Manage Your Google Directory
Focus
Focus
Identity

Manage Your Google Directory

Table of Contents

Manage Your Google Directory

Learn about managing your Google directory with CIE.
Where Can I Use This?What Do I Need?
  • NGFW
  • Prisma Access
The Cloud Identity Engine service is free; however, the enforcement points utilizing directory data may require specific licenses. Click here for more information.
Managing your Google Directory integration ensures that the Cloud Identity Engine retains valid access to the organizational units, users, and groups defined in your Google Workspace. If the connection status indicates a failure or becomes inactive, you must reconnect the directory by re-authenticating with your Google Admin credentials and testing the connection to restore synchronization.
To stop synchronization and remove the directory entirely, you must perform a two-step revocation process to ensure security. Once access is blocked at the source, you can safely remove the Google Directory from the Cloud Identity Engine application.

Reconnect Google Directory

If the connection between the Cloud Identity Engine and your Google Directory is inactive, reconnect the Google Directory to the Cloud Identity Engine.
  1. Log in to the hub and select the Cloud Identity Engine tenant that contains the Google Directory you want to reconnect.
  2. Select Directories.
  3. Select ActionsReconnect.
  4. Log in to Google and Test Connection to confirm the Cloud Identity Engine can access your Google Directory.
  5. (Optional) Customize Directory Name if you want to change the name that the Cloud Identity Engine displays for this directory in your tenant.
    You can use up to 15 lowercase alphanumeric characters (including hyphens, periods, and underscores) for the directory name in the Cloud Identity Engine. You don't need to change the name of the directory itself, only the name of the directory in the Cloud Identity Engine app. If your directory name contains more than 15 characters, you must change the directory name to contain a maximum of 15 characters.
  6. Submit your configuration.

Remove Google Directory

If you no longer need to use Google Directory with the Cloud Identity Engine app, revoke permissions for the Cloud Identity Engine app and remove the Google Directory from the Cloud Identity Engine app.
  1. Revoke permissions for the Cloud Identity Engine app in the Google Admin Dashboard.
    1. Log in to the Google Admin Dashboard.
    2. Select SecurityAPI ControlsApp Access Control.
    3. Select the Cloud Identity Engine app and Change access to Blocked: Can’t access any Google service.
    4. Click Change to confirm your changes.
  2. Remove the Google Directory from the Cloud Identity Engine app.
    1. Log in to the hub and select the Cloud Identity Engine app.
    2. Select Directories then select ActionsRemove.
    3. Click Yes to confirm removal of the directory.