you will see a failure for this user to import as the account with the same email already exists.
探花大神's Google synchronization UI displays all of your Google users, regardless of whether they are suspended and/or previously imported. We will provide filtering mechanisms in the future.
At this time, only user accounts are supported between 探花大神 and Google Workspace. OU and Group membership management should continue to be managed in Google directly.
Use the Apply advanced filters on import functionality.
All users are imported by default unless an advanced filter is applied.
No. Once the Super Admin credentials have been authenticated, the connection to Google Workspace, regardless of Administrator, can perform importation and provisioning tasks.
Please see the attributes table in Sync User Attributes with Google Workspace.
The default user state is determined by the value set for Application / Directory Integrations (creation method) in Settings > User Management > Default User State for User Creation > Application / Directory Integrations.
Provisioning
While an admin can prevent an automated email from being delivered to the end user when creating the account inside of 探花大神 by specifying an initial password (Get Started: Users), associating a user to Google Workspace will send an email to the employee. We recommend educating the employee base first before associating them to Google Workspace so the email is expected.
This is generally caused by the Require user to change password at next sign-in setting within the Google User Account being set to true. This is found in the individual User鈥檚 鈥淎ccount鈥 settings within Google. It is advised that this setting be turned to false; 探花大神 will act as the authoritative source of password synchronization, and all password changes must originate from it. Users can then reset their strong password in 探花大神, and log in with those credentials.
A: If you are utilizing a Google Workspace trial account, this is a known limitation for API-created users until your instance is upgraded to a paid account. In order to remove the suspended user state on a newly created Google Workspace account, the user must attempt a login to the account in order to complete Google's verification steps. This is to prevent malicious activity on trial accounts, and to require that users complete validation prior to being placed into an active state.
Synchronization
The administrator can unassociate the user from the Google Workspace directory in 探花大神, which will trigger the user in Google to be suspended. Reassociating the user will re-activate the user in Google.
The user remains unchanged in 探花大神. If you wish to remove the user from 探花大神, these actions must be performed manually in the 探花大神 Admin Portal.
Should the user need to be re-provisioned from 探花大神 to Google, Google will often require up to 4-5 days before releasing the same email address to be used again.
Credentials
探花大神's password complexity works with Google Workspace-synced users just as with any other 探花大神 user and wherever their credentials are being used. Any attempt by a 探花大神 user to change their password in the 探花大神 User Portal to one that does not meet 探花大神's complexity requirements will fail. This does not, however, prevent the user from changing their password in their Google account to a non-compliant password. Since 探花大神 is the password authority, any change to the user in 探花大神 will overwrite the non-compliant password in Google with the compliant 探花大神 password.
When synchronizing between 探花大神 and Google Workspace, the password must be compliant with .
Be aware that passwords must be created with 12 or more characters. Passwords can be any combination of letters, numbers, and symbols (ASCII-standard characters only), or users won't sync from 探花大神 to Google Workspace.
The user鈥檚 Google account is suspended, blocking the user from accessing their account. The admin must set a new password for the user in 探花大神 to re-activate the user鈥檚 Google account.
Employees shouldn't change their password from Google Workspace's password change system because it won't update in 探花大神 and users could get locked out. We suggest referring to Require Users to Change Google Workspace Passwords in 探花大神 to prevent this.