Configure authentication to Google Workspace

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Google Workspace from the Previews page. See Manage Azure Databricks previews.

Configure Google Workspace to enable authentication from Azure Databricks for the Google Workspace connector. Use the credentials retrieved from these steps to create a Unity Catalog connection in Azure Databricks.

Prerequisites

  • A Google Workspace administrator account with the Reports privilege. Super administrators already have this privilege. Otherwise, create a custom administrator role that includes Reports, then assign the role to the account that authorizes the connection. Reports is listed under Reports in the privilege list.
    • To ingest the vault table, include the Google Vault Access All Logs privilege on the same custom role, under Vault.
  • Access to a Google Cloud project where you can enable the Admin SDK API and create OAuth credentials.
  • A supported edition for each source table that requires one:

Configure Google Workspace

Create a Google Cloud project, configure the OAuth consent screen, enable the Admin SDK API, and create OAuth client credentials. Use the resulting client ID and secret to create the Unity Catalog connection in Azure Databricks. For more information, see Enable Google Workspace APIs and Create access credentials.

Create or select a Google Cloud project

  1. Log in to the Google Cloud console.
  2. At the top of the page, open the project picker. Select an existing project, or click Create project to create a new one.
  3. If you create a project, enter a descriptive Project name, choose a Location, then click Create. It takes a few seconds to create the project.
  4. In the left navigation menu, go to Cloud overview > Dashboard.
  5. Confirm that the project you selected or created is shown at the top of the page. If it isn't, open the project picker and select it.

Configure your Google Cloud app

  1. In the top search bar, search for OAuth consent screen and select it.
  2. On the OAuth consent screen page, click Get started.
  3. On the Branding page, enter the following, then leave the remaining fields blank:
    • App name: A name for the app.
    • User support email: Your email address.
    • Audience: Select Internal.
    • Developer contact information: Your email address.
  4. Click Save and continue.
  5. On the Data access page, click Add or remove scopes.
  6. In Manually add scopes, enter https://www.googleapis.com/auth/admin.reports.audit.readonly.
  7. Click Add to table, then click Update.
  8. Click Save.

Enable the Admin SDK API

  1. In the top search bar, search for Admin SDK API and select it.
  2. On the Admin SDK API page, click Enable.

Create OAuth credentials

  1. In the top search bar, search for API & Services and select it.
  2. In the left navigation menu, click Credentials.
  3. Click Create credentials.
  4. Select OAuth client ID.
  5. For Application type, select Web application, then enter a Name for the client.
  6. Under Authorized redirect URIs, click Add URI.
  7. Enter https://<workspace-url>/login/oauth/http.html. Replace <workspace-url> with the Azure Databricks workspace host name.
  8. Click Create.
  9. In the dialog, record the Client ID and Client secret. Use these values to create the Unity Catalog connection.

Next steps

Create a Google Workspace connection in Azure Databricks. See Create a Google Workspace connection.