---
sourceDocument: Australia Asset Management
sourceDocumentLink: https://www.servicenow.com/docs/r/it-asset-management

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Asset Management

ft:clusterId :

    - itam

bundleId :

    - itam

workflow :

    - Technology


---

# Integrating with Google Workspace

# Integrating with Google Workspace {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 7 minutes to read

Integrating your Software Asset Management application with the Google Workspace service enables you to track your software subscriptions and to reclaim unused licenses.

For additional information about the Google Workspace service, see [Google Workspace Admin Help](https://support.google.com/a/?hl=en#topic=7570177).  
Important:  
Minimize security risks and protect information by granting access only to the necessary user or API permissions.{#integrate-with-gsuite__table_box__entry__3}

| Process | Required user role in the Google Workspace application | Authentication scopes |
|-|-|-|
| Download subscriptions | Admin API privileges: Users Read | * \[Admin SDK API\] https://www.googleapis.com/auth/admin.directory.user.readonly * \[Admin SDK API\] https://www.googleapis.com/auth/admin.directory.domain.readonly * \[Enterprise License Manager API\] https://www.googleapis.com/auth/apps.licensing {#integrate-with-gsuite__ul_h4p_1fr_dcc} |
| Pull user activity | Admin API privileges: Users Read | * \[Admin SDK API\] https://www.googleapis.com/auth/admin.directory.user.readonly * \[Admin SDK API\] https://www.googleapis.com/auth/admin.reports.usage.readonly {#integrate-with-gsuite__ul_qp3_3fr_dcc} |
| Reclaim subscription | Super Administrator | * \[Admin SDK API\] https://www.googleapis.com/auth/admin.directory.user.readonly * \[People SDK API\] https://www.googleapis.com/auth/userinfo.email * \[People SDK API\] https://www.googleapis.com/auth/userinfo.profile * \[Admin SDK API\] https://www.googleapis.com/auth/admin.datatransfer.readonly * \[Admin SDK API\] https://www.googleapis.com/auth/admin.directory.user {#integrate-with-gsuite__ul_ojw_lfr_dcc} |
[Table 1. Minimal user permissions]

{#integrate-with-gsuite__box-title}

## Create a Google Workspace project {#ariaid-title2}

Create a project in the Google API Console.

### Before you begin

Google Workspace Role required: Refer to the [Minimal user permissions](https://www.servicenow.com/docs/aQolc~JO6tpJqM22UOBNpA#integrate-with-gsuite "Integrating your Software Asset Management application with the Google Workspace service enables you to track your software subscriptions and to reclaim unused licenses.") table.

### Procedure

1. Log in to [Google API Console](https://console.developers.google.com).
2. Select Select a projectNew Project.
3. Enter a name for your project in the Project name field, then select your Organization and Location.
4. Select Create.
5. Select OAuth consent screen on the side navigation menu.
6. If you haven't configured Google Auth Platform yet, select Get started.
7. Enter the App name and select User support email in the App information section.
8. Select Next.
9. In the Audience section, select Internal as the user type and select Next.
10. In Authorized domains, select the ADD DOMAIN button and add <kbd class="ph userinput">service-now.com</kbd>.
11. Enter your email address in the Developer contact information section.
12. Select Save and Continue to add scopes.
13. On the Scopes page, select the Add or Remove Scopes button.
14. In the Manually add scopes section, enter the following scopes by pasting them to the text area:  
    * https://www.googleapis.com/auth/apps.licensing
    * https://www.googleapis.com/auth/admin.directory.user
    * https://www.googleapis.com/auth/admin.directory.user.readonly
    * https://www.googleapis.com/auth/admin.directory.domain.readonly
    * https://www.googleapis.com/auth/admin.datatransfer
    * https://www.googleapis.com/auth/admin.datatransfer.readonly
    * https://www.googleapis.com/auth/admin.reports.usage.readonly
    * https://www.googleapis.com/auth/userinfo.profile
    * https://www.googleapis.com/auth/userinfo.email
    {#create-gsuite-project__ul_ldk_cqm_mwb}
15. Select ADD TO TABLE and then select Update.
16. Select Save and Continue.
17. Select Credentials on the side navigation menu and select CREATE CREDENTIALS.
18. Select OAuth client ID.
19. Fill out the form as shown and select Create.  
    {#create-gsuite-project__table_tgs_fjf_1hb__entry__2}

    | Field | Value |
    |-|-|
    | Application type Note: Selecting a value for this field causes the remaining fields to be displayed. | Web application |
    | Name | Any name of your choice |
    | Authorized JavaScript origins | https://<var class="keyword varname">instance</var>.service-now.com, where <var class="keyword varname">instance</var> is the name of your ServiceNow instance |
    | Authorized redirect URIs | https://<var class="keyword varname">instance</var>.service-now.com/oauth_redirect.do, where <var class="keyword varname">instance</var> is the name of your ServiceNow instance |
    [ ]

    {#create-gsuite-project__table_tgs_fjf_1hb}
20. Select OK.  
    You can now view your client ID and client secret that you would use in your ServiceNow instance.  
    Note:  
    Your client ID and client secret are sensitive. Don't share them.
21. Select Library on the side navigation menu.  
    Search for and enable the following APIs:
    * Enterprise License Manager API
    * Admin SDK
    * Google People API
    {#create-gsuite-project__ul_ukg_rgc_chb}
{#create-gsuite-project__steps_m5h_xtg_ynb}

## Create a Google Workspace integration profile {#ariaid-title3}

Create an integration profile to track software subscriptions and optimize licensing for the Google Workspace service.

### Before you begin

To create a Google Workspace integration profile, request the Software Asset Management - SaaS License Management plugin (sn_sam_saas_int) from the [ServiceNow Store](https://store.servicenow.com/).

ServiceNow Role required: sam_integrator

### About this task

If you're using Software Asset Workspace, the option to create the Google Workspace integration profile in Core UI is inactive.

### Procedure

1. Navigate to the integration profile.

   | Interface | Action |
   | Core UI | 1. Navigate to AllSoftware AssetSaaS LicenseDirect Integration Profiles. 2. Select New. 3. Select Google Workspace Integration Profile. {#create-integration-profile-gsuite__ol_ijd_bjk_qtb} |
   | Software Asset Workspace | 1. Navigate to License operationsUser SubscriptionsDirect integration profiles. 2. Select New. 3. Select Google Workspace from the drop-down list. 4. Select Continue. {#create-integration-profile-gsuite__ol_wjd_bjk_qtb} |
   |-|-|

   {#create-integration-profile-gsuite__choicetable_o3p_z3k_qtb}
2. On the form, fill in the fields.  
   {#create-integration-profile-gsuite__table_gnm_whv_5fb__entry__2}{#create-integration-profile-gsuite__display-name-def}{#create-integration-profile-gsuite__client-id-def}{#create-integration-profile-gsuite__redirect-url-def}{#create-integration-profile-gsuite__client-secret-def}{#create-integration-profile-gsuite__profile-type-def}

   | Field | Value |
   |-|-|
   | Display name | Name of the integration profile. For example, <kbd class="ph userinput"><span class="keyword">Google Workspace</span> Integration</kbd> |
   | Client Id | Client ID for the OAuth application created in the SaaS admin account. |
   | Redirect url | URL of the OAuth provider that you're redirected to after authentication. This value is automatically populated. |
   | Client secret | Password associated with the client ID. |
   | Profile type | Type of integration profile. This value is automatically set to Google Workspace Subscription. |
   [Table 2. Integration Profile form]

   {#create-integration-profile-gsuite__integration-form-title}
3. In the Process configuration section, review the required user roles or API permissions specified in the Vendor configuration field for each process to minimize security risks and optimize SaaS licenses.  
   Note:  
   For more information about the required roles and scopes, see [Minimal user permissions](https://www.servicenow.com/docs/aQolc~JO6tpJqM22UOBNpA#integrate-with-gsuite "Integrating your Software Asset Management application with the Google Workspace service enables you to track your software subscriptions and to reclaim unused licenses.") table.
   * The Download subscriptions check box is selected by default and you can't clear it.

   * The Download Activity check box is selected by default. If you clear it, the activity scheduled job SAM - Refresh \<displayname\> Events isn't created.

     In the Analyze user activity field, you can also select the date and time starting from when you want to analyze the user activity. By default, you can analyze user activity up to 60 days prior to the current date and view events performed by individual users from the time you create this profile.  
     Note:  
     Software Asset Management pulls the events from the time that you start analyzing user activity irrespective of the profile creation date.
     You can modify this value in the Last activity threshold field of your software reclamation rules. For more information, see [Review a software reclamation rule](https://www.servicenow.com/docs/QjHAOC5kmvypyG1Pph5iIQ "Use reclamation rules to cancel user subscriptions that have limited to no activity.").
   * The Reclaim subscriptions check box is selected by default. If you don't want to reclaim subscriptions, you can clear this check box. If you clear it, the removal candidates are
     created but the reclaim subscription subflow isn't triggered or the reclamation process isn't initiated.

   {#create-integration-profile-gsuite__ul_nmd_wsd_xcc}
4. Select Submit after completing all the required fields.  
   Your ServiceNow instance creates a draft integration profile.
5. On the integration profile, select Get OAuth Token.  
   Note:  
   For the role required to perform this step, refer to the [Minimal user permissions](https://www.servicenow.com/docs/aQolc~JO6tpJqM22UOBNpA#integrate-with-gsuite "Integrating your Software Asset Management application with the Google Workspace service enables you to track your software subscriptions and to reclaim unused licenses.") table.
6. In the pop-up window, select your Google admin account and select Allow.  
   Note:  
   When user subscriptions are reclaimed, files from the reclaimed accounts are transferred to the admin account selected in this step. This account can be a different admin account than the one used to set up the integration. If you have to start transferring files to a new admin, you can select the Get OAuth Token related link again at any time to select a different admin account. After selecting a new admin, you can reclaim the old admin account to transfer all of their files to the new admin, including all previously reclaimed user files.
7. On the integration profile form, select Validate Connection to verify the connection and credential details of this integration.  
   Validating the connection verifies the Download Subscriptions and Calculate Activity APIs, but not the Reclaim Subscriptions APIs.  
   Note:  
   If you clear the Download Activity check box after the integration profile is validated and scheduled jobs are created, you must revalidate the connections because the following events occur:
   * The Status field on the integration profile form changes to Draft.
   * The Validate connection button shows up on the form.
   * The current SAM - Refresh \<displayname\> Events job gets deleted.
   {#create-integration-profile-gsuite__ul_vzt_qbq_kdc}

### Result

You can view events performed by individual users up to one year prior to the current date. For more information, see [Review a software reclamation rule](https://www.servicenow.com/docs/QjHAOC5kmvypyG1Pph5iIQ "Use reclamation rules to cancel user subscriptions that have limited to no activity."). Software Asset Management pulls the events from the time that you start downloading user subscriptions irrespective of the profile creation date.

### What to do next

After the integration connects, your ServiceNow instance automatically creates software models, reclamation rules, and software subscriptions that are refreshed daily.  
After creating an integration profile, view information about the profile in the Software Asset Workspace by navigating to License operationsUser subscriptionDirect integration profiles. You can select an integration profile to view the following related lists. If all of the following related lists aren't visible for an integration profile in the default view, you can select the custom integration view from the Details tab:

* Software Models
* Unrecognized Subscription Identifiers
* Scheduled Jobs
* Scheduled Job Results
* Software Subscriptions
* Subscription Identifier Exclusion Rule
* Subscription User Exclusion Rule
{#create-integration-profile-gsuite__ul_gxp_qfk_rfc}

After creating an integration profile, you can define subscription exclusion rules to keep certain subscriptions from license cost calculations. For more information, see [Subscription exclusions for SaaS and SSO applications](https://www.servicenow.com/docs/kwS~TWLEZdf67e7UjappHg#subscription-exclusions "Define subscription exclusions for your SaaS and SSO applications to optimize your licensing costs by keeping the excluded subscriptions out of license cost calculations.").

If you want to set up multiple integration profiles with unique connections, create child aliases to manage different configurations and settings for each integration profile. For more information, see [Create a child alias to set up multiple integration profiles](https://www.servicenow.com/docs/o5L0ctEzWkFYzYxMhh78ew "Create a child alias to set up multiple integration profiles with unique connections and manage different configurations for each integration profile.").

Review all automatically generated reclamation rules to reclaim user subscriptions. For more information, see [Review a software reclamation rule](https://www.servicenow.com/docs/QjHAOC5kmvypyG1Pph5iIQ "Use reclamation rules to cancel user subscriptions that have limited to no activity.").  
Create software entitlements for the automatically generated software models to track used software against owned software.

* For more information on creating software entitlements in the Software Asset Management Core UI, see [Create entitlements in Software Asset Management Core UI](https://www.servicenow.com/docs/8ZR9KWQ1FY73pUmBw_wZRQ "Create entitlements in the Software Asset Management Core UI application to record your license details and allocate purchased software rights to users or devices.").
* For more information on creating software entitlements in the Software Asset Workspace, see [Create entitlements in workspace](https://www.servicenow.com/docs/ZvL7kERffOGQ6dpBU_744w "Create entitlements in the Software Asset Workspace to enter your license details and allocate purchased software rights to users or devices.").
* For more information on creating software entitlements using the Software Asset Management Playbook, see [Create entitlements using the guided walk-through](https://www.servicenow.com/docs/rw30KUYxwGuwCDdFtc0mOg "Use the guided walk-through playbook for a step-by-step process of creating entitlements.").
{#create-integration-profile-gsuite__ul_cbz_vhr_sqb}  
Reconciliation also runs on your subscriptions as a scheduled job or on-demand. You can view your reconciliation results in the [License Workbench](https://www.servicenow.com/docs/K_GziLbR~smXeeWp0kcdNw "Review reconciliation results in a simplified workbench view.") (Software Asset Management classic application) or the [License usage view](https://www.servicenow.com/docs/Ct5YAvsPFESpnVaeLwu5_w "Use the license usage view as a single plane to understand the license position of all software products, remediate non-compliance, view reconciliation results, view, or add removal candidates, and view Software Asset Management related reports.") (Software Asset Workspace). Use these results to determine your license compliance position and to remediate any non-compliance.

* For more information on running reconciliation in the Software Asset Management classic application, see [Run software reconciliation in Software Asset Management classic](https://www.servicenow.com/docs/Pic766RsbcGCoP1GsB_9RA "Reconciliation is run as a scheduled job (default is weekly), but you can also run reconciliation manually to reconcile software products in your environment on demand.").
* For more information on running reconciliation in the Software Asset Workspace, see [Run software reconciliation in the workspace](https://www.servicenow.com/docs/SUHzxdFqMeO8rQemacW3sA "Reconciliation is run as a scheduled job (default is weekly), but you can also run reconciliation manually to reconcile software products in the Software Asset Workspace environment on-demand.").
{#create-integration-profile-gsuite__ul_qgf_zhr_sqb}

*[\>]: and then


