The following are Frequently Asked Question regarding JumpCloud's G Suite User Provisioning and Sync Feature.
A: JumpCloud Utilizes OAuth to secure and persist its connection with Google to perform our integration tasks.
A: When the OAuth session is deactivated in JumpCloud, all users in Google will remain ‘Active’ and functioning. Within JumpCloud, all User accounts will remain Active as well. All accounts will be unbound from the G Suite Directory. When and if the products are-reactivated, the admin will need to re-bind the users to the G Suite Directory to re-establish the connection and ownership-control of the accounts in Google.
A: While this was previously not a supported configuration, use of the Active Directory Bridge can indeed be used when either Google Apps or Office 365 User Provisioning are enabled.
A: At this time, only one Google account can be integrated with JumpCloud.
A: At this time, JumpCloud can not import Avatars into JumpCloud's user accounts.
Q: Can the G Suite and Office 365 Directory integrations be used in tandem, and if so, what configuration requirements are needed?
A: The G Suite and Office 365 Directory integrations can be used together to successfully synchronize both service providers with JumpCloud. The directory integrations utilize the user's email address as the unique identifier for synchronization. Due to this architecture, your domain records may need to be mapped so that the same email address is used between all service providers. For more information refer to the follow vendor-specific documentation:
Add a domain to Office 365
Add a domain to G Suite
A: Upon import, you will see a failure for this user to import as the account with the same email already exists.
A: JumpCloud's Google synchronization UI displays all of your Google users regardless of whether they are suspended and/or previously imported. We will provide filtering mechanisms in the future.
A: At this time, only user accounts are supported between JumpCloud and G Suite. OU and Group membership management should continue to be managed in Google directly.
A: No. Once the Super Admin credentials have been authenticated, the connection to G Suite, regardless of Administrator, can perform importation and provisioning tasks.
A: While an admin can prevent a Welcome email from being delivered to the end user when creating the account inside of JumpCloud by specifying an initial password (Getting Started: Users), binding a user to G Suite will send an email to the employee. We recommend educating the employee base first before binding them to G Suite so the email is expected.
A: In certain circumstances, the setting within the Google Account to “require user to change password at next sign-in” may be set true. This is found in the individual User’s “Account” settings within Google. Turning this off will not force a change to the Google password. Users can then re-set their strong password in JumpCloud and log in with those credentials.
A: The administrator can unbind the user from the G Suite directory in JumpCloud, which will trigger the user in Google to be suspended. Re-binding the user will re-activate the User in Google.
A: The user remains unchanged in JumpCloud. If you wish to remove the user from JumpCloud, these actions must be performed manually in the JumpCloud console. PLEASE NOTE: Should the user need to be re-provisioned from JumpCloud to Google, Google will often require up to 4-5 days until they release the same email address to be re-used again.
A: JumpCloud's Password Complexity works with G Suite synced users just as with any other JumpCloud user and wherever their credentials are emitted to and being used. Any attempt by a JumpCloud user to change their password in the JumpCloud console to one that does not meet JumpCloud's complexity requirements will fail. This does NOT, however, prevent the user from changing their password in their Google account to a non-compliant password. But since JumpCloud is the password authority, any change to the user in JumpCloud will overwrite the non-compliant password in Google with the compliant JumpCloud password.
Note that when synchronizing between JumpCloud and G Suite, the password must be compliant with Google's name and password guidelines.
A: The user’s Google account is suspended, blocking the user from accessing their account. The admin must set a new password for the user in JumpCloud to re-activate the user’s Google account.
A: Employees can change their password from G Suite's password change system- We suggest referring to: Forcing Users to Change Their G Suite Password in JumpCloud to prevent this.