Google Sync for federated directories

Last updated on Aug 3, 2026

Understand how Google Sync automates user management between your Google Admin Console and Adobe Admin Console.

Google Sync links your Google Admin Console with the Adobe Admin Console. It automates user provisioning and management, eliminates manual updates, and maintains consistent identities across systems.

Add Google Sync to any federated directory in the Adobe Admin Console, regardless of which identity provider (IdP) manages authentication. Your user data must be in the Google Admin Console for Google Sync to work.

How Google Sync works

Google Sync uses SCIM protocol to synchronize user information between Google and Adobe. After configuration, Google automatically sends user data changes to the Adobe Admin Console based on your Google directory's provisioning settings.

The sync manages user accounts and updates user attributes. You control which user information flows to Adobe through attribute mapping in Google Admin Console. Synced users can be assigned to product profiles for license provisioning.

Google Organizational Units sync to the Adobe Admin Console as user groups. This mapping enables product assignment based on your existing organizational structure in Google.

Benefits of Google Sync

Google Sync gives you these benefits:

  • Manage provisioning centrally: Control all user provisioning from Google Admin Console.
  • Control data flow: Specify which user attributes Adobe receives via mapping.
  • Align organizations: Sync Google Organizational Units as user groups for easier product assignment.
  • Integrate flexibly: Add sync to existing federated directories without affecting authentication.
  • Support multiple IdPs: Use Google Sync even if another provider manages authentication.
  • Simplify onboarding: Automate user creation and removal based on Google directory updates.
  • Eliminate extra services: Remove the need for separate sync tools or API integrations.

Integration scenarios

Google Sync supports these deployment configurations:

Directory setup scenario

Integration method

Single Google Admin Console tenant to a single Adobe Admin Console

Configure Google Sync directly

Multiple federated directories, one Google tenant

Consolidate domains into a single directory, then configure Google Sync.

Multiple federated directories with domains from different Google Admin Console tenants

Configure Google Sync separately for each directory

Planning considerations

Before you configure Google Sync, consider these factors:

  • User backup: Create a backup of your current user list and license assignments. This record helps track accounts and entitlements before sync.
  • Username matching: Ensure usernames in the Adobe Admin Console match those in Google provisioning mappings. Mismatched values create duplicate accounts.
  • Directory requirement: Google Sync requires a federated directory. Organizations without one must create a directory before enabling sync.
  • Trust relationships: If your Admin Console (owning Console) has trust relationships with other Admin Consoles (trustee Consoles), trustees must use alternative management methods. Options include the User Sync Tool, the User Management API, or a bulk CSV upload. Add users to the owning Console for license provisioning in trustee Consoles.
  • Automation tools: Pause any active User Sync Tool or UMAPI integrations before enabling Google Sync. Remove these tools completely after Google Sync is operational.
  • Domain transfers: To move domains to or from a Google Sync–managed directory, remove sync from the directory first. After moving the domain, reestablish sync on the target directory.

Quarantine policy

We monitor sync operations to protect data integrity. When error rates exceed defined thresholds, the system temporarily quarantines the connection. During quarantine, all sync requests from the Google Admin Console are rejected.

Quarantine activates when too many requests fail. If errors continue, quarantine extends. Google may also quarantine the connection on their side due to rejected calls counting toward their error thresholds.

Adobe reserves the right to adjust quarantine parameters based on ongoing analysis. This policy ensures sync reliability and prevents cascading errors from affecting your user directory.