This guide walks you through the process of configuring Google Workspace and Clavister Cloud Services to establish seamless integration between the two systems. To achieve this, you will need to perform specific configuration steps in both Google Workspace and Clavister Cloud Services. The guide uses our example companyShieldIT as<company_name> through the different steps
To integrate with the Google Workspace API, complete the setup in the Google Cloud management console, the Google Workspace admin console, and within Clavister Cloud Services.
Google Cloud Console Configuration
- Enable required APIs: (How to enable Google APIs)
- Admin SDK API
- IAM API
- Create a Service Account:
- Go to IAM & Admin > Service Accounts.
- Create a new Service Account (a name is sufficient; no special configuration is needed).
- Note down the Service Account client ID.
- Download the Service Account key in JSON format.
Google Workspace Admin Console Configuration
- Enable Domain-Wide Delegation:
- Navigate to Security > Access and data control > API controls.
- Click on Domain-Wide Delegation.
- Add a new API client using the Service Account client ID from before, and scopes.
- https://www.googleapis.com/auth/admin.directory.user.readonly
- https://www.googleapis.com/auth/admin.directory.group.readonly
- Create a user for API access:
- Create a user account in your Google Workspace domain for Clavister Cloud Services to impersonate.
- This user must have read access to users and groups.
Setting up Google Workspace in Clavister Cloud Services
- Access Clavister Cloud Services, example using ShieldIT: https://shieldit.sase.eu/.
- Navigate to Users and select the User directories tab.
- Click on the Add new button and choose the Google option. Provide a name for the directory, input the Impersonated user created previously, choose the Domain and upload the Service Account JSON file.
- Google users should now have the ability to enroll.
Please note:
Once you have successfully completed the steps outlined above, the configuration process is considered complete. Further configuration within Google and Clavister Cloud Services may not be necessary at this stage. Users who are part of the Google Workspace setup will now have the ability to enroll in the service, note that they will need to have a mobile phone number and email configured in to be able to enroll and that they will not show up in the Clavister Cloud Services console until enrolled using the normal enrollment link. If needed, additional actions and configurations can be performed by users within the Google Workspace environment to facilitate their enrollment in Clavister Cloud Services.
Related articles
17 Mar, 2025 oneconnect sase cloud
5 Feb, 2024 oneconnect sase
6 Dec, 2023 sase
16 Feb, 2023 sase
28 Feb, 2025 sase cloud ad
31 Jan, 2023 sase
11 Feb, 2025 sase azure cloud
10 Oct, 2024 sase oneconnect core userauth
9 Oct, 2024 oneconnect sase cloud radius
8 Jan, 2025 sase
7 Feb, 2024 sase
14 Apr, 2023 sase
25 Mar, 2025 cloud sase