Google Workspace settings
Google Workspace settings
Google Workspace settings connect a school to its Google domain and control what Realsmart provisions there. They live under Google Workspace in the sidebar, split into four sub-areas so each setting has one clear home: Settings (this page — connection and what to sync), OU settings, Classroom and Groups.
Google Workspace enabled, at the top of the Connection section, is the master switch: with it off, nothing syncs to Google for the school no matter what the rest of the page says. It is the same switch as Google sync on School settings → Sync services — change it in either place and both update. See Enable or disable sync services. Everything else on this page controls how Google sync behaves once it is on.
Before you start
- You must be a school admin with sync settings permission, with a school selected in the switcher.
- You will need your school's Google primary domain (e.g.
school.org) and a Google admin account to sign in with. - Setting up the underlying access (below) is a job for whoever administers your Google Workspace / Google Admin console. If that is not you, share the "access the service account needs" section with them.
Steps
Step 1 — Open Google Workspace settings {#step-1}
In the sidebar, open Google Workspace → Settings. The Connection section is shown first; a section switcher lets you move between Connection and Sync.
Step 2 — Enter the connection details {#step-2}
The Connection section is split into Service, Domains and Admin account. Fill in:
- Google Workspace enabled — the master switch described above. Leave it on for a school that syncs to Google.
- Primary domain — your main Google Workspace domain, e.g.
school.org. This is the domain your users' Google email addresses end in. - Secondary domain — only if your school also uses a second verified domain in the same Google tenant. Leave blank if you have just one.
- Admin user — a Google super administrator account (e.g.
[email protected]). The sync acts as this account when it makes changes in your domain. - Admin password — the password for that admin account. This is a masked field: once saved it shows as dots, and leaving it blank when you next edit keeps the stored value unchanged. Only type in it when you need to replace the password.
Step 3 — Choose what to sync {#step-3}
Switch to the Sync section and turn on the parts you want Realsmart to keep in step with Google. The section is split into three blocks — Passwords, Groups and Classroom, and Profile details — so related switches sit together.
User accounts themselves have no separate switch: while Google Workspace enabled is on, Realsmart creates, updates and suspends Google accounts to match Realsmart. The blocks below narrow what else is written.
Passwords — see Choose who password sync applies to below.
Groups and Classroom
- Sync groups — provision Google groups and their membership. Turn it off to hold every group change back for this school; user accounts are unaffected.
- Group types to sync — narrow which kinds of group go to Google; see Choose which group types sync.
- Don't sync Classroom teachers — leave Classroom teacher membership alone rather than have the sync manage it.
Profile details
- Sync mentor profile pictures / Sync learner profile pictures — push Realsmart profile photos up to Google for staff and/or students.
- Sync organisation profile — writes each staff member's organisation details (job title, department and similar) into their Google Workspace profile. Learners are never included.
Choose who password sync applies to {#passwords}
Two controls in the Passwords block decide whose Google passwords Realsmart is allowed to change.
- Sync passwords to Google — the school-wide switch. Push password sets/resets from Realsmart to Google. Turn this off if your school manages Google passwords elsewhere and you do not want Realsmart to change them: existing users then keep whatever password they have in Google, and password changes in Realsmart are not pushed. Two things still happen with it off — new Google accounts are always created with their initial Realsmart password (Google requires one), and if you later turn the switch back on, each user's current Realsmart password is pushed on their next sync so the two sides line up again.
- Skip password sync for these user types — carve-outs for individual kinds of user, so you do not have to choose between "everyone" and "nobody". Tick Students, Staff, Admins, Governors or Observers and those users keep whatever password they already have in Google, even while the switch above is on. Everyone else still syncs as normal.
A worked example: to push student passwords to Google but leave staff and admin passwords alone, leave Sync passwords to Google on and tick Staff and Admins.
The same two exceptions apply per type as they do to the school-wide switch — a brand-new Google account for an excluded user is still created with its initial Realsmart password, and unticking a type again pushes each affected user's current Realsmart password on their next sync. Leave every type unticked to sync passwords for everyone — that is the default. Ticking types has no effect while Sync passwords to Google is off, because nothing is being pushed anyway.
Choose which group types sync {#group-types}
With Sync groups on, Group types to sync lets you narrow which kinds of group go to Google, instead of all of them. Tick any combination of:
- Teachers of — the "teachers of" groups.
- Houses — house groups.
- Registration groups — registration / form groups.
- Role groups — the fixed role groups (learners, mentors, teaching staff, non-teaching staff, governors, observers, Ofsted).
- Year groups — year-group cohorts.
- Subjects — subject groups from Provision Subjects.
- Groups — the catch-all: classes and anything else, including groups you create by hand and any group that hasn't been classified into a type yet.
Leave every type unticked to sync them all — that's the default and matches how Google sync behaved before this option existed. This filter only takes effect while Sync groups is on. A per-group opt-out (Sync this group to Google on the group itself) still applies underneath — a group syncs only if its type is selected here and it's opted in. This is the same taxonomy as the Entra selector, so a trust can scope both platforms the same way.
Ticking Groups (or leaving every type unticked) also picks up any group that has no type set yet — a backstop so an unclassified group never silently drops out of sync. The other types match only their own kind.
Deselecting a type is not a purge: Realsmart simply stops managing that type in Google, leaving any groups it already created in place.
Preview which groups will sync {#group-preview}
Below the type checkboxes, Groups that will sync previews exactly which groups match your current selection for this school — grouped by type, with a count you can expand to see the group names. It updates live as you tick and untick types, before you save. It's hidden while Sync groups is off.
Step 4 — Save, then test the connection {#step-4}
Select Save settings. Then confirm the connection actually works using Sync → Test connection — it does a read-only check with the real credentials and never changes anything. See Test connection / Test permissions.
How the connection works: service account and domain-wide delegation
You do not paste a secret key into Realsmart for Google. Instead, Realsmart's provisioning runs as a Google service account — a non-human Google identity — and your Google administrator grants that service account permission to act inside your domain. This is called domain-wide delegation.
In practice, your Google administrator does this once, in the Google Admin console (under Security → API controls → Domain-wide delegation): they add Realsmart's service account client ID and authorise it for the specific scopes listed below. The admin user you entered above is the account the service account impersonates when it works in your domain.
If the connection test reports a missing capability, it almost always means one of these scopes has not been authorised yet — re-authorise the service account for the missing scope in the Google Admin console.
The access the service account needs (scopes)
These are the exact Google API scopes the sync uses. Your Google administrator authorises them for Realsmart's service account when they set up domain-wide delegation. Grouped by what they are for:
Directory (users, groups, organisation units)
https://www.googleapis.com/auth/admin.directory.userhttps://www.googleapis.com/auth/admin.directory.grouphttps://www.googleapis.com/auth/admin.directory.orgunithttps://www.googleapis.com/auth/apps.groups.settings
Google Classroom
https://www.googleapis.com/auth/classroom.courseshttps://www.googleapis.com/auth/classroom.coursework.mehttps://www.googleapis.com/auth/classroom.coursework.studentshttps://www.googleapis.com/auth/classroom.rostershttps://www.googleapis.com/auth/classroom.announcements
Drive and Calendar
https://www.googleapis.com/auth/drivehttps://www.googleapis.com/auth/calendar
Classroom guardian links — additionally used when managing Google Classroom guardian (parent) invitations:
https://www.googleapis.com/auth/classroom.guardianlinks.students
Grant the full list even if you do not use every feature today — missing a scope only shows up later as a failed capability in the connection test. If your school does not use Classroom, its scopes simply go unused.
The other Google sub-areas
The rest of the Google settings have their own pages so they stay manageable:
- OU settings — the organisation-unit roots for learners and mentors and the path templates that decide where each account is placed. See Google OU settings.
- Classroom — provision Google Classroom, Classroom reporting, the fallback owner for orphaned classes, and what happens to classrooms between years. See Google Classroom settings.
- Groups — the default membership role mentors get in Google groups. See Google group settings.
What's on the Sync tab now
The Sync tab of School settings holds the remaining MIS/provisioning options — fetch groups from the MIS, import parents, MIS profile pictures, purge retention, the provisioning date window — plus pre-admission import. Google-only options such as Sync organisation profile live here under Google Workspace → Settings, not on that shared Sync tab.