Connecting Cyber Aware to Google Workspace is a one-time admin task that removes the worst part of running security awareness training by hand: importing users. Once the sync is on, every person in your Google directory lands in the training programme automatically with a welcome email, leavers drop off the list on the next sync, and the monthly course cadence runs without anyone touching a spreadsheet. This guide walks through the 2026 setup end to end, including the Google Admin console step that trips most people up.
TL;DR
- Cyber Aware syncs learners from Google Workspace, Microsoft 365, CSV upload or signup links.
- The Google side uses domain-wide delegation, authorised in the Workspace Admin console.
- New hires enrol automatically with a welcome email; leavers are removed on the next sync.
- Authorisation can take up to 24 hours to propagate, so test before your first real sync.
- Verify with one test user before switching the whole domain over.
Why this matters
Manual enrolment fails quietly. A CSV import in January misses everyone hired in February, leavers keep seats they no longer use, and nobody notices until an auditor asks who completed what. Directory sync removes the human step: the Google directory becomes the single source of truth and the training list follows it.
It also makes the reporting defensible. Human risk reporting ties overdue courses and phishing results to individual learners, and that chain only holds if the learner list matches reality on day one.
Who this is for
MSPs running Google Workspace across several client tenants, and internal IT teams at businesses that hire in bursts. If enrolment currently depends on someone remembering to run a CSV export, this is the fix.
Before you start
- Super administrator access to the Google Workspace Admin console at admin.google.com - only a super admin can authorise domain-wide delegation.
- Admin access to your Cyber Aware partner account with Auto Enrol available on your plan.
- One test user in the Google directory, so you can verify enrolment, welcome email and removal end to end.
- The gotcha: after authorising under Manage Domain Wide Delegation, propagation usually takes minutes, but Google's documentation allows up to 24 hours. Do not rebuild the connection because day one fails.
Step 1 - Authorise the connection in the Google Admin console
The sync needs delegated read access to your user list, and Google controls that through domain-wide delegation:
- Sign in to admin.google.com with a super administrator account.
- Go to Security > Access and data control > API controls > Manage Domain Wide Delegation.
- Click Add new, then enter the client ID shown in your Cyber Aware sync settings and the OAuth scopes the sync requests.
- Click Authorize.
Google's walkthrough of this exact path, including the propagation window, is in the Google Workspace documentation. One rule from those docs is worth knowing first: you cannot edit a client ID after it is saved - delete the entry and add it again if the ID was pasted wrong.
Step 2 - Connect Cyber Aware to the directory
- Sign in to your Cyber Aware admin area and open the Auto Enrol sync settings.
- Choose Google Workspace as the directory source.
- Enter the connection details from step 1 and save.
- Run the first sync manually.
Expected result: the learner list populates from the Google directory within minutes. Exact field labels can vary between product updates, so if a label does not match this guide, use its on-screen equivalent - the Google-side authorisation is the step that actually gates the connection.
Step 3 - Set arrival, cadence and leaver rules
- Arrival: new learners land in the default training schedule automatically, welcome email included.
- Departure: leavers are removed cleanly on the next sync, so ex-staff stop counting as active learners.
- Cadence: enable auto-add to place a new course in every learner's queue each month, with due and overdue reminders queued on schedule.
- Branding: portals, notification emails and certificates carry your brand rather than Cyber Aware's - confirm it before the first client logs in.
Pick the enrolment path per client
| Path | Best for | Follows joiners and leavers? |
|---|---|---|
| Google Workspace sync | Clients already on Google | Yes - automatic |
| Microsoft 365 sync | Clients on Microsoft | Yes - automatic |
| CSV upload | One-off imports | No - manual |
| Signup link | Contractors and small teams | Partial - self-service |
Standardise on the sync wherever the client runs Google or Microsoft; keep CSV for migrations only.
Verify before you roll out
- Check the test user appears in the learner list after the first sync.
- Confirm the welcome email arrived.
- Suspend the test user in Google Workspace and sync again to confirm removal.
- Then extend the sync to the full domain.
Keep the cadence on autopilot
The sync handles enrolment; the cadence keeps the programme alive after week two. With auto-add on, a new course lands in every queue monthly, reminders fire daily, and scheduled client summary reports go out without a chase. Anyone who fails a phishing simulation is auto-enrolled into the failed-phishing course, closing the loop between testing and teaching.
Troubleshooting
- Authorisation fails at step 1. The client ID was pasted wrong or a scope is missing. Saved client IDs cannot be edited - delete and re-add.
- The connection errors right after setup. Propagation. Google allows up to 24 hours for domain-wide delegation to take effect; retry tomorrow before reconfiguring.
- Some users are missing. Check they sit in an organisational unit inside the sync scope and that their accounts are not suspended.
- Duplicate learners. A stale CSV import plus the live sync list the same person twice. Make the directory the single source of truth and remove imported duplicates.
What to do next
Enrolment is plumbing; the programme itself runs on security awareness training - story-driven courses, quizzes and branded certificates on a monthly cadence. Enrolment just guarantees the right people are in it from day one.
FAQ
Does Cyber Aware sync automatically from Google Workspace?
Yes. Auto Enrol lists Google Workspace alongside Microsoft 365, CSV upload and signup links as enrolment sources, and new hires land in the default training schedule automatically with a welcome email.
Do I need domain-wide delegation?
Yes, on the Google side. Authorising a service account under Security > Access and data control > API controls > Manage Domain Wide Delegation is what grants the sync read access to your directory.
How long does the first sync take?
Authorisation usually takes minutes, though Google allows up to 24 hours in edge cases. Once authorised, a typical SMB directory syncs in minutes.
What happens when an employee leaves?
They are removed on the next sync, which stops ex-staff appearing as active learners in your reports.
Can I still use CSV upload?
Yes, but mixing CSV with a live sync creates duplicates. Pick the directory as the source of truth.
What runs after enrolment?
Story-driven courses monthly, with quizzes, leaderboards and branded completion certificates, plus automatic remediation for anyone who fails a phishing simulation.
One last thing
Run the first sync against a client with a hiring freeze, not your fastest-growing one. A static directory gives you a clean cycle to prove arrival and leaver rules before real joiner traffic stresses the setup.