Feature
Connect your email provider before you set up anything else in SaaS Management. Nothing else works until identities are syncing.
The two providers are not equivalent today:
Google Workspace |
Microsoft Entra ID |
|
|---|---|---|
Identity sync |
Yes |
Yes |
Automated provisioning |
Yes |
Yes |
SaaS discovery |
Yes |
Not yet available |
Data transfer at offboarding |
Yes |
No |
Mac login with directory credentials |
No |
Yes |
If you use Entra ID and need SaaS discovery, install the Chrome Extension instead — see Activate SaaS Discovery.
How to use — Google Workspace
- Go to Settings > Integrations and select Google Workspace.
- Sign in with a Super Administrator account. Anything less cannot grant the permissions required.
- Authorise the scopes. Read access covers users, groups, and org units. Write access covers provisioning and offboarding actions.
- Launch the first sync. Users and groups import, and SaaS mapping starts on its own.
What connecting Google Workspace gives you:
- SaaS discovery — detects every app accessed with Google sign-in across the organisation
- Identity sync — imports users and groups
- Automated provisioning — creates, updates, and suspends accounts as part of onboarding and offboarding
- Data transfer at offboarding — moves Drive file and email ownership when someone leaves
What is accessed in Google Workspace:
Data |
Purpose |
|---|---|
Users (name, email, status) |
Identity sync and provisioning |
Groups and org units |
Applying provisioning rules |
OAuth app access |
SaaS discovery mapping |
Drive (at offboarding only) |
Transferring file ownership |
How to use — Microsoft Entra ID
- Go to Settings > Integrations and select Microsoft Entra ID.
- Sign in as a Global Administrator, or with a delegated admin role that holds the required API permissions.
- Grant the Microsoft Graph permissions. These cover reading and writing users, groups, and directory data.
- Launch the first sync. Users and groups import from the tenant.
What connecting Entra ID gives you:
- Identity sync — imports users and groups from the tenant
- Automated provisioning — creates, updates, and disables accounts during onboarding and offboarding
- Mac login with Entra credentials — lets employees sign in to their Mac with their directory account (see Entra Platform SSO)
What is accessed in Entra ID:
Data |
Purpose |
|---|---|
Users (name, email, status, attributes) |
Identity sync and provisioning |
Groups |
Applying provisioning rules |
Application assignments |
SaaS visibility |
Tips and Best Practices
- Connect the provider before you build onboarding or offboarding flows. Those flows act on synced identities, so an empty directory makes them do nothing.
- Use a service account for the Super Admin or Global Admin sign-in, not a personal one. The connection breaks when the person who authorised it leaves.
- Review the scopes with your security team before authorising. Write access to your directory is what makes provisioning and offboarding work, and it is easier to explain in advance than after the fact.
Troubleshooting and FAQ
Troubleshooting
-
The sign-in is rejected or the scopes cannot be granted.
The account is not a Super Administrator (Google Workspace) or a Global Administrator (Entra ID). A delegated admin role works for Entra only if it carries the required API permissions.
-
No SaaS apps are discovered after connecting Entra ID.
This is expected. SaaS discovery through Entra is not available yet — use the Chrome Extension for coverage.
FAQ
- Can I connect both providers?
Each one covers a different set of capabilities. Compare them in the table above and connect the one that matches what you need.
-
Why does the connection need write access?
Provisioning creates and updates accounts, and offboarding suspends or disables them. Read-only access supports the directory listing but none of the automation.
-
How soon do users appear after connecting?
The first sync imports users and groups straight away. With Google Workspace, SaaS mapping then starts on its own.