How to Set Up SCIM Provisioning in Okta for Google Workspace
Provisioning connects Okta to Google Workspace so accounts follow your roster automatically. A new hire assigned in Okta gets their Gmail, Drive, and Calendar account without anyone opening the Google Admin console, and a departure is deactivated in both systems with one action. The setup:
- Authenticate Okta's prebuilt Google Workspace integration with a Google admin account
- Turn on Create Users, Update User Attributes, and Deactivate Users
- Assign people or groups and let Okta run the account lifecycle from there
Verified against Okta's Google Workspace provisioning documentation on 2026-09-11.
One naming note: Okta provisions many apps over the SCIM protocol, but its Google Workspace integration does the same lifecycle work through Google's own APIs. The admin experience and the result are identical, so the steps below are what you are looking for either way.
Prerequisites
- The Google Workspace app added to your Okta org from the Okta Integration Network, ideally with SSO already working
- A Google Workspace admin account for the API connection. Okta recommends a dedicated system account, so provisioning keeps working when a specific person leaves
- Okta admin access with rights to configure applications
The configuration is identical at 5 people and at 120. Best practice is to wire provisioning in from day one, and if your team has been creating Google accounts by hand, these same steps retire that chore now.
Step 1: Open the Provisioning Settings
- In the Admin Console, go to Applications → Applications.
- Open your Google Workspace app instance.
- Go to the Provisioning tab and click Configure API Integration.
Step 2: Authenticate with Google Workspace
- Select Enable API integration, then click Authenticate with Google Workspace.
- Select the Google admin account to use for authentication, or enter its username and password, and click Next.
- Review the list of permissions Google grants Okta and click Allow.
- Back on the Provisioning tab, click Save.
Step 3: Turn On the Provisioning Features
- On the Provisioning tab, click To App under Settings.
- Click Edit in the Provisioning to App section.
- Enable Create Users, Update User Attributes, and Deactivate Users.
- Click Save.
Deactivating a user in Okta sets their Google account to inactive rather than deleting it, so email and documents survive until you decide what to keep. If your accounts are created primarily inside Google Workspace by an existing process, leave Create Users off and use Okta's import to map the accounts instead.
Step 4: Sync Passwords
- Still under To App, click Edit.
- Select Enable for Sync Password.
- Select Sync Okta Password as the password type.
- Click Save.
Mail and calendar clients that sign in to Google directly still need a Google password even with SSO in place. Syncing the Okta password means your team manages one credential instead of two. Your Okta password policy should meet Google's password requirements for the sync to succeed.
Step 5: Set Okta's Access Level in Google
- Sign in to the Google Workspace admin console.
- Go to Security → Access and data control → API controls.
- Click MANAGE THIRD-PARTY APP ACCESS, then click Okta.
- Expand Access to Google data and select Limited or Trusted. Limited restricts Okta to unrestricted Google data and is the most secure choice.
- Click Save.
Step 6: Assign People or Groups
- In the Google Workspace app instance, go to the Assignments tab and click Assign → Assign to People.
- Select a user and click Assign.
- Choose the organizational unit to place the account in, set the deactivation and license options, and click Save and Go Back.
- Click Done.
Assigning by group scales better than one person at a time: add a new hire to the right Okta group and their Google account is created with the rest of their stack.
Verify the Setup
- Assign a test user in Okta, then confirm the account appears in the Google Admin console user list within a few minutes
- Change the test user's first name in Okta and confirm the update reaches their Google profile
- Deactivate the test user in Okta and confirm their Google account shows as inactive
Troubleshooting
- The provisioning options will not enable. The API integration is not authenticated. Rerun Configure API Integration and complete the Google authentication and permissions steps.
- Account creation fails for a rehire or renamed user. Google does not reuse usernames deleted within the past week. Wait out the window or choose a different username.
- Password sync silently fails. Confirm your Okta password policy meets Google's requirements, then have the user sign in to Okta again to trigger a fresh sync.
- Duplicate accounts after enabling provisioning. Existing Google users were never mapped to Okta users. Run an import from the app's Import tab and match the accounts before pushing new ones.
Would it help to have every new hire fully provisioned on day one without touching an admin console? ScaleIt sets up Okta provisioning for Google Workspace and the rest of your stack as part of managed IT support. Book a free call and we will map your onboarding flow end to end.
Verified against Okta's Google Workspace provisioning documentation on 2026-09-11. Vendor docs: https://help.okta.com/en-us/content/topics/provisioning/google/google-provisioning.htm, https://help.okta.com/en-us/content/topics/provisioning/lcm/lcm-provision-application.htm.