Google Workspace connects per company, not once for your whole tenant. Each client signs in to their own Google Workspace, exactly like the Microsoft 365 company connection flow.
What Gets Synchronized
Users
Directory profiles, account status, aliases, and organizational unit
Groups
Groups, descriptions, aliases, and full membership lists
Licenses
Product and SKU assignments across the Google product catalog
Domains
Primary, secondary, and alias domains with verification status
Daily security posture
2-Step Verification, sign-in activity, and account risk signals scored out of 100
Prerequisites
Access MSPortal Requests
The synchronization reads Google Workspace data. Directory and usage-report scopes are read-only; Google’s Apps licensing scope grants read/write API access even though this integration uses it to read assignments. Review that distinction during consent. Google documents the licensing scope here.
Consent must include every one of these. If an administrator declines part of the consent screen, the connection is rejected and reports which access is missing.
Connecting a Company
1
Open the Google Workspace companies page
Go to Settings > Integrations, find the Google Workspace card, and click Set up companies.Once at least one company is connected, that button reads Manage companies.
2
Find the company
The companies table shows one row per connection, or an unconnected row for a company that needs setup. Use the status selector and column filters to find the company and domain. A company with multiple Workspace connections can appear more than once.The Connection progress card at the top tracks how many companies are connected out of your total.
3
Start the connection
Click Connect on the company row. A Google sign-in popup opens.If the company already has a connection and you are adding a second Google Workspace account, click Add connection instead.
4
Sign in and approve access
Sign in with an administrator account for that client’s Google Workspace and approve the requested access.MSPortal then verifies the connection against Google’s directory, reports, and licensing services before saving it. The popup closes on its own and the company shows a green Connected badge.
5
Let the first sync run
The connection requests an initial synchronization. Check the row’s status, counts and last-sync time after it completes. A connected badge alone does not prove every dataset has refreshed; posture may be deferred until Google supplies complete reporting data.
Each Google Workspace account can be connected to one MSPortal company. If you try to connect a Google Workspace account that is already linked elsewhere, MSPortal reports that the customer is already connected to another company so two companies never claim the same tenant.
Reading the Connection Row
Each connected Google Workspace tenant appears as a row inside the company row, labeled with its primary domain.
The progress summary counts companies, while the table lists connections. A company may count as connected while one of its connections needs attention; inspect the individual rows.
Choosing What to Sync
Click Sync settings on a connection to open Choose data to sync. All five datasets are enabled by default.
Click Save settings to apply. Turning a dataset off stops future updates for it on the next run.
Managing a Connection
Disconnecting
Click Disconnect, then confirm in the Disconnect Google Workspace? dialog. MSPortal stops updating Google Workspace data for that company. Do not use Disconnect as a reversible pause or assume imported data will remain available. Review the company and domain in the confirmation first; reconnecting requires administrator consent again.Synchronization Schedule
- Google Workspace synchronizes once per day, deliberately offset from the Microsoft 365 secure score run so the two do not compete.
- Enabled directory datasets are refreshed from Google. Stale-record cleanup depends on complete retrieval. If a run fails, inspect its error and dataset timestamps; do not assume every dataset is equally current.
- Use Sync now whenever you need data ahead of the daily schedule, for example right before a client review.
Google’s usage reporting, which supplies the 2-Step Verification and sign-in signals behind posture scoring, is published on a short delay. Posture snapshots therefore reflect account activity from a few days prior, while users, groups, licenses, and domains reflect the moment of the sync.
Automatic Pausing
If a connection fails repeatedly, MSPortal pauses it and notifies you rather than retrying indefinitely.
A paused connection shows Paused on the companies page. Click Reconnect and complete the Google sign-in again to resume.
Troubleshooting
Questions and troubleshooting
Can I connect one Workspace account to two companies?
Can I connect one Workspace account to two companies?
No. Use the company that owns the Workspace customer. Resolve an existing mapping before reconnecting elsewhere; do not create a second company to work around the conflict.
Does Connected mean every dataset is current?
Does Connected mean every dataset is current?
No. Inspect last-sync times, count badges and errors. Progress counts companies, and a connected company can still have a connection needing attention.
Why does Google consent mention license management?
Why does Google consent mention license management?
Google’s Apps licensing scope permits read/write API access. MSPortal’s synchronization reads assignments. The directory and reporting scopes are read-only; the whole consent request should not be described as exclusively read-only.
Can I send the Google popup URL to another administrator?
Can I send the Google popup URL to another administrator?
Complete this connection in the browser session that started it. The Google flow is bound to that MSPortal user and browser and expires after ten minutes. Restart Connect if the session expires.
Does disabling a dataset delete its imported records?
Does disabling a dataset delete its imported records?
The setting stops future updates for that dataset. It is not an erase control. Check freshness before using older values in client reporting.
Why are users current but posture is missing?
Why are users current but posture is missing?
Google usage reports can lag or be incomplete. A run can update directory data while deferring posture; a missing snapshot is not a perfect security score.
What should I check after reconnecting?
What should I check after reconnecting?
Confirm the correct company, Workspace domain and administrator, then verify a successful synchronization and the datasets needed for your review.
Related Resources
Cloud Overview
Where Google Workspace and Microsoft 365 data appears
Cloud Posture
How the Google Workspace posture score is calculated
Cloud Users
Browse every cloud identity across both platforms
Integrations Overview
Explore all available integrations