Skip to main content

Configure Connection

Google Workspace guide

Follow this focused guide to configure and validate Google Workspace in NIM.

Platform referencesDirect link to Platform references

For Google Workspace requirements outside NIM, review Google's domain-wide delegation guidance. Review the authorized client and scopes regularly, and limit delegated scopes to the Google Workspace data and operations your NIM implementation uses.

What you needDirect link to What you need

To connect NIM to Google Workspace, create a Google Cloud project and service account, download its P12 key, authorize that service account through Google Workspace domain-wide delegation, and add the P12 certificate to NIM. You also need the Google Workspace customer ID and an administrator account with the required roles for the Directory (Tenant) ID.

Success looks like this: after saving the Google system in NIM, Test Connection returns a success message. You can then collect the system and confirm the tables needed by your workflow are available.

Create the NIM system and Google Cloud service accountDirect link to Create the NIM system and Google Cloud service account

  1. Go to Systems > Overview.

  2. Click Add.

  3. Select Google for System Type.

  4. Enter a System Name.

  5. Click Save.

  6. The new system is added to the Configured Systems pane.

  7. In a new tab, open the Google Cloud console.

  8. Create a new project named NIM and switch to it.

  9. Open Cloud Shell

  10. Run these commands in Cloud Shell to enable the required Google APIs:

    gcloud services enable admin.googleapis.com
    gcloud services enable groupssettings.googleapis.com
    gcloud services enable licensing.googleapis.com
    gcloud services enable drive.googleapis.com
    gcloud services enable gmail.googleapis.com
    gcloud services enable classroom.googleapis.com
  11. Expand the menu and go to APIs & Services > OAuth Consent Screen.

  12. Select the Internal user type and click Create. Enter NIM for the App Name. Enter a relevant User Support Email and Developer Email Address. Click Save And Continue.

  13. On the Scopes page, click Save And Continue.

  14. On the Summary page, click Back To Dashboard.

  15. Expand the menu and go to APIs & Services > Credentials.

  16. Click Create Credentials > Service Account.

  17. For the Service Account Name, enter NIM. Accept the default generated Service Account ID value. Click Create and Continue. Click Done.

  18. Click the pencil icon to edit the newly created NIM service account. On the Details tab, Copy the Email and Unique ID to a local text editor application.

  19. Go to the Keys tab. Click Add Key > Create New Key. Select P12. Click Create. The .p12 file is downloaded. Copy the Private Key Password (notasecret) to a local text editor application. Click Close.

Authorize domain-wide delegationDirect link to Authorize domain-wide delegation

  1. Open the Google Admin console.
  2. Go to Security > Access > API Controls.
  3. Click Manage Domain-Wide Delegation.
  4. Click Add New.
  5. Paste the Unique ID you copied earlier into the Client ID field.
  6. In the OAuth Scopes (Comma-Delimited) field:
https://www.googleapis.com/auth/admin.datatransfer,https://www.googleapis.com/auth/admin.datatransfer.readonly,https://www.googleapis.com/auth/admin.directory.device.chromeos,https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly,https://www.googleapis.com/auth/admin.directory.device.mobile,https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,https://www.googleapis.com/auth/admin.directory.group,https://www.googleapis.com/auth/admin.directory.group.readonly,https://www.googleapis.com/auth/admin.directory.orgunit,https://www.googleapis.com/auth/admin.directory.orgunit.readonly,https://www.googleapis.com/auth/admin.directory.rolemanagement,https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly,https://www.googleapis.com/auth/admin.directory.user,https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.user.security,https://www.googleapis.com/auth/admin.directory.userschema,https://www.googleapis.com/auth/apps.groups.settings,https://www.googleapis.com/auth/apps.licensing,https://www.googleapis.com/auth/classroom.courses,https://www.googleapis.com/auth/classroom.courses.readonly,https://www.googleapis.com/auth/classroom.guardianlinks.students,https://www.googleapis.com/auth/classroom.guardianlinks.students.readonly,https://www.googleapis.com/auth/classroom.rosters,https://www.googleapis.com/auth/classroom.rosters.readonly,https://www.googleapis.com/auth/drive,https://www.googleapis.com/auth/drive.readonly,https://www.googleapis.com/auth/gmail.settings.basic,https://www.googleapis.com/auth/gmail.settings.sharing,https://www.googleapis.com/auth/gmail.readonly,https://www.googleapis.com/auth/gmail.labels
  1. Click Authorize. The new OAuth application is added with the scopes.
  2. Go to Account > Account Settings > Copy Customer ID

Add the certificate and validate the connectionDirect link to Add the certificate and validate the connection

  1. Return to your NIM browser tab. Add a certificate using the .p12 certificate you downloaded earlier, and the password you copied (notasecret). Name the certificate Google.

  2. In NIM, edit the Google system you created previously. See Edit or remove a system.

  3. For the Application (Client) ID, paste the service account Email you copied previously. For the Directory (Tenant) ID, enter the email address you use to log in to Google Cloud Platform. For the Certificate, select the Google certificate you just added. For Customer ID, paste the Customer ID you copied previously.

Required Google Workspace roles

The account used for the Directory (Tenant) ID must have User Management Admin and Groups Admin (built-in roles), plus License Admin (a role you create) in your Google Workspace tenant.

  1. Click Save.
  2. Click Test Connection. A success message is returned.