STANDARD OPERATING PROCEDURE
Google Workspace Integration in Threatcop Admin
This SOP outlines the step-by-step process to configure a new Google Workspace (G-Suite) integration in Threatcop Admin, so that users and groups from a client's Google Workspace directory can be synchronized into product. Use this procedure whenever a new client domain needs to be connected, or an existing domain needs a fresh sync configuration.
STEP 1 Open the Directory Dashboard
From the Threatcop Admin home screen, go to the left-hand menu and select the relevant application panel. Navigate to Directory to view the summary of Users, Groups, Applications, Domains, Integrations, and Organisation data for the tenant.
Fig 1 — Threatcop Admin home screen with TSAT, TLMS, TDMARC and TPIR overview
Fig 2 — Directory Dashboard showing Users, Groups, Applications, Domains and Integrations summary
STEP 2 Go to Integrations
Click Manage next to the Integrations card, or select Integrations from the left-hand menu under Other Menu. Locate the Google Workspace card and click Configure.
Fig 3 — Integrations page listing Microsoft Azure, Google Workspace, SSO, JumpCloud, Darwinbox and AD Blocking
STEP 3 Review Existing G-Suite Configurations
The G-Suite Integration page lists all domains already configured for user and group syncing, along with their Last Sync date and Auto Sync setting. To add a new domain, click New Configuration in the top-right corner.
Fig 4 — G-Suite Integration page showing existing synced domains and the New Configuration option
STEP 4 Choose a Domain
In the configuration panel that opens, Step 1 — Choose a Domain requires selecting the client's domain from the Domain Name dropdown list. Select the correct domain and proceed.
Fig 5 — Step 1: Domain selection dropdown showing all available domains
STEP 5 Grant Admin Consent
In Step 2 — Grant Admin Consent, click the Authorise button. This triggers a Google sign-in and OAuth consent prompt in a new browser tab.
Fig 6 — Step 2: Grant Admin Consent screen with the Authorise button
STEP 6 Authorize via Google OAuth Consent Screen
Sign in with a Google Workspace super admin account for the client domain. Review the requested permissions — viewing customer-related information, user schemas, domains, and groups — and click Allow to grant access.
Fig 7 — Google OAuth consent screen requesting access to the Google Workspace account
STEP 7 Review Retrieved Domains
Once authorization is complete, Step 3 — Retrieved Domains displays the list of domains fetched from the connected Google Workspace account. Confirm the correct domain(s) appear in the list, then click Next.
Fig 8 — Step 3: Retrieved domains list fetched from Google Workspace
STEP 8 Select Groups to Synchronize
In Step 4 — Select Group(s), choose the groups to sync. Use Select All Groups to include all subgroups, or search for and select specific groups individually. Optionally enable Sync only active users to exclude suspended or inactive accounts.
Fig 9 — Step 4: Group selection with Select All Groups and Sync only active users options
STEP 9 Choose Sync Type and Start Syncing
Click Sync to open the Sync Users dialog and choose a sync method:
Full Sync (Mirror AD Users) — mirrors Threatcop Admin exactly with Google Workspace; any user not found in the directory is automatically removed.
Incremental Sync (Add New Users Only) — adds only new users; existing users remain unchanged and none are removed.
Select the appropriate option based on the client requirement and click Start Syncing to complete the configuration.
Fig 10 — Sync Users dialog with Full Sync and Incremental Sync options
Return to Directory → Dashboard and confirm the updated Users and Groups counts.
Check the G-Suite Integration listing to confirm the Last Sync date has been updated for the domain.
Verify newly synced users are visible under Directory → Users and available for assignment in TLMS.
Use Full Sync only when Google Workspace is the single source of truth for the client's user directory, as it removes users not present there.
Use Incremental Sync for ongoing, low-risk updates where existing Threatcop Admin users should not be affected.
Admin consent must be granted by a Google Workspace super admin account for the client domain; a standard user account cannot authorize this integration.