Resolve Google sync failures with federated directory

Last updated on Aug 3, 2026

Resolve Google sync errors by checking setup, mappings, and provisioning logs.

Google Sync failures typically stem from misconfigured settings, incorrect attribute mappings, or scope issues. The result is users not appearing in Adobe, errors appearing in the Autoprovisioning logs of the Adobe SAML app, or Organizational Units not creating matching groups. Review Autoprovisioning logs to identify errors and solutions.

Users don't appear after sync

Users and groups are configured incorrectly in the Google Admin Console.

Verify the configuration matches Google’s setup requirements.

Confirm that users are within the provisioning scope in the Google Admin Console.

Confirm that groups are assigned to the Adobe SAML app.

Check that user provisioning is enabled for the Adobe SAML app.

Attribute mappings are incorrect or incomplete

User attribute mappings between Google Admin Console and Adobe Admin Console are incorrect or incomplete.

Sign in to your Google Admin Console.

Select Apps > Web and mobile apps.

Select the Adobe SAML app.

Select Autoprovisioning > Edit Attribute mapping.

Verify the required attributes map correctly: FirstName, LastName, Username, Email, and Country Code.

If syncing Google Organizational Units, confirm that the Organizational unit path is mapped to urn:ietf:params:scim:schemas:extension:Adobe:2.0:User:organizationalUnit

Organizational Unit structure exceeds limits

Google Sync fails when an Organizational Unit's structure or group names exceed Adobe Admin Console limits, with error messages: “Failed because OU depth is greater than 10”, “Failed because OU attribute would yield groups that are too long”, or “Failed because OU attribute contains disallowed chars”.

Review your OU structure in Google Admin Console.

Verify that no OU hierarchy exceeds 10 levels in depth.

Check that generated group names (formatted as OU/Sales/Germany) do not exceed 256 characters.

Ensure OU names contain only allowed characters for group names.

Restructure OUs in Google Admin Console if any limits are exceeded.

Wait for the next sync cycle to complete.

Provisioning logs show errors

The provisioning application shows errors that prevent user synchronization.

Sign in to your Google Admin Console.

Navigate to Apps > Web and mobile apps > Adobe SAML app.

Select Autoprovisioning to view the provisioning logs.

Review any error messages for specific users or groups.

Fix identified issues within Google Admin Console.

Monitor the next sync cycle to confirm resolution.

Temporarily edit synced user data

Identity provider's change requests automatically overwrite these changes during the next sync.

Sign in to Adobe Admin Console.

Navigate to Settings > Directory Details > Sync.

Select Go to Settings.

Select Allow editing synced data in Admin Console.

Make necessary edits to user information (available for one hour).

Select Disable editing immediately after completing changes to ensure the Admin Console reflects Google Admin Console changes.

Contact Google customer support if issues persist. You can also refer to Google's configuration instructions for additional guidance.