Top.Mail.Ru

Advanced UnSpot Plan from $100 $50 for Your Company Fix this Price

Promo deadline:
Help center / Administration / Integrations / User sync / Set up user sync with Google Workspace

Set up user sync with Google Workspace

A guide for the UnSpot administrator and the Google Workspace administrator: how to connect employee synchronization from the organization directory and which fields to transfer. You connect it in Manage > Integrations > Synchronisations. The roles that may configure integrations are Super Administrator and Integrations Administrator. How the exchange works, which permissions are granted and what leaves the directory is covered in the companion article User sync with Google Workspace: how it works — that is also the one to hand to your information security team.

What you need

  • An UnSpot role: Super Administrator or Integrations Administrator.
  • A Google account with the right to read the organization directory — a Workspace super administrator, for example. The exchange then runs on its behalf, so disabling it stops the synchronization.
  • The ability to confirm every requested permission. If Google returns an incomplete set, the connection fails — UnSpot checks that the permissions are complete.
  • A free synchronization slot: only one method can be connected at a time — Google Workspace, Entra ID, AD LDAP or OpenLDAP. If another one is connected, disconnect it first.

Step 1. Connecting

  1. Open Manage > Integrations > Synchronisations and click Connect on the Google Workspace card.
  2. In the Google window that opens, sign in with an account that can read the organization directory and confirm the requested permissions.
  3. The card then shows the connected account, and employee synchronization starts immediately.

Connect from the administrator’s own workstation: when the authorization starts, the session token is passed as a parameter in the address, and addresses with parameters stay in browser history.

Step 2. Synchronization data

Email, first name and last name are always transferred. The other fields are switched on with the Edit button on the card — the field set can be changed at any time.

CheckboxWhat is transferred
DepartmentThe department from the Google record. Mutually exclusive with the organizational structure — see step 3
PhoneThe first number in the employee phone list
PositionThe position from the Google record; values longer than 128 characters are truncated
ManagerThe link is built by the manager email address, so their record has to be in UnSpot as well and must not be archived
User profile pictureThe profile photo. Refreshed by a separate platform job — avatars will not appear immediately after you select the checkbox
Organizational structureThe Workspace department tree and the employee position in it. See step 3

Note the email address: UnSpot takes the first address in the list of the employee addresses, not necessarily the one marked primary in Workspace. If your employees have several addresses and the UnSpot login is not the one you expected, that is why.

Step 3. Organizational structure and department

Google Workspace is the only cloud synchronization integration that transfers the organizational structure into UnSpot: the Workspace department tree and where the employee sits in it. Local AD LDAP and OpenLDAP directories can do it too; a connection to Entra ID through Graph API cannot.

Department and Organizational structure are mutually exclusive. You cannot enable both: an employee department is filled from a single source. The form blocks the second option, and an attempt to save both is rejected.

If the integration was connected long ago, the organizational structure sync may not run — the token issued back then may lack the required permission, and refreshing a token does not widen the permission set. The failure is silent: the connection is not flagged as invalid, the Reconnect button never appears, and the entire user pass fails because units are read before employees. The symptom is that employees stopped updating after the Organizational structure checkbox was switched on; entries with the synchronization initiator stop appearing in the User management history report, and the underlying insufficient-permissions error is written only to the service synchronization log — the console does not show it. The fix: click Disconnect, then connect the integration again and confirm the permissions; after that click Edit and tick the fields you need again — disconnecting resets the field set to the required ones.

The head of a department is not transferred from Google Workspace — that field is filled only when synchronizing with Active Directory.

What is available after connecting

The card shows the connected account. From then on the synchronization runs automatically, once a day on the platform schedule. This integration has no manual run button.

Employees created by the synchronization receive no email from UnSpot: the password is generated randomly and told to no one. They sign in through Google SSO (when configured) or by recovering the password for their email address.

ButtonWhen it is availableWhat it does
Editwhile the connection is healthyOpens the synchronization field set. Adding a field starts a resynchronization straight away; clearing a checkbox takes effect from the next cycle, and values already transferred stay on the records
Reconnectonly while the connection is flagged as invalid — the card then reads that the account is not valid and asks you to reconnect it or use another oneRuns the authorization again; the account is not checked for a match — take care not to finish it under a different account. The settings and the links between directory entries and UnSpot records are cleared, and objects are matched again by email address
DisconnectalwaysStops the synchronization and clears the settings together with the tokens. Employee records are kept. The application access on the Google side is not revoked — if that is what you need, revoke it in the Google admin console

What this integration cannot do

  • Narrow the result. This integration has no user filter: the whole organization directory is synchronized. If service or shared mailboxes exist as Workspace users, they reach UnSpot as well.
  • Transfer Workspace groups. There is no groups checkbox for Google in the interface, and groups are not transferred in any mode. If you need groups in UnSpot permissions, create them in UnSpot by hand or use another synchronization method.
  • Transfer the badge number. There is no NumberPass checkbox for this integration.
  • Handle the archived account state. Only “suspended” is processed: a suspended employee is archived in UnSpot, an archived one is not.

If something does not work

What you seeWhyWhat to do
The connection does not complete and the message “Invalid scopes. Please try again.” appearsGoogle returned an incomplete set of the requested permissionsConnect again and confirm every requested permission
A message that the account is not supported for synchronization and asking you to check its permissionsThe account has no administrator rights on the organization directoryConnect with an account that can access the directory — a super administrator, for example
A message that the account is not validThe token stopped working: the account was disabled or the application access was revokedClick Reconnect and authorise again
A message that user synchronization is already connected through another directory serviceAnother synchronization method is already connectedDisconnect it first, then connect this one
A message that department and organizational structure cannot be synchronized at the same timeBoth mutually exclusive settings are selectedKeep one of them — see step 3
Employees stopped updating after the structure checkbox was switched onThe token lacks permission to read organizational units; the failure is silent and aborts the whole passDisconnect the integration and connect it again, confirming the permissions; then click Edit and tick the fields you need again — disconnecting resets the field set to the required ones
A new or renamed unit did not appear in UnSpotThe tree is imported once — at the moment the Organizational structure checkbox is switched on; the daily cycle does not refresh itSwitch the Organizational structure checkbox off and back on
Extra accounts appeared in UnSpotThere is no result filter — the whole directory is transferredDeactivate those records in UnSpot (deleting a synchronized record is the same as deactivating it) or suspend/remove the accounts in Workspace. Archiving a record by hand will not help — the next cycle restores it
An employee login is not the address you expectedThe first address in the list is taken, not the one marked primaryCheck the employee primary address and aliases; if the wrong address became the login, remove the extra alias or contact UnSpot support
Avatars did not appearPhotos are refreshed by a separate platform jobWait for the next run of that job

Changes made by the synchronization are visible in Analytics > Reports, the User management history report: such entries carry a synchronization marker in the initiator column.

Leave a request for a call and we will contact you

Loading