Configuring Google Workspace Integration for ChromeOS
This article explains how to configure Google Workspace for ChromeOS within Lenovo Device Manager (LDM). This setup enables LDM to securely connect with your organization’s Google Cloud environment and retrieve ChromeOS device data for monitoring and management. Once the configuration is complete, you can proceed to onboard ChromeOS devices to LDM.
Only one Google Cloud connection can be configured per LDM organization.
I. Find Google Workspace Account Customer ID
- Log in to Google Admin > Account > Account Settings
(https://admin.google.com/ac/accountsettings) (e.g. C02fy2zib)
II. Create a Google Cloud Project and enable API Access
- Go to https://console.cloud.google.com/apis/dashboard
Create a Project (e.g. “ldm-cloudconnector”)
Select
Enable APIs and Services
In the library, search for and enable Admin SDK API
- Search for Chrome Management API and enable.
III. Create a Google Cloud Service Account
- Log in to Google Workspace Admin (https://admin.google.com)
- Go to https://console.cloud.google.com/iam-admin/serviceaccounts
- Select the Project you created and click Create a Service Account
- Service Account Name (e.g. “ldm-cloudconnector-user”)
- Service Account ID (Google will automatically generate one)
- Service Account Description
- Continue without granting roles or permissions to this service account
- Copy the service account email (e.g. “ldm-cloudconnector-user@ldm-cloudconnector.iam.gserviceaccount.com”)
IV. Create Credentials for the Service Account
- Go to https://console.cloud.google.com/iam-admin/serviceaccounts
- Select the Service Account
- Go to Keys > Add Key > Create New Key
- Select JSON
- The JSON Credential will be downloaded to your device (keep this file secure)
V. Configure Domain-wide Delegation
- Go to https://console.cloud.google.com/iam-admin/serviceaccounts
- Select the Service Account
- Expand Advanced Settings and copy the Client ID (e.g. “123456789012345678901”
- Log in to Google Workspace Admin (https://admin.google.com)
- Go to Security > Access and data control > API Controls
- Click Manage Domain Wide Delegation > Add New
- Paste the Service Account’s Client ID that was copied earlier
- Paste the following OAuth Scopes:
https://www.googleapis.com/auth/chrome.management.telemetry.readonly,https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly - Authorize and Confirm Consent
VI. Enable Device Telemetry Reporting
- Log in to Google Workspace Admin (https://admin.google.com)
- Go to Devices > Chrome > Settings > Device Settings
- In the User and Device Reporting section, select Report Device Telemetry
- Enable the following components for your Organizational Unit:
- Power Status
- Network Status
- Storage Status
Network Configuration
- Click Save
VII. Create Google Workspace Admin Role
- Log in to Google Workspace Admin (https://admin.google.com)
- Go to Account > Admin Roles
- Create new role with a name (e.g. “LDM Connector Admin”)
- Select the following Privileges:
- Organization Units > Read
- Chrome Management > Manage ChromeOS Devices > Read > Telemetry API
- Continue the role creation process
- Assign Service Accounts
- Enter the service account email address (e.g. “ldm-cloudconnector-user@ldm-cloudconnector.iam.gserviceaccount.com”)
- Click Assign Role
- Login to LDM
- Go to Device Management > Devices and select + Add Device
- Under ChromeOS section, select please visit Policy Management > Connectors page to add/modify the connection details. Refer to Utilizing Policy Management.
Related Articles
Integrating Microsoft Entra ID with LDM
Register an Application in Microsoft Entra ID Navigate to the Microsoft Azure Portal. Proceed to Microsoft Entra ID > App registrations and select New registration. Register a new application. Securely note the following generated values: Application ...
Intel® EMA CIRA Connection Issues
There may be occasions when the EMA CIRA connection will display the status as Not Connected in the Device tray - please refer to Accessing Device information - Windows operating system. This troubleshooting article will help you resolve the Not ...
Utilizing Policy Management
Policy Management provides customized settings for LDM organizations. This feature is available only for Org Admins and MSP Admins. Feature Settings Navigate to Policy Management > Feature Settings on the left pane. The following options are ...
Onboarding Chrome Devices to LDM
Lenovo Device Manager supports an automated process that simplifies the onboarding of Chrome devices. The setup is unique for the organization and must not be shared. To set up a new LDM account, it is mandatory to have a Lenovo ID and get an email ...
Remote BIOS Access and Configuration in LDM
This feature enables Org and MSP Admins to remotely change the BIOS password and manage BIOS settings through Lenovo Device Manager (LDM). To access a device’s BIOS settings: Go to the Devices menu in the left panel. Select a device to open the ...