Troubleshoot the Google Workspace connector

Important

This feature is in Beta. To use it, a workspace admin must turn on Lakeflow Connect for Google Workspace from the Previews page. See Manage Azure Databricks previews.

Resolve common errors with the managed Google Workspace connector.

For general troubleshooting guidance that applies to all managed ingestion pipelines, see Troubleshoot managed ingestion pipelines.

Google rejects the access token

Error message:

Google access token rejected. Refreshing credentials and retrying.

Cause: The access token expired or Google rejected it.

Solution:

The connector refreshes the credentials and retries automatically. If the error persists, recreate the connection authorization. See Create a Google Workspace connection.

Admin SDK Reports API rate limit exceeded

Error message:

Google Admin SDK Reports API rate limit exceeded. Please retry the pipeline after some time.

Cause: The Admin SDK Reports API applied a request rate limit.

Solution:

The connector retries automatically. If the error persists, wait and run the pipeline again. Reduce concurrent pipelines that use the same Google Cloud project.

Admin SDK Reports API per-user rate limit exceeded

Error message:

Google Admin SDK Reports API per-user rate limit exceeded. Please retry the pipeline after some time.

Cause: The Admin SDK Reports API applied a per-user request rate limit to the authorizing administrator.

Solution:

The connector retries automatically. If the error persists, wait and run the pipeline again. Reduce concurrent pipelines authorized by the same administrator.

Insufficient Admin SDK Reports API privileges

Error message:

Insufficient privileges for the Admin SDK Reports API. Verify the OAuth consent granted the admin.reports.audit.readonly scope and that the authorizing user has the Reports admin privilege.

Cause: The OAuth grant lacks the required scope, or the authorizing administrator lacks the Reports privilege. If the pipeline includes the vault table, the administrator might also lack the Google Vault Access All Logs privilege.

Solution:

Verify the OAuth scope and administrator privileges, then recreate the connection authorization. See Configure authentication to Google Workspace and Create a Google Workspace connection.

Admin SDK Reports API temporarily unavailable

Error message:

Google Admin SDK Reports API is temporarily unavailable. Please retry the pipeline after some time.

Cause: The Admin SDK Reports API returned a transient server error.

Solution:

The connector retries automatically. If the error persists, wait and run the pipeline again.