Target
- Access Control administrators
- Customers who synchronize with Google Workspace using user provisioning
Purpose
- Enable the user provisioning feature from Access Control to Google Workspace.
Notes
- The content of this article is based on the product specifications as of January 2026 and is subject to change without notice.
- After performing this procedure, please make all edits (create, update, delete) to user information in Access Control.
- Changes made in Google Workspace will not be synchronized to Access Control.
- If you need to add users created in Google Workspace via this feature to Google Groups, please do so separately from Google Workspace.
- This procedure requires Access Control global administrator privileges and Google Workspace super administrator account information.
- You cannot check the provisioning results from Access Control to Google Workspace.
To check provisioning logs, use the Google Workspace Admin console: [Reports] > [Audit and Investigation] > [Admin log events].
Admin log events (external link) - For instructions on how to access the Administration, please refer to the following article.
How to access the Access Control Administration
Procedure
Google Workspace API Settings
- Sign in to the Google Admin console with a Google Workspace super administrator account.
- Go to [Show all] > [Security] > [Access and data control] > [API controls] > [Domain-wide delegation].
- On the [Domain-wide delegation] screen, click [Add new].
-
Enter the information from Customer Portal provided by HENNGE, [API Client Registration ①] and click [Authorize].
Example configuration string (values will differ for each customer)
・Enter the "Client Name" in [Client ID].
000000000000-0aa0aaaaaaaaaaa00a0aaaaaaaaaa0aa.apps.googleusercontent.com・Enter "one or more API scopes" in [OAuth scopes (comma-delimited)].
https://www.googleapis.com/auth/admin.directory.user - On the [Domain-wide delegation] screen, click [Add new] again.
-
Enter the information from Customer Portal provided by HENNGE, [API Client Registration ②], and click [Authorize].
Example configuration string (values will differ for each customer)
・Enter the "Client Name" in [Client ID].
000000000000.apps.googleusercontent.com・Enter "one or more API scopes" in [OAuth scopes (comma-delimited)].
https://mail.google.com/ - Verify that the information for the added API clients is displayed on the screen.
Access Control Provisioning Settings
- Access the Access Control Administration.
-
Select [System] > [Provisioning Settings] from the left menu.
-
In the [Sync from Access Control] menu, click [Google Workspace] > [View Details].
- Enter the following settings and click [Save Changes].
- [Account provisioning]: "Enabled" (Please enable the toggle.)
- [Password provisioning]: "Disabled" (Please disable the toggle.)
- [Google Workspace administrator user]: Enter the email address of an account with Google Workspace super administrator privileges.
* After enabling the setting, any changes (create, update, delete) to user information made in Access Control will be synchronized to Google Workspace.
Notes on Password Provisioning
- If a Google Workspace password is changed via provisioning, the target user's session will be disconnected.
When enabling password provisioning, be sure to notify users in advance of the password information to be provisioned. - Do not provision passwords synchronized from Active Directory to Access Control.
Since passwords are hashed, even if provisioned, users will not be able to log in directly to Google Workspace. - For the account set as [Google Workspace administrator user], specify an account that will not be deleted in the future.