Connect Google Workspace
Authorize Elba for Google Workspace using domain-wide delegation.
Connecting Google Workspace lets Elba import your organization’s users and enable the Google capabilities available to your workspace.
Administrator required
Complete this flow with a Google Workspace Super Admin. Only a Super Admin can grant domain-wide delegation.
Authorize Elba
- Start the Google Workspace connection from Elba onboarding or Settings → Integrations.
- Select Authorize. Elba opens Google Admin Console in a new tab and keeps the authorization step open.
- In Elba, copy the client ID and OAuth scopes displayed for your workspace.
- In Google Admin Console, add a new domain-wide delegation entry using those exact values.
- Save the entry, return to Elba, and continue the authorization step.
- Wait for Elba to confirm authorization and complete the first user import.
Do not copy client IDs or scopes from screenshots or old documentation. The in-product values are the source of truth for your region and environment.
See OAuth scopes and permissions for the current Google grants split by sign-in, directory synchronization, security source, phishing simulations, and Google Chat.
Verify the connection
- The onboarding authorization step completes without an admin-policy error.
- Users begin appearing in Elba after the initial synchronization.
- The Google Workspace integration reports as connected under Settings → Integrations.
Connect Google Chat
Google Chat has its own connection and authorization step. A connected Google Workspace directory does not mean Google Chat is connected. You need an owner or administrator role in Elba and a Google Workspace administrator account to start; a Workspace super administrator must approve the delegated access in Google when required.
- Open Settings → Integrations → Google Chat, or select Google Chat in Communications and use Connect Google Chat.
- When Google asks which account to use, choose the administrator account for the intended Workspace.
- If Elba shows One step left in Google, use Authorize access. The Google Admin console opens with the application's client ID and permissions filled in. The Workspace super administrator reviews and approves that entry according to your organization's policy.
- Keep the Elba page open. From that click, Elba checks whether Google has accepted the authorization and then shows Connected. If the approval was completed earlier or the Elba page was closed, use Authorize access again to check it.
- To make Google Chat the default employee communication channel, finish and save the Communications setup separately. Connecting the integration alone does not switch your current channel.
Cancel closes the integration dialog. Closing Communications before completing the setup leaves the saved default channel unchanged.
Recover a stopped Google Chat connection
The explanation stays in the dialog until you close it, including after a reload. Follow the named step rather than repeating the whole setup:
| Explanation | Next step |
|---|---|
| The Google sign-in was not completed | Start again in one tab. The earlier sign-in may have been canceled, expired or replaced by another tab. |
| Google did not grant a permission Elba asked for | Review the directory permissions Google lists and accept them if your organization's policy permits. Elba uses the directory to check your administrator account. |
| This Google account was not recognized as a Workspace administrator | Start again with the intended Google Workspace administrator account. An Elba owner or administrator role does not establish Google Workspace privileges. |
| Google did not answer | Try again in a few minutes. Google returned an error or was too busy during the check. |
| This Google Workspace is already connected to another Elba organization | Contact Elba support or manage the existing Google Chat connection in the other organization. A Workspace can be connected in one Elba organization at a time. |
| Google Chat could not be connected | Retry once. If it stops again, contact Elba support and include the displayed reference when one is available. Your current communication channel is unchanged. |
Google refused a request from Elba shows the date of a recorded refusal for an already authorized connection. It does not mean every request has failed since that date. Use Reconnect with a Workspace administrator account; if the refusal returns, contact Elba support.
An authorization step can remain pending if Google Workspace policy refuses delegated access. The recovery route does not override that policy or establish that Google Chat can deliver messages. Keep your working channel until the connection is confirmed and you choose to save a different default.
Troubleshooting
If Google displays 400: admin_policy_enforced, see Resolve Google Workspace “admin policy enforced” errors.
If authorization still fails, confirm that you are signed in with the intended Google Workspace tenant and that the delegation entry contains the exact client ID and scopes displayed by Elba.