Manage Google Workspace users

When an Okta end user is assigned to Google Workspace or when their assignments are updated, admins have the option to manage all Google licenses and roles, and deprovisioning actions, within Okta. Additionally, this Okta end user's licenses and roles can be automatically updated within their third-party Google account. This is true individually or within a group. In essence, any updates created in Okta can be subsequently pushed to Google.

Prerequisites

  • In Okta, enable Google Workspace provisioning and enable the appropriate provisioning features (Create users, Update User Attributes, Deactivate Users).

  • Disable Auto-assign the following license to all currently unassigned users and users subsequently created.

    Clear the Auto-Assign Users option

Procedures

Manage Google licenses

When Okta end users are assigned, or changed in the Universal Directory Profile Editor, choosing true allows any changes in their Google licenses to be automatically pushed to Google. Choosing false doesn’t push any information.

  1. In Okta, select the Assignments tab for your Google Workspace instance, select a User or Group, then click Edit.

  2. Select true from the Manage licenses on create update drop-down menu.

  3. Select the User or Group to assign the licenses to.

Only certain groups of Google licenses can be individually selected, as some groups provide mutually exclusive options. For example, you can assign only one license selection at a time for Google Workspace and Google Drive. Choosing more than one license results in an error on the Tasks page, and only the first selection is honored.

Note that you also have the option to Remove all Google Workspace licenses for the selected User or Group under Deactivation options on the Edit User/Group Assignment screen.

Manage Google roles

Note: Customers need to contact Okta Support to migrate their Universal Directory profile template to enable this feature.

  1. In Okta, select the Assignments tab for your Google Workspace instance, select a User or Group, then click Edit.

  2. Select true from the Manage roles on create and update drop-down menu.

  3. Select the User or Group to assign the Role to.

Note that you also have the option to Remove all Google Workspace Roles for the selected User or Group under Deactivation options on the Edit User/Group Assignment screen.

Manage user assignments

When you need to deprovision or deactivate an Okta user from Google Workspace, you can do so without compromising the user's Google account. Control this element under Deactivation options on the Edit User Assignments page.

If options are left unchecked, the user is suspended in Okta and in their corresponding Google account.

These are the deactivation options:

  • Do not suspend user: Checking this box prevents the user's account from being suspended in Google after deprovisioning in Okta. The user's Google account remains active.
  • Remove all Google Workspace licenses: Checking this box ensures that, when deprovisioned, Google licenses for this user no longer exist in Okta.
  • Remove all Google Workspace Roles: Checking this box insures that, when deprovisioned, Google roles for this user no longer exist in Okta.

License Mapping

We have recently updated Google Workspace licenses for our Google Workspace provisioning integration. To use updated licenses, contact Okta Support and request that they migrate your Google Workspace application instance to the new profile template.


Due to some limitations, there is a slight difference in license naming. This table provides the license mapping.

SKU ID Okta Name GSuite Name
Google-Apps-For-Business Google Apps for Business G Suite Basic
Google-Apps-For-Postini Google Apps for Postini Google Apps Message Security
Google-Apps-Unlimited Google Apps Unlimited G Suite Business
Google-Apps-Lite Google Apps Lite G Suite Lite
1010020020 G Suite Enterprise G Suite Enterprise
1010060001 Drive Enterprise Drive Enterprise
Google-Drive-storage-20GB Google Drive Storage 20GB Google Drive storage 20 GB
Google-Drive-storage-50GB Google Drive Storage 50GB Google Drive storage 50 GB
Google-Drive-storage-200GB Google Drive Storage 200GB Google Drive storage 200 GB
Google-Drive-storage-400GB Google Drive Storage 400GB Google Drive storage 400 GB
Google-Drive-storage-1TB Google Drive Storage 1TB Google Drive storage 1 TB
Google-Drive-storage-2TB Google Drive Storage 2TB Google Drive storage 2 TB
Google-Drive-storage-4TB Google Drive Storage 4TB Google Drive storage 4 TB
Google-Drive-storage-8TB Google Drive Storage 8TB Google Drive storage 8 TB
Google-Drive-storage-16TB Google Drive Storage 16TB Google Drive storage 16 TB
Google-Vault Google Vault Google Vault
Google-Vault-Former-Employee Google Vault Former Employee Google Vault - Former Employee
1010010001 Cloud Identity Cloud Identity
1010050001 Cloud Identity Premium Cloud Identity Premium
     

Troubleshooting

Apps for which users do not have a license may appear on their Okta Home page. Clicking these apps results in an error message.