Skip to main content
The Google Workspace integration connects each of your client companies to their own Google Workspace tenant. Once connected, MSPortal synchronizes directory users, groups and memberships, license assignments, and verified domains every day, and calculates a daily security posture score from Google’s own admin reporting. Connected data appears on the Cloud pages alongside Microsoft 365, so a mixed-estate MSP reviews both platforms in one place.
Google Workspace connects per company, not once for your whole tenant. Each client signs in to their own Google Workspace, exactly like the Microsoft 365 company connection flow.

What Gets Synchronized

Users

Directory profiles, account status, aliases, and organizational unit

Groups

Groups, descriptions, aliases, and full membership lists

Licenses

Product and SKU assignments across the Google product catalog

Domains

Primary, secondary, and alias domains with verification status

Daily security posture

2-Step Verification, sign-in activity, and account risk signals scored out of 100

Prerequisites

No Google Cloud project, service account key, or domain-wide delegation setup is required. MSPortal supplies the verified OAuth application, so the client only has to sign in and approve access.

Access MSPortal Requests

Every permission requested is read-only. MSPortal cannot create, modify, suspend, or delete anything in Google Workspace. Consent must include every one of these. If an administrator declines part of the consent screen, the connection is rejected and reports which access is missing.

Connecting a Company

1

Open the Google Workspace companies page

Go to Settings > Integrations, find the Google Workspace card, and click Set up companies.Once at least one company is connected, that button reads Manage companies.
2

Find the company

Every active company appears as a card. Use the Search companies or domains box, or the status filter, to narrow the list to All companies, Needs setup, Connected, or Needs attention.The Connection progress card at the top tracks how many companies are connected out of your total.
3

Start the connection

Click Connect on the company card. A Google sign-in popup opens.If the company already has a connection and you are adding a second Google Workspace account, click Add connection instead.
4

Sign in and approve access

Sign in with an administrator account for that client’s Google Workspace and approve the requested access.MSPortal then verifies the connection against Google’s directory, reports, and licensing services before saving it. The popup closes on its own and the company shows a green Connected badge.
5

Let the first sync run

A full synchronization starts immediately. User, group, license, and domain counts appear on the connection row as data arrives, and posture scoring begins on the next daily run.
Google Workspace connections cannot be created while you are impersonating another user. Exit impersonation first.
Each Google Workspace account can be connected to one MSPortal company. If you try to connect a Google Workspace account that is already linked elsewhere, MSPortal reports that the customer is already connected to another company so two companies never claim the same tenant.

Reading the Connection Row

Each connected Google Workspace tenant appears as a row inside the company card, labeled with its primary domain. Cards and rows that need attention are highlighted in amber, and the Connection progress card shows a needs attention count so problems are visible without opening every company.

Choosing What to Sync

Click Sync settings on a connection to open Choose data to sync. All five datasets are enabled by default. Click Save settings to apply. Turning a dataset off stops future updates for it on the next run.
Leave Daily security posture enabled even if you disable other datasets. Posture scoring is what powers the client-facing Cloud Posture page.

Managing a Connection

Disconnecting

Click Disconnect, then confirm in the Disconnect Google Workspace? dialog. MSPortal stops updating Google Workspace data for that company. Previously synchronized data may remain visible until it is replaced or removed.

Synchronization Schedule

  • Google Workspace synchronizes once per day, deliberately offset from the Microsoft 365 secure score run so the two do not compete.
  • Each run is a full refresh, not an incremental update. Every record is retrieved and validated before anything is written, and records that no longer exist in Google are removed only after a complete, successful retrieval. An interrupted run can never delete good data.
  • Use Sync now whenever you need data ahead of the daily schedule, for example right before a client review.
Google’s usage reporting, which supplies the 2-Step Verification and sign-in signals behind posture scoring, is published on a short delay. Posture snapshots therefore reflect account activity from a few days prior, while users, groups, licenses, and domains reflect the moment of the sync.

Automatic Pausing

If a connection fails repeatedly, MSPortal pauses it and notifies you rather than retrying indefinitely. A paused connection shows Paused on the companies page. Click Reconnect and complete the Google sign-in again to resume.

Troubleshooting

Cloud Overview

Where Google Workspace and Microsoft 365 data appears

Cloud Posture

How the Google Workspace posture score is calculated

Cloud Users

Browse every cloud identity across both platforms

Integrations Overview

Explore all available integrations