Google Administrator requires Google Workspace account with Super Admin Role to grant the service account with API access.
The account with Super Admin role only needs to perform this one time configuration for the Google Workspace account to be added to FortiCWP.
- Log into Google Admin with the Google Workspace account with Super Admin role.
- Go to Security > API Controls, scroll down and click Manage Domain wide Delegation.
- Click Add new to authorize the registered client to access your user data.
- In the Client ID field, enter the Client ID saved from Configure Service Account. Your Client ID must be a string of numbers.
- In the OAuth scopes field, enter: