How to Set Up SCIM Provisioning in Okta for Google Workspace

Provisioning connects Okta to Google Workspace so accounts follow your roster automatically. A new hire assigned in Okta gets their Gmail, Drive, and Calendar account without anyone opening the Google Admin console, and a departure is deactivated in both systems with one action. The setup:

Verified against Okta's Google Workspace provisioning documentation on 2026-09-11.

One naming note: Okta provisions many apps over the SCIM protocol, but its Google Workspace integration does the same lifecycle work through Google's own APIs. The admin experience and the result are identical, so the steps below are what you are looking for either way.

Prerequisites

The configuration is identical at 5 people and at 120. Best practice is to wire provisioning in from day one, and if your team has been creating Google accounts by hand, these same steps retire that chore now.

Step 1: Open the Provisioning Settings

  1. In the Admin Console, go to Applications → Applications.
  2. Open your Google Workspace app instance.
  3. Go to the Provisioning tab and click Configure API Integration.

Step 2: Authenticate with Google Workspace

  1. Select Enable API integration, then click Authenticate with Google Workspace.
  2. Select the Google admin account to use for authentication, or enter its username and password, and click Next.
  3. Review the list of permissions Google grants Okta and click Allow.
  4. Back on the Provisioning tab, click Save.

Step 3: Turn On the Provisioning Features

  1. On the Provisioning tab, click To App under Settings.
  2. Click Edit in the Provisioning to App section.
  3. Enable Create Users, Update User Attributes, and Deactivate Users.
  4. Click Save.

Deactivating a user in Okta sets their Google account to inactive rather than deleting it, so email and documents survive until you decide what to keep. If your accounts are created primarily inside Google Workspace by an existing process, leave Create Users off and use Okta's import to map the accounts instead.

Step 4: Sync Passwords

  1. Still under To App, click Edit.
  2. Select Enable for Sync Password.
  3. Select Sync Okta Password as the password type.
  4. Click Save.

Mail and calendar clients that sign in to Google directly still need a Google password even with SSO in place. Syncing the Okta password means your team manages one credential instead of two. Your Okta password policy should meet Google's password requirements for the sync to succeed.

Step 5: Set Okta's Access Level in Google

  1. Sign in to the Google Workspace admin console.
  2. Go to Security → Access and data control → API controls.
  3. Click MANAGE THIRD-PARTY APP ACCESS, then click Okta.
  4. Expand Access to Google data and select Limited or Trusted. Limited restricts Okta to unrestricted Google data and is the most secure choice.
  5. Click Save.

Step 6: Assign People or Groups

  1. In the Google Workspace app instance, go to the Assignments tab and click Assign → Assign to People.
  2. Select a user and click Assign.
  3. Choose the organizational unit to place the account in, set the deactivation and license options, and click Save and Go Back.
  4. Click Done.

Assigning by group scales better than one person at a time: add a new hire to the right Okta group and their Google account is created with the rest of their stack.

Verify the Setup

Troubleshooting

Would it help to have every new hire fully provisioned on day one without touching an admin console? ScaleIt sets up Okta provisioning for Google Workspace and the rest of your stack as part of managed IT support. Book a free call and we will map your onboarding flow end to end.

Verified against Okta's Google Workspace provisioning documentation on 2026-09-11. Vendor docs: https://help.okta.com/en-us/content/topics/provisioning/google/google-provisioning.htm, https://help.okta.com/en-us/content/topics/provisioning/lcm/lcm-provision-application.htm.