Google Workspace
Tablets and phones managed by Google, versions of installed apps, domain accounts; setting up the service account.
The Google Workspace screen reads, without changing anything, the mobile devices managed by Google (model, Android version, last sync, linked account), the installed apps with their versions, and the accounts in your domain. Every lookup is logged.
The tabs
| Tab | Use |
|---|---|
| Tablets and phones | Search by account, name, model, serial number or installed app; device details (status, encryption, first sync, apps) |
| One app | The versions of one app across the estate: the newest version seen, the devices lagging behind, the ones that don't have it |
| Accounts | Accounts per organizational unit, last sign-in, suspended accounts |
When someone reports that an app is not up to date on some tablets, the One app tab gives you the list of lagging devices directly.
Installed apps are only reported for devices under advanced management at Google.
Connecting the connector (administrator)
- In Google Cloud, create a project, enable the Admin SDK API, create a service account and download its key (JSON). Note its numeric client ID.
- In the Google Admin console, Security → API controls → Domain-wide delegation: add that client ID with the read-only scopes shown in the FirstSI form.
- In FirstSI, under Connectors, new connector, Google Workspace: paste the content of the JSON file (it is checked, reduced to what is needed for signing, encrypted, and never shown again). Enter the administrator on whose behalf to read (a read-only account is enough if it can see the devices), the domain, the agent if any, and the allowed roles.
- Save, then Test.
Pre-diagnostics use it for tickets about tablets, and so does the AI assistant, for authorized roles.
Source: · FirstSI Docs · updated 2026-10-10