Skip to content
Avanet

Synchronize Sophos Email with Google Directory

Google Directory synchronization imports mailboxes, groups, and distribution lists from Google Workspace into Sophos Fusion (formerly Sophos Central). The connection has two distinct permission stages: a Google administrator first authorizes the connection; you then register the client ID and OAuth scopes displayed by Sophos in the Google Workspace Admin console. Enable filters and synchronize only after the connection test succeeds.

This feature is available when your license includes Sophos Email or Sophos Phish Threat. This guide covers only the directory source. It doesn’t change MX records or mail routing and doesn’t replace a Gateway or Mailflow setup.

Check the prerequisites

Before you begin, you need:

  • a Sophos Fusion administrator account permitted to configure directory sources;
  • a license that includes Sophos Email or Sophos Phish Threat;
  • a Google Workspace administrator account with administrative access to the workspace;
  • the exact Google domain name from Account > Domains > Manage domains;
  • permission to authorize an API client and its OAuth scopes in the Google Workspace Admin console;
  • where a Google Cloud organization policy is enforced, an administrator with the Organization Policy Administrator role.

Pay particular attention to the Google Cloud policy iam.disableServiceAccountKeyCreation. The service-account key creation policy is enabled by default for new Google Workspace accounts. If it remains enabled, the Google Directory connection can fail at about 80 percent.

Allow service-account key creation

Change the organization policy only with approval from the responsible Google Cloud owner. Removing this restriction is a security decision, not merely a Sophos setting.

  1. In the Google Cloud console, select the organization in the project picker.
  2. Open IAM & Admin > IAM and confirm that your account has the Organization Policy Administrator role. Edit the account and assign the role if necessary.
  3. Open IAM & Admin > Organization Policies and find Disable service account key creation, or iam.disableServiceAccountKeyCreation.
  4. Edit the policy, set Policy source to Inherit parent’s policy, and apply it with Set Policy.
  5. Retry the connection in Sophos Fusion.

If your organization can’t disable the policy, stop the setup. Sophos documents disabling it as necessary for successful synchronization.

Connect and authorize Google Directory

  1. Sign in to the Google Admin console and note the domain to synchronize under Account > Domains > Manage domains.
  2. In Sophos Fusion, open Global Settings > Platform > Directory service and select Add directory service.
  3. Enter a name and description, choose Google directory as the directory type, and enter the recorded domain.
  4. In Configure Google directory sync settings, read and accept the Google Apps Admin APIs and Google APIs terms.
  5. Select Connect, sign in with the responsible Google administrator account, and allow sophos.com the requested access. Continue only after Sophos confirms the connection.
  6. Copy the Client ID displayed in Sophos Fusion.
  7. Follow the provided link to the Google Workspace Admin console, add a new API client, and paste the client ID.
  8. Copy the OAuth scopes displayed by Sophos Fusion into the corresponding Google console field and authorize them.
  9. Return to Sophos Fusion and run Test connection. Save only after the test succeeds.

Always copy the client ID and OAuth scopes from your current Sophos Fusion session. Don’t use values from another environment or old documentation.

Select users and groups safely

Sophos provides three selection methods:

  • All users and groups synchronizes every user and group. For objects already present in Sophos Fusion, this is the recommended first selection because it gives the synchronization service the largest matching set.
  • Add users by group filter imports every user from groups that meet the filter criteria.
  • Add users by user filter directly imports users who meet the filter criteria.

For complex Google hierarchies, a user or group filter can be more appropriate before the first run. First decide whether all or any conditions must match. For each condition, choose the attribute, available operator, and comparison value. Additional conditions refine the result; logical groups create nested subsets.

A filter supports at most 10 binary conditions and no more than three nesting levels for AND/OR groups. You can’t add more filters after reaching either limit.

Important: Sophos Fusion can’t preview the changes that Google synchronization will make in Sophos Fusion. A successful connection test is not an object preview.

Changing a filter replaces the previous filter selection and can add or remove synchronized users and groups in Sophos Fusion. It doesn’t affect users and groups managed manually in Sophos Fusion. Record the target inventory and previous filter before changing any criteria.

Synchronize and verify the result

  1. Save the directory source and selected object scope.
  2. Select Turn on, followed by Synchronize.
  3. Wait for the synchronization run to finish.
  4. In Manage protection > People, check the connected users. With multiple domains, search by domain name.
  5. Also check My Environment > Users & Groups for the expected users and groups.

Compare the result with a target inventory rather than opening only a few sample accounts. Include mailboxes, groups, and distribution lists that matter to policies or mail operations. Record unexpected additions and removals before changing the filter again.

Change settings or add another domain

Before editing a connected source, disable synchronization with Turn off. You can then change settings such as its name, synchronization schedule, and user/group selection. Save the changes, enable the source again, run another synchronization, and compare the inventory again.

Sophos can reuse the existing account authorization for another domain in the same Google account:

  1. First confirm that a domain from that Google account is already connected, then note the additional domain name in Google.
  2. In Directory service, add another Google directory source and enter the additional domain.
  3. Select Connect, then Test connection and Save.
  4. Enable the source with Turn on and start Synchronize.
  5. In Manage protection > People, filter by the new domain and compare connected users with the target inventory.

Turn off, disconnect, or delete synchronization

These actions have different consequences. Choose the process that matches the intended outcome.

Pause or edit only

Use Turn off to stop runs or edit settings. Don’t purge data if the existing synchronized objects and policy assignments must remain.

Disconnect the source

Synchronization must be off before disconnection.

  1. Open the domain in Global Settings > Platform > Directory service and select Turn off.
  2. In Configure Google directory sync settings, select Disconnect, then Continue.
  3. Select the associated Google administrator account. Allow sophos.com the requested access and continue. This renewed consent lets Sophos clean up connection data from the Google Cloud service account.
  4. Wait for confirmation that disconnection has finished.

A data purge is optional for disconnection alone. Run it only when the synchronized mailbox data must actually be deleted.

Purge synchronized data

Warning: Purge data is irreversible. It deletes the synchronized data and the configuration of every policy linked to synchronized mailboxes. Neither can be restored.

Turn off the source, open More > Purge data, explicitly acknowledge that the action can’t be undone, and start the purge. Then confirm that the source status shows the data has been purged.

Permanently delete the directory source

You must purge a Google Directory source’s data before deleting the source. The deleted data and source can’t be restored.

  1. Record the source, synchronized objects, and linked policies, and obtain deletion approval.
  2. Turn off synchronization and run Purge data as described above.
  3. Disconnect the source using Disconnect. Use the Google administrator account to consent to connection-data cleanup and wait for confirmation.
  4. Only then select More > Delete and confirm Delete directory source.

Troubleshoot methodically

  • Google reports that access wasn’t granted: Retry Connect or Disconnect with the correct Google administrator account. Allow sophos.com the required access or select the corresponding consent option in Google’s dialog.
  • The connection fails near 80 percent with “Key creation is not allowed on this service account”: Check iam.disableServiceAccountKeyCreation. Have an Organization Policy Administrator disable the policy as described above, then test again.
  • Users or groups are missing after synchronization: Check whether user or group filters are active, whether all or any conditions must match, and whether each attribute, operator, and value matches the Google object.
  • Objects disappear after a filter change: This may be expected. The new filter replaces the previous selection and adjusts synchronized Sophos Fusion objects. Compare the old filter, new filter, and target inventory before synchronizing again.
  • The source won’t disconnect: First confirm that synchronization is off, then repeat the consent dialog with the connected Google administrator account.

Setup is complete only when the connection test succeeds, synchronization finishes, and the resulting users, groups, and distribution lists match the expected inventory. Repeat this complete comparison after every subsequent filter change.