Back

Connect your email provider

Connecting Google Workspace or Microsoft Entra ID is the first step to using SaaS Management. It turns on user provisioning, SaaS discovery, and — combined with offboarding — automatic access revocation.

Feature

Connect your email provider before you set up anything else in SaaS Management. Nothing else works until identities are syncing.

The two providers are not equivalent today:

 

Google Workspace

Microsoft Entra ID

Identity sync

Yes

Yes

Automated provisioning

Yes

Yes

SaaS discovery

Yes

Not yet available

Data transfer at offboarding

Yes

No

Mac login with directory credentials

No

Yes

If you use Entra ID and need SaaS discovery, install the Chrome Extension instead — see Activate SaaS Discovery.


 

How to use — Google Workspace

  1. Go to Settings > Integrations and select Google Workspace.
  2. Sign in with a Super Administrator account. Anything less cannot grant the permissions required.
  3. Authorise the scopes. Read access covers users, groups, and org units. Write access covers provisioning and offboarding actions.
  4. Launch the first sync. Users and groups import, and SaaS mapping starts on its own.

What connecting Google Workspace gives you:

  • SaaS discovery — detects every app accessed with Google sign-in across the organisation
  • Identity sync — imports users and groups
  • Automated provisioning — creates, updates, and suspends accounts as part of onboarding and offboarding
  • Data transfer at offboarding — moves Drive file and email ownership when someone leaves

What is accessed in Google Workspace:

Data

Purpose

Users (name, email, status)

Identity sync and provisioning

Groups and org units

Applying provisioning rules

OAuth app access

SaaS discovery mapping

Drive (at offboarding only)

Transferring file ownership


 

How to use — Microsoft Entra ID

  1. Go to Settings > Integrations and select Microsoft Entra ID.
  2. Sign in as a Global Administrator, or with a delegated admin role that holds the required API permissions.
  3. Grant the Microsoft Graph permissions. These cover reading and writing users, groups, and directory data.
  4. Launch the first sync. Users and groups import from the tenant.

What connecting Entra ID gives you:

  • Identity sync — imports users and groups from the tenant
  • Automated provisioning — creates, updates, and disables accounts during onboarding and offboarding
  • Mac login with Entra credentials — lets employees sign in to their Mac with their directory account (see Entra Platform SSO)

What is accessed in Entra ID:

Data

Purpose

Users (name, email, status, attributes)

Identity sync and provisioning

Groups

Applying provisioning rules

Application assignments

SaaS visibility


 

Tips and Best Practices

  • Connect the provider before you build onboarding or offboarding flows. Those flows act on synced identities, so an empty directory makes them do nothing.
  • Use a service account for the Super Admin or Global Admin sign-in, not a personal one. The connection breaks when the person who authorised it leaves.
  • Review the scopes with your security team before authorising. Write access to your directory is what makes provisioning and offboarding work, and it is easier to explain in advance than after the fact.

 

Troubleshooting and FAQ

Troubleshooting

  • The sign-in is rejected or the scopes cannot be granted. 
    The account is not a Super Administrator (Google Workspace) or a Global Administrator (Entra ID). A delegated admin role works for Entra only if it carries the required API permissions.
     
  • No SaaS apps are discovered after connecting Entra ID. 
    This is expected. SaaS discovery through Entra is not available yet — use the Chrome Extension for coverage.

FAQ

  1. Can I connect both providers?
    Each one covers a different set of capabilities. Compare them in the table above and connect the one that matches what you need.
     
  2. Why does the connection need write access?
    Provisioning creates and updates accounts, and offboarding suspends or disables them. Read-only access supports the directory listing but none of the automation.
     
  3. How soon do users appear after connecting?
    The first sync imports users and groups straight away. With Google Workspace, SaaS mapping then starts on its own.

Was this article helpful?

Give feedback about this article

Can’t find what you’re looking for?

Our customer care team is here for you.

Contact us

Knowledge Base Software powered by Helpjuice