Synchronize Google Workspace with Sophos Central
Sophos Central can import mailboxes, users, groups, and distribution lists from Google Workspace. The Google Directory source is primarily intended for Sophos Email and Sophos Phish Threat and is available only with a suitable license.
Synchronization is more than an address-book copy. Filter changes can affect objects and policy assignments, some OAuth permissions remain necessary for ongoing operation, and a purge can irreversibly delete linked configuration.
Prerequisites
Setup requires:
- a Sophos Email or Phish Threat license,
- a Sophos Central administrator role with Directory Service access,
- a Google Workspace administrator with the required permissions,
- the primary or secondary Google domain to synchronize,
- an agreed filter for users and groups,
- a change and rollback plan.
In newer Google Workspace environments, the organization policy iam.disableServiceAccountKeyCreation can block creation of service-account keys. When enabled, the Central connection may stop at about 80 percent and report Key creation is not allowed on this service account.
To permit setup, first select the organization in Project Picker in Google Cloud Console. Under IAM & Admin > IAM, the acting account needs Organization Policy Administrator. Then go to IAM & Admin > Organization Policies, search for Disable service account key creation, open Edit policy, select Inherit parent’s policy as Policy source, and save with Set Policy. This changes an organization-wide security control and requires documented approval.
Inventory existing objects first
Before the first sync, export or document existing users, mailboxes, and groups under My Environment > Users & Groups or in the Email context. Unique primary email addresses are essential.
Review in particular:
- manually created users with the same email address,
- shared mailboxes and aliases,
- nested or dynamic groups,
- disabled and external accounts,
- existing Email policies and group links.
Do not run one source in parallel with another for the same objects without testing matching behavior. AD, Entra ID, and Google Directory serve different purposes and must not be combined blindly.
Connect Google Directory
First record the exact domain name under Account > Domains > Manage domains in Google Admin Console. Then go to Global Settings > Platform > Directory service > Add directory service in Central.
- Enter a name and description, select Google directory as Directory type, enter the recorded domain, and select Next.
- Under Configure Google directory sync settings, read the Google Apps Admin APIs Terms of Service and Google APIs Terms of Service, then select Accept.
- Select Connect, choose the approved Google administrator account, allow the requested access for
sophos.com, and select Continue. Close the dialog with Close after connection is confirmed. - Copy the displayed Client ID in Central and open the linked Google Workspace Admin console.
- In domain-wide delegation, select Add new and insert the Client ID.
- Return to Central, copy the OAuth scopes displayed for this tenant, paste them into Google, and approve with Authorise.
- Run Test connection in Central and confirm a successful test with OK.
- Under Select users and groups to include in the synchronization, choose a controlled filter and save with Save.
Understand Google permissions
In the Google consent dialog, Sophos currently requests https://www.googleapis.com/auth/cloud-platform to create, read, update, or validate the required Google Cloud resources during setup. https://www.googleapis.com/auth/userinfo.email identifies the Google administrator account granting consent. Both permissions can be requested by Google Directory, Google Post-Delivery Protection, and Google Direct Delivery.
Some permissions are used only for setup and validation; others remain active while the connection is turned on. If a required permission is removed in Google, the related Sophos feature does not work again until it is reconnected.
Build filters safely
Central can synchronize all users and groups, a group filter, or a user filter. For a manageable, clean directory, a complete first sync is often the best basis for correct matching. For very large or heterogeneous directories, begin with a filtered pilot group instead.
Design filters around stable organizational attributes, such as a defined Google group. Names, country fields, or time conditions can change and unexpectedly remove objects from scope. Central supports at most ten binary conditions and three levels of nested AND/OR groups.
Before saving, export the expected inventory from Google or document it from a defined pilot group. After the run, compare the count and a sample of added and removed objects against that target list.
Synchronize all Google users and groups
Under Global Settings > Platform > Directory service, open the Google source. In Select users and groups to include in the synchronization, select All users and groups, then choose Turn on and Synchronize. Compare the result under My Environment > Users & Groups with the previous inventory.
This option offers the largest matching set for the first run. It does not replace planned scope: after controlled reconciliation, exclude unneeded accounts with a stable filter.
Select Google users with a group filter
Under Select users and groups to include in the sync > Add users by group filter, first decide whether any or all conditions and groups must match. Then select the primary condition, an operator supported for that attribute, and the comparison value. For Last directory sync time, for example, the available operators are is, greater or equal, and less or equal.
Add condition refines the results. Add group creates a nested subset of already matched users. A filter can, for example, combine users whose last Directory Sync is before a current cutoff date, who have a proxy address, and whose display name begins with Admin. Do not reuse an old Sophos example date without review.
Switching to this filter replaces the previous filter definition. After Turn on > Synchronize, review added and removed users and groups under My Environment > Users & Groups.
Select Google users with a user filter
Add users by user filter works directly with user attributes. After selecting any or all, choose the primary condition, permitted operator, and comparison value. A clear example is Country is Germany; some attributes also support starts with.
With Add condition and Add group, selection can be restricted to German users whose display name begins with Admin. The limit remains ten binary conditions and three nesting levels. Turn on > Synchronize activates the new inventory, which is then compared with the target list under My Environment > Users & Groups.
Connect another domain from the same Google account
An already authorized Google connection can be reused for another domain belonging to the same Google account. First verify the additional domain under Google Admin > Account > Domains > Manage domains. Then create another Google directory source under Global Settings > Platform > Directory service, enter that domain, and select Connect.
Central reuses the existing Google authorization. Still run Test connection, Save, Turn on, and a manual Synchronize separately. Under Manage protection > People, filter a sample by the new domain. A second source does not replace clean domain and object uniqueness.
Validate the first sync
After Save, activate the source with Turn on and run it for the first time with Synchronize. After completion, review connected users under Manage protection > People.
Do not check only Successful and the object count after the manual run. Sample:
- primary email address and display name,
- group membership,
- shared mailbox or user object,
- expected Email or Phish Threat policy,
- no newly created duplicates,
- no unintended external or disabled accounts.
Then define the schedule and include failed runs in the operational alert process.
Changes and disconnect
Turn synchronization off before changing the domain, filters, or schedule. Save, enable it again, and run a manual test.
Disconnect removes the Google authorization. First turn sync off, then disconnect under Configure Google directory sync settings. In the Google dialog, grant sophos.com the required consent once more so Sophos can clean up connection data in the Google service account. Also review third-party permissions in Google Admin Console. Disconnect is not the same as purging synchronized data.
To delete the source entirely, first review and, where necessary, purge its data. Then select Turn off, Disconnect, grant Google consent for cleanup, and choose More > Delete > Delete directory source. Neither the source nor purged data can be recovered.
Change a Google source
Open the Google source under Global Settings > Platform > Directory service and stop it with Turn off before every change. Then edit the domain, name, synchronization schedule, and user or group selection. Save with Save and enable it again with Turn on. Complete the change with a manual Synchronize and a review under Manage protection > People or My Environment > Users & Groups.
Disconnect Google
For a disconnect without deletion, turn the source off and select Disconnect under Configure Google directory sync settings. Alternatively, More > Delete > Disconnect now enters the same cleanup flow. After Continue, choose the Google administrator account, approve the access sophos.com needs for cleanup, and select Continue. Close the dialog with Close when Google confirms disconnection. Existing synchronized Central data has not yet been purged.
Delete a Google Directory source
A Google source can be deleted only after its synchronized data has been purged or the purge has completed in the deletion flow. Open the source name under Global Settings > Platform > Directory service and select Turn off.
Then disconnect through Configure Google directory sync settings > Disconnect or More > Delete > Disconnect now. Continue starts cleanup. In the Google dialog, select the authorized administrator account, approve access for sophos.com, and select Continue. Close with Close after disconnection is confirmed.
Back in Central, select More > Delete > Delete directory source. A deleted source and previously purged data cannot be recovered. Also review the domain-wide delegation and unneeded permissions configured in Google and remove them after approval.
Purge only with approval
To purge a source, open it under Global Settings > Platform > Directory service and stop it with Turn off. Then select More > Purge data, acknowledge that the purge cannot be undone, and select Purge data again. The source status then shows that its data has been purged.
The operation cannot be undone. Sophos warns that it also deletes policy configurations linked to synchronized mailboxes.
Before a purge, document configuration, groups, policy assignments, affected mailboxes, and reconstruction. Do not use purge as the first troubleshooting step.
Common problems
Connection test fails immediately
Check the domain, Google administrator account, Client ID, authorized scopes, and the organization policy for service-account keys. If the dialog says access to Google Cloud data was not granted, sophos.com did not receive complete consent. A browser sign-in alone does not prove domain-wide API authorization.
Sync succeeds, but objects are missing
Check filters, primary email addresses, group nesting, and disabled accounts. Then verify that the license and function support the expected object types.
Users appear twice
Primary email addresses or existing manual objects usually do not match. Do not delete duplicates indiscriminately. First determine which source should own the object and which policy links exist.
Connection fails after months
Check Google OAuth consent, removed third-party permissions, changed administrator accounts, and Central status. A new full sync without root-cause analysis can make the data state worse.
Frequently asked questions
Can Google Directory synchronize without Sophos Email or Phish Threat?
The current function requires a Sophos Email or Phish Threat license. AD or Entra ID sources are generally more suitable for Endpoint users.
The separate operating models are explained in Synchronize Active Directory with Sophos Central and Synchronize Microsoft Entra ID with Sophos Central. Define one authoritative source for each user inventory instead of importing the same identities from multiple directories.