探花大神

Troubleshoot: Google Workspace Integration

After a user changes their password and is logged out of their Google session, 2-Step Verification only asks for a backup code when trying to log back in.

Cause: The users do not have a secondary/additional form of MFA.

Resolution: Ensure users have a secondary/additional form of MFA, like Authenticator (TOTP) or 2-Step Phone verification phone.

I made group membership changes and then bound the group to the Google Directory – the removed users are now suspended.

Cause: When users are removed and the directory is added in the same save action, the group members are synced in the group's original state and then the removed users are updated to indicate they no longer have access.

Resolution: The change in membership and then adding the directory must be completed in two separate steps. Remove the user(s) and save the group. Then, add the directory and save the group again.

500 Error when attempting to import Google Workspace Users.

When using the Google Apps User Provisioning and Sync utility, administrators occasionally receive a 500 Error during the import process. This occurs after an admin has successfully established an OAuth connection and attempts to import users.

Cause:

The most prevalent cause of this is the Google Apps account itself not having API Access enabled under  > Security > API Reference > API access.

Resolution:

We recommend that you enable the API access setting and re-attempt to import users. 

The advanced filter I entered is not returning the expected results.

Double-check the filter with of advanced filters.

Updates made in Google Workspace are not being imported into 探花大神.

This can be a timing issue. Try to import the updates again by doing a manual full sync or update only sync or wait for the next automatic import to run. 

A 探花大神 user bound to Google Workspace does not synchronize as expected.
  • If provisioning from 探花大神 to Google, the user might not show up in the Google Apps Admin Console.
  • Previously provisioned users don鈥檛 synchronize new passwords when reset in 探花大神.

Cause:
The username and/or password doesn't comply with Google's name and password guidelines. 

Resolution:
Make sure the Gmail username and password comply with .

If the above resolutions don't solve the issue, contact your 探花大神 administrator to verify your account status and assist in troubleshooting. If signing up for service, please submit a support request and confirm the email address being used in the form.

Alternate Resolution:

Add 探花大神 as a Trusted Third-Party application.

The password is not syncing for a user.
  • Verify that the password attribute is set to Export in the Attribute Mappings and Settings section of the configuration.
  • Check if the user is a super admin.
    • If yes, verify that the account used to authorize the integration was a super admin. If not or if you are unsure, reactivate the integration with an account that is a super admin account.聽
    • If the user is not a super admin, consult the DI events and the Google audit logs.
New 探花大神 users don’t appear in Google Workspace.

When a new user is created in 探花大神, their account is not synchronized to and does not appear in Google Workspace list of users. Existing users will synchronize without issue.

Cause:

The Google Workspace instance has run out of available license seats.

Resolution:

I鈥檓 trying to import a user from Google into 探花大神, but I鈥檓 getting the following message: 鈥 has already been registered鈥

Cause: This issue occurs because the integration automatically sets the user鈥檚 探花大神 username to the prefix of their Google email address (the part before the @ symbol) during import. This prefix already exists as a Username or Local User Account for an existing user in your 探花大神 organization.

Resolution: There are a few options for resolving this issue.

  • Create a matching 探花大神 account:  Manually create the user in 探花大神 with just their Google email address and a unique username. Then, use the Google Workspace Cloud Directory manual import functionality to update the user record with the rest of the user information from Google. You can use an import filter to limit the update to just that user, if needed. See Using the Google Workspace Integration to learn more.
  • Update the email address in Google: Change the prefix to something unique and not used in 探花大神. Note that this may have impacts on the end-user.
  • Update the 探花大神 username: Change the existing 探花大神 username or Local User Account to avoid conflicts. This requires disconnecting the user from all resources and may cause service disruptions.
鈥淓rror 400: admin_policy_enforced鈥

When you attempt to authorize the Google Workspace Directory integration using a Super Administrator account, you can receive an 鈥淓rror 400: admin_policy_enforced鈥 error message.

There are three common causes for the "Error 400: admin_policy_enforced" message:

Cause 1:

API Access is Restricted. 

To fix this and Enable API Access: 

  1. Log in to the Google Workspace Admin Console.
  2. Go to Security > API Controls > Manage Google Services
  3. FindGoogle Workspace Admin and select Change Access
  4. Select Unrestricted: Any user-approved app can access a service to enable API Access

Cause 2:

One of the systems is disabled.

To fix this and enable systems:  

  1. Log in to the Google Workspace Admin Console.
  2. Go to Security  > API Permissions.
  3. Enable any disabled systems:

Cause 3:

URL Blocking is blocking necessary URLs like the GAM client_id.

To fix this and unblock necessary URLs:  

  1. Log in to the Google Workspace Admin Console. 
  2. Go to Devices > Chrome Settings > User Settings.
  3. Confirm that necessary URLs aren't blocked.
I am trying to specify a distribution group, but I cannot add an email address.

Ensure that Enable management of groups and memberships in Google Workspace is enabled. Once it is enabled, click Save. You should see the Distribution Group Email column.

I am getting a “This app is blocked” error when trying to add a Google Workspace domain to 探花大神.

Cause: There are pre-existing restrictions or security measures that prevent access

Resolution: Use the following steps to resolve this issue:

  1. Navigate to the Google Workspace Admin dashboard.
  2. In the top search bar, search for and select API Controls.
  3. Under App access control, click MANAGE THIRD-PARTY APP ACCESS.
  4. Search for the name "探花大神" or the matching ID and click Change Access.
  5. Select Trusted and then click Continue.
  6. Once this done, admins would be able to successfully add domain to Google Workspace in 探花大神.

Additional Resources

  • Enroll:
Back to Top

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case