Google Cloud / G Suite Connector by Microsoft | Provisioning

Paul Bomboy 0 Reputation points
2023-08-24T20:34:20.77+00:00

I am trying to allow Azure AD users to log onto Chromebooks. I

I am following this guide https://portal.azure.com/#view/Microsoft_AAD_Connect_Provisioning/ProvisioningMenuBlade/~/Provisioning/objectId/23a2565d-393d-4c7f-a1de-57d8baacd1d4/appId/733c21f1-d0c9-45f9-bf43-e3c7f3a69fd9

I at at the point of automatic provisioning. I select authorize. I am prompted by Google to sign in. I sign in user the new super admin credentials I created, but get an error Access blocked: Authorization Error

Access to your account data is restricted by policies within your organization. Please contact the administrator of your organization for more information.

If you are a developer of Azure Active Directory, see error details.

Error 400: admin_policy_enforced

Any help would be great!

Microsoft Security | Microsoft Entra | Microsoft Entra ID
{count} votes

2 answers

Sort by: Most helpful
  1. Harpreet Singh Matharoo 8,401 Reputation points Microsoft Employee Moderator
    2023-08-25T06:36:14.01+00:00

    Hello @Paul Bomboy

    Thank you for reaching out. Error 400: admin_policy_enforced is an G Suite Policy error and not an Azure AD error. When login with super admin credentials we authenticate the credentials your G-Suite Environment. If we receive any error during this phase it needs to be reviewed and worked upon target app system.

    I tried to look up for this error and found that the error message «Error 400: admin_policy_enforced» is caused by changes in permissions that haven't been accepted.

    You can find more details about this error in G-Suite Admin Console Help documentation. Few that I found are listed below:

    If these links do not help, the would recommend you to please contact G-Suite Support team for further assistance.

    I hope this helps and redirects you to correct support platform to help you fix the issue. I would request you to please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

  2. Jacob Rupe 0 Reputation points
    2023-08-26T22:08:49.9866667+00:00

    I had this issue today, I found that it was the Google Workspace admin service being restricted. Change to unrestricted.

    Under Security>Access and Data Control>API Controls>Google Services>Google Workspace Admin (Restricted)

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.