For the complete documentation index, see llms.txt. This page is also available as Markdown.

Google Workspace Identity Provider & Access Review Integration

Learn how to integrate Google Workspace with Sprinto for Identity Provider (SSO) and Access Review to automate user management, audit tracking, and compliance monitoring.

The Google Workspace integration in Sprinto enables you to connect your organisation’s directory and audit systems to automate identity management and access governance.

This integration serves two core purposes:

  • Identity Provider (IdP): Sync users, groups, and organisational structure from Google Workspace into Sprinto.

  • Access Review: Monitor user access, audit activity, and security events for compliance frameworks such as SOC 2 and ISO 27001.

By combining identity and audit data, Sprinto provides continuous visibility into user access, detects compliance gaps, and ensures timely remediation.


How It Works

The integration operates across two layers: identity management and access monitoring.

Identity Provider (SSO and User Sync)

Sprinto connects to Google Workspace using the Cloud Identity and Admin SDK APIs to:

  • Fetch and sync users, groups, and organisational units.

  • Map users to Sprinto’s People module.

  • Enable SSO configurations using SAML 2.0 or OIDC.

  • Track user lifecycle changes such as onboarding and offboarding.

Supported SSO protocols include:

  • SAML 2.0: Uses Entity ID, SSO URL, and X.509 certificates for authentication.

  • OIDC (OpenID Connect): Uses client credentials and OAuth-based authentication flows.

Access Review (Audit and Security Monitoring)

Sprinto uses Google Workspace audit and reporting APIs to:

  • Track login activity, admin actions, and OAuth usage.

  • Monitor access across applications such as Drive, Gmail, and Calendar.

  • Identify inactive users or policy violations.

  • Support access reviews and compliance checks.

Audit data is sourced from:

  • Login and admin activity logs.

  • OAuth token usage.

  • Device and access evaluation logs.

  • Security alerts and investigation data.

Sprinto checks for Google Workspace

Here's a list of Sprinto checks available for Google Workspace integration, along with reference procedures on how to fix them:

Sprinto check
Description
Reference procedure

Staff role should be assigned

All in-scope staff members must have an assigned staff role.

Reporting manager should be assigned

All in-scope staff members should have an assigned reporting manager. Note: Top management roles like CEO, CTO, etc. are exceptions.

Date of joining for new staff should be provided

Define the joining date for all newly onboarded staff members.

Google Workspace user should have MFA enabled

All in-scope staff members should enable Multi-Factor Authentication configured on their Google Workspace user account.

Permissions and Data Access

Sprinto requires specific permissions to enable identity sync and access monitoring.

Identity Provider Permissions

These permissions enable user and SSO management:

  • Read user directory information.

  • Read group and organisational unit data.

  • Configure inbound SSO settings (SAML/OIDC).

Access Review Permissions

These permissions enable audit and monitoring:

  • Read audit logs (login, admin, token activity).

  • Access security alerts.

  • Retrieve device and access-related information.

  • View user and group activity.

Data Collected by Sprinto

Sprinto collects the following data:

  • User details: name, email, status.

  • Group memberships.

  • Organisational unit mapping.

  • Login and activity logs.

  • OAuth and token usage.

  • Security alerts and audit events.


Prerequisites

Ensure the following requirements are met before setting up the integration:

Access Requirements

  • You must have Super Admin access to your Google Workspace account.

  • Alternatively, use a custom admin role with:

    • User management permissions.

    • Group management permissions.

    • SSO configuration access.

    • Security and reporting access.

Google Workspace Requirements

  • Google Workspace must be active and properly configured.

  • Required APIs must be enabled:

    • Admin SDK

    • Reports API

    • Cloud Identity API

    • Alert Center API (for security alerts)

Plan Requirements

  • Access to advanced audit logs and investigation tools may require:

    • Enterprise Standard or Enterprise Plus

    • Cloud Identity Premium

    • Equivalent supported editions


Setup Instructions

Follow these steps to connect Google Workspace with Sprinto:

  1. Log in to the Sprinto dashboard.

  2. Navigate to Settings → Integrations.

  3. In the All tab, search for Google Workspace.

  4. Click Connect next to Google Workspace.

  1. In the integration drawer, click Connect for Identity Provider & Access Review.

  1. Review the following:

    • Controls and checks enabled

    • Permissions required

    • Data accessed by Sprinto.

  2. Click Next.

  1. In the setup screen:

    1. Review connection type (OAuth).

    2. Confirm prerequisites.

  2. Click Connect Google Workspace.

  1. In the Google OAuth window:

    1. Select your admin account.

    2. Sign in if required.

    3. Review requested permissions.

    4. Click Allow.

Once authorised, the integration is successfully established.


Post-Connection Flow

After successful integration:

  • Initial Sync: Sprinto performs an initial sync of users and groups within 15–20 minutes.

  • Continuous Monitoring: Audit logs and access data are continuously ingested.

  • User Mapping: Users are mapped to the People module for compliance checks.

  • Access Reviews: Access review workflows are enabled using synced user and audit data.

  • Compliance Checks: Sprinto automatically evaluates controls related to:

    • User access management.

    • Inactive users.

    • Access removal on offboarding.


Troubleshooting

1. OAuth Authentication Fails

  • Ensure you are using a Super Admin account.

  • Verify that third-party app access is not restricted in Google Workspace.

2. Insufficient Permissions

  • Confirm required admin roles are assigned:

    • User management

    • Security and reporting

    • SSO configuration

3. Missing Audit Data

  • Ensure your Google Workspace plan supports audit logs.

  • Some logs (Drive, Gmail, device activity) require higher-tier plans.

4. Integration Errors (400 or API Issues)

  • Check if required APIs are enabled in Google Cloud Console.

  • Verify API access is not restricted by organisation policies.

5. Sync Delays

  • Initial sync may take up to 20 minutes.

  • Large directories may take longer to fully process.


Support

Please contact Sprinto Support If you have any queries related to the integration or need any assistance.

Last updated