Overview

The Google Workspace integration monitors your organization’s user directory, MFA enrollment, security settings, admin activity, and managed devices. LowerPlane uses read-only OAuth access and connects via the Google Admin SDK.

Authentication

Google Workspace uses OAuth 2.0. You must sign in with a Super Admin account to authorize LowerPlane.

Required Permissions (OAuth Scopes)

ScopeWhat It GrantsWhy LowerPlane Needs It
admin.directory.user.readonlyRead user profiles and statusList all users for access reviews, MFA checks, and offboarding verification
admin.directory.group.readonlyRead group membershipsMap users to groups for access certification
admin.directory.orgunit.readonlyRead organizational unitsUnderstand org structure for scoped policies
admin.directory.rolemanagement.readonlyRead admin rolesIdentify privileged accounts for elevated access monitoring
admin.directory.domain.readonlyRead domain settingsVerify domain-level security configurations
admin.directory.device.chromeos.readonlyRead Chrome OS devicesInventory Chrome OS devices for endpoint compliance
admin.directory.device.mobile.readonlyRead mobile devicesInventory managed mobile devices
admin.reports.audit.readonlyRead admin audit logsCollect admin activity events for audit trail
admin.reports.usage.readonlyRead usage reportsMonitor login activity and service usage patterns

What LowerPlane Collects

User Directory

All users with profile data: name, email, department, title, status, creation date, last login, and organizational unit.

MFA / 2-Step Verification

Per-user 2-step verification enrollment status. Whether each user has enrolled in 2SV and what factors they use.

Groups & Roles

Group memberships and admin role assignments for access review campaigns and privileged access monitoring.

Admin Audit Logs

Administrative actions from the Google Admin Console: user creation, suspension, password resets, group changes, and security setting modifications.

Managed Devices

Chrome OS and mobile devices enrolled in Google endpoint management with compliance status.

Domain Settings

Domain-level security configurations including 2SV enforcement policy.

Security Tests

LowerPlane runs automated tests against your Google Workspace organization:
TestSeverityApplies ToDescription
2-Step Verification EnforcedCriticalOrganizationVerifies org-wide 2SV enforcement is enabled so all users must enroll
User MFA EnrolledCriticalEach userChecks each active user has completed 2-step verification enrollment
Inactive User AccountsMediumEach userFlags accounts with no sign-in activity in the last 90 days
Offboarded User Access RemovedCriticalEach userConfirms suspended/deleted users match terminated employees

Cross-IdP MFA Passthrough

When Google Workspace enforces 2-step verification at the organization level, LowerPlane automatically passes MFA-related tests for downstream services authenticated via Google SSO.

Connecting

1

Navigate to Integrations

Go to Settings > Integrations and find Google Workspace under Identity Providers.
2

Click Connect

Click the Connect button. You will be redirected to Google’s OAuth consent screen.
3

Authorize with Super Admin

Sign in with a Google Workspace Super Admin account. Review the requested permissions and click Allow. Standard admin accounts may not have sufficient privileges.
4

Initial Sync

LowerPlane syncs your user directory, groups, security settings, and admin logs. This typically takes 2-5 minutes depending on organization size.
You must use a Super Admin account to authorize. Delegated admin accounts may not have access to all required Admin SDK endpoints (particularly reports and domain settings).

Evidence Artifacts

ArtifactDescriptionFrameworks
User DirectoryComplete user inventory with status and last loginSOC 2, ISO 27001, HIPAA, GDPR
2SV Enrollment StatusPer-user MFA enrollment for access control evidenceSOC 2, ISO 27001, HIPAA, PCI-DSS
Group MembershipsUser-to-group mapping for access reviewSOC 2, ISO 27001
Admin Audit LogsAdministrative actions for change management evidenceSOC 2, ISO 27001, HIPAA
Managed DevicesEndpoint inventory with compliance statusSOC 2, ISO 27001

Data Access

Data TypeAccess
User profiles and statusRead
2-Step Verification enrollmentRead
Group membershipsRead
Admin audit logsRead
Chrome OS and mobile devicesRead
Email contentsNo access
Google Drive filesNo access
Calendar eventsNo access
Chat messagesNo access

Troubleshooting

Ensure you are signing in with a Super Admin account, not a delegated admin. Go to Admin Console > Account > Admin roles to verify your role.
LowerPlane syncs users from all organizational units by default. Check if some OUs are suspended or if certain users are in a different Google Workspace instance.
Google’s Admin SDK reports 2SV enrollment status from the directory, not from individual sign-in sessions. If 2SV enforcement was recently enabled, users may not appear as enrolled until they complete the enrollment flow.
Admin audit logs require at least a Google Workspace Business or Enterprise subscription. Google Workspace Essentials may not include audit log API access.