Signing up with Google Identity / Google Workspace
Prerequisites
A Google Identity or Google Workspace account and a Google IAM Service Account.
Create a new Service Account
-
Visit https://console.cloud.google.com/iam-admin/serviceaccounts and select or create a project.
-
Click
Create Service Account -
Fill in the required service account details and click
Done
- Select the newly created service account, navigate to the
Keystab and clickAdd Key, selectJSONand save the key.
Key creation may be blocked by an organization policy
Google Cloud organizations created on or after May 3, 2024 enforce the
organization policy Disable service account key creation
(iam.managed.disableServiceAccountKeyCreation, formerly
iam.disableServiceAccountKeyCreation) by default. While it is enforced,
Add Key fails with Key creation is not allowed on this service account.
To lift it for this project only:
- Visit https://console.cloud.google.com/iam-admin/orgpolicies and select the project in the project picker.
- Open the
Disable service account key creationconstraint and clickManage policy. - Under
Applies tochooseOverride parent's policy, clickAdd a rule, setEnforcementtoOff, and clickSet policy.
Changing an organization policy requires the Organization Policy Administrator
role (roles/orgpolicy.policyAdmin), which is granted at the organization
level; a project owner alone cannot do this. Afterwards return to the Keys
tab and add the key.
-
Enable the
Admin SDK APIin the same Google Cloud project: visit https://console.cloud.google.com/apis/library/admin.googleapis.com, make sure the project that owns the service account is selected, and clickEnable.The Admin SDK API is disabled by default
Every new Google Cloud project starts with the Admin SDK API disabled, and Domain-Wide Delegation alone does not turn it on. As long as the API is disabled, the service account cannot reach the Workspace directory and the signup fails with an error similar to
Admin SDK API has not been used in project ... before or it is disabled. -
Under
API ClientsclickAdd new, paste the service account'sClient ID(visible on the service account's detail page in Google Cloud, or as theclient_idfield in the downloaded JSON file), add the following scopes, and clickAuthorize:https://www.googleapis.com/auth/admin.directory.group.readonlyhttps://www.googleapis.com/auth/admin.directory.user.readonly
- Pick (or create) a Google Workspace user with admin privileges sufficient
to read users and groups. You will enter this user's email address as the
Service Account Userduring signup — the service account does not have a Workspace identity itself, so it impersonates this admin user via Domain-Wide Delegation when calling the Admin SDK.
Sign Up
-
Fill in the email address of the Workspace admin user from the previous step as the
Service Account User, and upload the downloaded JSON key file as theService Account Config. -
Click the Signup button.
-
Follow the Google login process.
-
You are now signed in to the XplicitTrust Admin Console:
https://console.xplicittrust.com/
Why is a Google IAM Service Account required?
To allow XplicitTrust to query the isAdmin attribute and the group membership
of users as well as fetching existing user groups for the group import, a service
account has to be created that has the following scopes from the
Admin SDK API :
| Scope | Description | Reason |
|---|---|---|
https://www.googleapis.com/auth/admin.directory.group.readonly |
Read group information. | Required by the User Groups Import feature, that allows to import groups from the Google Directory to be used in XplicitTrust Policies. |
https://www.googleapis.com/auth/admin.directory.user.readonly |
Read user information. | Required to read the users isAdmin attribute, that indicates a user with administrator privileges. |