Skip to content

Signing up with Google Identity / Google Workspace

Prerequisites

A Google Identity or Google Workspace account and a Google IAM Service Account.

Create a new Service Account

Create Service Account Screen

  • Select the newly created service account, navigate to the Keys tab and click Add Key, select JSON and save the key.

Add Key Screen

Key creation may be blocked by an organization policy

Google Cloud organizations created on or after May 3, 2024 enforce the organization policy Disable service account key creation (iam.managed.disableServiceAccountKeyCreation, formerly iam.disableServiceAccountKeyCreation) by default. While it is enforced, Add Key fails with Key creation is not allowed on this service account. To lift it for this project only:

  • Visit https://console.cloud.google.com/iam-admin/orgpolicies and select the project in the project picker.
  • Open the Disable service account key creation constraint and click Manage policy.
  • Under Applies to choose Override parent's policy, click Add a rule, set Enforcement to Off, and click Set policy.

Changing an organization policy requires the Organization Policy Administrator role (roles/orgpolicy.policyAdmin), which is granted at the organization level; a project owner alone cannot do this. Afterwards return to the Keys tab and add the key.

  • Enable the Admin SDK API in the same Google Cloud project: visit https://console.cloud.google.com/apis/library/admin.googleapis.com, make sure the project that owns the service account is selected, and click Enable.

    The Admin SDK API is disabled by default

    Every new Google Cloud project starts with the Admin SDK API disabled, and Domain-Wide Delegation alone does not turn it on. As long as the API is disabled, the service account cannot reach the Workspace directory and the signup fails with an error similar to Admin SDK API has not been used in project ... before or it is disabled.

  • Visit https://admin.google.com/ac/owl/domainwidedelegation

  • Under API Clients click Add new, paste the service account's Client ID (visible on the service account's detail page in Google Cloud, or as the client_id field in the downloaded JSON file), add the following scopes, and click Authorize:

    • https://www.googleapis.com/auth/admin.directory.group.readonly
    • https://www.googleapis.com/auth/admin.directory.user.readonly

Add New API Client Screen

  • Pick (or create) a Google Workspace user with admin privileges sufficient to read users and groups. You will enter this user's email address as the Service Account User during signup — the service account does not have a Workspace identity itself, so it impersonates this admin user via Domain-Wide Delegation when calling the Admin SDK.

Sign Up

Sign Up Screen

  • Fill in the email address of the Workspace admin user from the previous step as the Service Account User, and upload the downloaded JSON key file as the Service Account Config.

  • Click the Signup button.

  • Follow the Google login process.

  • You are now signed in to the XplicitTrust Admin Console:
    https://console.xplicittrust.com/

Why is a Google IAM Service Account required?

To allow XplicitTrust to query the isAdmin attribute and the group membership of users as well as fetching existing user groups for the group import, a service account has to be created that has the following scopes from the Admin SDK API :

Scope Description Reason
https://www.googleapis.com/auth/admin.directory.group.readonly Read group information. Required by the User Groups Import feature, that allows to import groups from the Google Directory to be used in XplicitTrust Policies.
https://www.googleapis.com/auth/admin.directory.user.readonly Read user information. Required to read the users isAdmin attribute, that indicates a user with administrator privileges.