Configure Google Workspace synchronization and authentication
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
On this tab
- Prerequisites
- Admin access
- Managed Google Domain account
- Chrome OS settings
- Connect to Google Workspace
- Manage Google Workspace connection
- Connection status
- Google Workspace account information
- Google Workspace sync
- Google Workspace sync settings
- Sync behavior
- Users
- Groups
- Organizations
- Enroll devices with their Managed Google accounts
- Disconnect from Google Workspace
Once you configure the Android Enterprise environment, you can integrate your Knox Manage tenant with Google Workspace. This integration syncs all directory resources, such as users and groups, from your Google Admin Console. Once it’s integrated, users can enroll Android Enterprise devices with their Managed Google Domain Accounts.
Google authentication is supported when devices are enrolled in Knox Manage using a QR code sent with the enrollment guide.
Prerequisites
To sync your tenant with Google Workspace, you must meet the following prerequisites:
Admin access
You must be the super admin who created your tenant to link your Google Workspace account.
Managed Google Domain account
You must have registered your Android Enterprise environment with a Managed Google Domain account, not a Managed Google Play account.
You can check what account you’re registered with by going to Settings > ANDROID ENTERPRISE. On the Account tab, your account type displays under Enterprise type. If the Enterprise type isn’t Managed Google Domain, then you must unlink your account and re-register with a Managed Google Domain account. You can also switch to the original console to upgrade your account from Knox Manage. See Configure the Android Enterprise environment to learn more.
Additionally, if your account isn’t a Managed Google Domain, or if you previously set up Chromebook management in the original console, the Connection status is Not available. If you have a Managed Google Domain account, the Connection status is Incomplete.
Chrome OS settings
If you are set up for Chromebook management for your tenant in the original console, you must unlink your Chrome OS settings. See Manage Chromebooks.
Connect to Google Workspace
To connect Knox Manage to Google Workspace:
- Go to Settings > Google Workspace. The Google Workspace page opens.
- Under Connection status, click Sign in with Google. The Google sign-in page opens.
- Sign in with the same Managed Google Domain account you registered your Android Enterprise environment with.
- On the Sign in with Google screen, confirm that Knox Manage can access your Google account. You can click 4 services to see what resources from your Google account Knox Manage can access. By default, Knox Manage has access to view and manage groups, group subscriptions, organizations, and users. To ensure that Knox Manage can sync properly, you must not revoke access to any of these resources. Click Continue.
- Return to Knox Manage. The Verification code is automatically populated and you can now click VERIFY AND CONNECT. If verification is successful, the Sync with Google workspace dialog appears.
- In the dialog, click one of the following options:
- NO, SYNC LATER: Resources from your Google Workspace aren’t immediately synced to Knox Manage.
- YES, SYNC NOW: Resources from your Google Workspace are immediately synced to Knox Manage. If the synchronization is unsuccessful, a message appears to confirm whether the sync Failed or Connected. If the connection failed, you can click TEST AND SYNC on the message to try again.
Manage Google Workspace connection
Once your tenant is integrated with Google Workspace, you can manage your connection from Knox Manage on the Google Workspace page.
Connection status
The connection status between Google Workspace and Knox Manage. This reflects the connection status only, not the sync status. By default, once your tenant is integrated with Google Workspace, this status is Completed.
Google Workspace account information
Displays account information about your Google Workspace admin account.
- Managed Google domain — Your Google domain.
- Google Workspace account — The email for your Google Workspace account.
- Google Workspace sync frequency — The frequency, in days, that Google Workspace syncs with your tenant. You can set this under Google Workspace sync settings.
Google Workspace sync
The sync status between Google Workspace and Knox Manage. If not yet synced, the Test and Sync button is enabled. If already synced, the status is displayed as Connected and the Sync again button is enabled.
Google Workspace sync settings
The settings for synchronization between Knox Manage and Google Workspace.
- Sync start time — Set the time that Google Workspace automatically syncs with your tenant each day.
- Profile settings for synced users — Select how profiles are synced to organizations.
- Automatically apply profiles when added to an organization — Applies a profile to a user when it’s assigned to their organization.
- Don’t apply profiles — Doesn’t apply a profile to a user when it’s assigned to their organization.
- Profile and app settings for synced groups — Select how profiles and apps are synced to groups.
- Push profiles and apps if users added to group — Pushes assigned profiles and apps to users when they’re added to a group.
- Unassign profiles and apps from users if deleted from group — Unassigns associated profiles and apps from users when they’re removed from a group.
- Unassign profiles and apps from group if deleted — Unassigns associated profiles and apps from group members when the group is deleted.
Sync behavior
The following behaviors apply to all resources synced from Google Workspace:
- Resources can’t be synchronized individually, and must be synced all at once.
- If resources are deleted in Google Workspace, then they’re also deleted in Knox Manage.
Users
The following behaviors apply to all users synced from Google Workspace:
- If a Google Workspace user has the same email as an existing Knox Manage user, they replace the Knox Manage user.
- If a Google Workspace user doesn’t have the same email as an existing Knox Manage user, a new user is added to Knox Manage and their User ID will consist of the section of their email address before the
@domain. If this User ID overlaps with an existing User ID, three digits are added onto the end, such aslucymak001. - Google Workspace updates to users are always reflected in Knox Manage.
Groups
- Google Workspace updates to groups are always reflected in Knox Manage.
Organizations
- If a Google Workspace organization has the same Organization code as an existing Knox Manage organization, they replace the Knox Manage organization.
- Google Workspace updates to organizations are always reflected in Knox Manage.
Enroll devices with their Managed Google accounts
Before Google Workspace users can enroll devices, you must configure a few more settings. If you don’t configure these settings, device users can’t sign in with their Google accounts, but your resources will continue to sync from Google Workspace to Knox Manage.
- Go to Settings > ANDROID ENTERPRISE > Account.
- Toggle Sign in and authenticate account to allow users to enroll and sign in to their devices with their Google accounts. Then select one of the following:
- Allow user to skip sign-in — Allows users to continue to enroll and sign in to devices with their Knox Manage credentials instead of their Google accounts.
- Force user to sign in — Forces users to enroll and sign in to devices with their Google accounts.
- Only allow certain users to sign in — Allows only users who have received the enrollment guide to sign in with their Google accounts. Users can’t change their email when enrolling their devices.
Users can now enroll and sign in to devices with their Google credentials.
On devices where Google Mobile Services (GMS) is set to a version between 26.10 to 26.19, users can tap Skip, when asked to sign in with their Google account, and sign in with their Knox Manage credentials instead. To fix this issue, update the GMS version to 26.20 or later.
Disconnect from Google Workspace
You can unlink your Google Workspace account from your Knox Manage tenant. When you unlink your account, any users, groups, and organizations that are synced from Google Workspace are removed from Knox Manage.
Before you disconnect your account, you must first unenroll all Android Enterprise devices enrolled with a Managed Google Account. See Unenroll and delete devices to learn more.
If a user synced from Google Workspace has a device enrolled that isn’t Android Enterprise, then the user is not removed from your tenant when you unlink your account. Instead, their Source changes from Directory to Knox Manage, and their status changes to Inactive.
To unlink your Google Workspace account:
- Go to Settings > Google Workspace.
- At the top of the page, click DISCONNECT. The Disconnect from Google Workspace dialog appears.
- Confirm your intention by clicking YES, DISCONNECT.
Your account is disconnected.
Is this page helpful?
Thank you for your feedback!