Google Workspace connector FAQ

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Google Workspace from the Previews page. See Manage Azure Databricks previews.

This page answers frequently asked questions about the managed Google Workspace ingestion connector in Lakeflow Connect. For FAQs that apply to all managed connectors, see Managed connector FAQs.

Which Google Workspace plans does the connector require?

Plan requirements depend on the source table. The drive and keep tables require a Business or Enterprise edition.

The access_transparency table requires Frontline Plus, Enterprise Plus, Education Standard, Education Plus, or Enterprise Essentials Plus. The vault table requires a Google Vault add-on license and the Google Vault Access All Logs privilege on the authorizing administrator. See Prerequisites.

Which tables does the connector support?

The connector supports 35 audit activity tables, one for each Google Workspace application. For the complete list and destination schemas, see Supported source tables.

How far back can the connector ingest data?

The first sync starts 179 days before the pipeline runs.

Google retains audit data retrieved through the API for six months. Google limits audit activity reports to 180 days.

The connector cannot retrieve data that Google no longer makes available.

Which authentication methods does the connector support?

The connector supports OAuth U2M. OAuth M2M, username and password authentication, and API key authentication aren't supported.

Why might a Google authorization stop refreshing?

Google limits each Google Account and OAuth client combination to 100 refresh tokens. Creating another token makes the oldest token no longer valid.

Google can also expire a refresh token that hasn't been used for six months. Recreate the connection authorization if its refresh token is no longer valid.