Skip to content

Google

This article includes information on adding Google Workspace as an integration to sync objects to Oblique. To use Google as an identity provider to authenticate to Oblique, see Single sign-on.

When you connect a Google Workspace directory to Oblique, Oblique will automatically sync users, user attributes, accounts, and Google groups from Google to Oblique.

As you add or remove users, groups, or group members in Google, these changes are automatically synced to Oblique. If connected in read-write mode, Oblique can also change Google group membership.

You can add multiple Google Workspace directories to Oblique. These function as separate integrations and are distinguished by their domain.

Oblique syncs the following from your Google Workspace domain. In read-write mode, Oblique can also change Google group membership.

Google objectOblique objectCapability
UsersUsersRead-only
User fieldsUser attributesRead-only
UsersAccountsRead-only
GroupsResourcesRead-only
Group rolesRolesRead-only
Group membershipEntitlementsRead-write
Group nestingEntitlementsRead-only

Oblique also reads sign-ins to third-party apps from Google Workspace audit logs, to suggest apps that might be in scope for user access reviews.

Oblique syncs each user in the Google Workspace domain as an Oblique user.

Oblique uses the following user fields from Google to identify users:

  • primaryEmail
  • displayName
  • fullName

Oblique syncs the following user fields from Google as user attributes:

  • title
  • employeeType
  • managerEmail
  • department
  • costCenter
  • buildingId
  • floorName
  • floorSection
  • thumbnailPhotoUrl

Oblique also syncs each user in the Google Workspace domain who can sign in as an Oblique account. A user Google suspends can’t sign in, so their account is removed, along with the group memberships it holds, and comes back if Google restores them. The user stays in Oblique, marked deactivated.

Google accounts are matched to Oblique users by email.

Oblique syncs the following from Google as resources:

  • Each Google group in the domain

Oblique syncs Google group roles as Oblique roles. Every group member holds exactly one: MEMBER, MANAGER or OWNER, as Google reports it. Granting a group in Oblique names one of the three.

In Google, where a group is a member of another group, Oblique represents this as the nested group having an entitlement to the outer group. In Oblique, you can see the access that members of the nested group have through the outer group.

The Google integration requests the following permissions for your Google Workspace domain:

  • See info about users on your domain
  • View groups on your domain
  • View and manage the provisioning of groups on your domain (for a read-write integration)
  • View audit reports for your Google Workspace domain
You must be an admin to add an integration.

You connect a Google Workspace to Oblique by signing in to Google as a Workspace administrator and approving the access Oblique asks for.

To add a Google integration, navigate to the Integrations page:

  1. Select Add integration.
  2. Select Google Workspace.
  3. Under Connect, select Read-write to let Oblique manage Google groups, or Read-only to only use your Google Workspace as a source, and not as a destination. By default, this is read-write.
  4. Select Connect Google Workspace.
  5. Authorize the permissions that the Google integration asks for.

Oblique then authenticates to Google as that administrator, and syncs information about the organization their account belongs to. Oblique will immediately start syncing users and Google groups from Google to Oblique.

Configure Oblique app to authorize access to your Google Workspace APIs

Section titled “Configure Oblique app to authorize access to your Google Workspace APIs”

If your organization restricts which third-party apps can reach Google Workspace APIs, the Oblique app needs to be configured by a Google administrator before they can connect Oblique to your Workspace.

To configure the Oblique app in the Google Admin console, navigate to Security > Access and data control > API controls:

  1. Under App access control, select Manage app access.
  2. Select Configure new app.
  3. Search and select the client ID 298647613525-enafl8d47h08hjjrt6tbj432j57na4ki.apps.googleusercontent.com, which is the Oblique app.
  4. Select the organization or org units for which you are configuring the app, then select Continue.
  5. Select Trusted, then select Continue.
  6. Select Finish.

Change Google integration’s authorizations

Section titled “Change Google integration’s authorizations”
You must be an admin to change an integration's authorizations.

To reconnect the Google integration, including to change the administrator it is tied to, or to grant additional authorizations, from the integration’s detail page:

  1. Navigate to the Settings tab.
  2. Under Connection, select Reconnect, or Upgrade to read-write.
  3. Sign in as a Google Workspace administrator and approve the permissions Google asks for.

A read-write integration can’t be changed back to read-only. Instead, remove the integration and add it again.

Oblique can manage membership for Google groups in your Google Workspace. This is not possible if the Google integration has read-only access.

Oblique can’t create Google groups, or change which groups are nested in a group.

You must be an admin to remove an integration.

To remove a Google integration, from the integration’s detail page:

  1. Navigate to the Settings tab.
  2. At the bottom of the page, under Delete integration, select Delete integration….
  3. In the confirmation dialog, type the text to confirm, then select Delete integration.

This will immediately stop all syncing and remove all resources from the integration. Access that Oblique granted in Google stays as it is.