This article explains how to configure Google Workspace for ChromeOS within Lenovo Device Orchestration (LDO). This setup enables LDO to securely connect with your organization’s Google Cloud environment and retrieve ChromeOS device data for monitoring and management.
Once the configuration is complete, you can proceed to onboard ChromeOS devices to Device Management.
Only one Google Cloud connection can be configured per LDO organization.
I. Open two browser tabs. You will need these tabs throughout the process.
- Go to the Google Workspace Admin and log in.
- Go to Google Cloud and log in. https://console.cloud.google.com/
II. Create a Google Cloud Project and enable API Access
- Go to the Google Cloud tab. In the left-hand menu, click APIs & Services > Enabled APIs & services.
- Click Create Project, then enter a project name (e.g. “ldo-cloudconnector”).
- On the project page, select Enable APIs and services.
- In the library, search for the Admin SDK API, then enable it.
- Return to Enable APIs and services.
- Search for the Chrome Management API and enable it.
III. Create a Google Cloud Service Account
- On the same tab, in the left-hand menu, click IAM & Admin > Service Accounts.
- Select the Project you created (if not already selected) and click Create a Service Account.
- Complete the folowing fields:
- Service Account Name (e.g. “ldo-cloudconnector-user”).
- Service Account ID (automatically generated by Google).
- Service Account Description (optional).
- Continue without granting roles or permissions to this service account.
- Copy the service account email (e.g. “ldo-cloudconnector-user@ldo-cloudconnector.iam.gserviceaccount.com”).
IV. Create Credentials for the Service Account
- On the same tab:
- Select the Service Account you just created.
- Go to Keys > Add Key > Create New Key.
- Select JSON.
- The JSON Credential will be downloaded to your device (keep this file secure).
V. Configure Domain-wide Delegation
- Return to Service Accounts on the same tab in Google Cloud.
- Select the Service Account you just created.
- Expand Advanced Settings and copy the Client ID (e.g. “123456789012345678901”).
- Switch to the Google Workspace Admin tab.
- Go to Security > Access and data control > API Controls
- Click Manage Domain Wide Delegation > Add New
- Paste the Service Account’s Client ID.
Paste the following OAuth Scopes (one at a time):
- Authorize and confirm consent.
VI. Enable Device Telemetry Reporting
- Log in to Google Workspace Admin https://admin.google.com .
- Go to Devices > Chrome > Settings > Device Settings.
- Scroll to User and Device Reporting section, select Report Device Telemetry.
- If not already, enable the following components for your Organizational Unit:
- Power Status
- Network Status
- Storage Status
Network Configuration
- Save Changes.
VII. Create Google Workspace Admin Role
- On the same tab, go to Account > Admin Roles.
- Create new role and name it (e.g. “LDO Connector Admin”)
- Select the following Privileges (you will have to scroll several pages):
- Chrome Management > Manage ChromeOS Devices > Read > Telemetry API
- Organization Units > Read
- Click Continue and Create role.
- Click Assign service accounts
- Enter the service account email address (e.g. “ldo-cloudconnector-user@ldo-cloudconnector.iam.gserviceaccount.com”). To copy and paste, switch to the Google Cloud tab, in the left-hand menu, select IAM & Admin > Service accounts.
- Click Add and Assign Role.
- Sign in to LDO.
- Go to Configuration & Settings > Organization Settings > Organization Account > Connectors tab.
- Click Add Connection.
- Enter the Customer ID from the Google Workspace Admin tab.
- Enter your Google Workspace administrator email address.
- Upload the JSON file you downloaded earlier.
- Click Connect.
- After the connection is established, you can onboard ChromeOS devices. For more information, see Onboarding Chrome Devices.
Managing Connectors
- Click Manage connector.
- Update the connector settings as needed or upload a new file.
- If applicable, update the Admin email address.
- Click Connect.
Disconnecting Google Cloud Connector
- Click Disconnect Platform.
- Optionally, select Remove all Chrome devices from LDO to remove all onboarded ChromeOS devices and their associated UDS services.
- Click Proceed.