Assign Google Workspace Licenses with Filters and Roles
Google Workspace guide
Use NIM filters and roles to apply the right Google Workspace license to each user automatically.
Before you begin
- Confirm that NIM can read your Google Workspace users and licenses.
- Identify the source-system data that distinguishes each license population, such as student status, employee ID, or role.
- Obtain the applicable Google Workspace SKU IDs for your tenant.
Configure Google license relationships
-
Go to Systems > Google > Users > Columns. In the
primaryEmailcolumn, enable Reference. -
Go to Systems > Google > License assignments > Relations and configure the following relationships:
license_assignments.userIdtousers.primaryEmailas a Reference.license_assignments.licensestolicenses.skuIdas a Key.- The many-to-many relationship between users and licenses, using
userIdandskuId.
The many-to-many relationship is required for licensing roles to work correctly.
-
Go to Systems > Google > License assignments > Columns. Do not assign a key or display name to the license-assignment column.
Create license filters
Create a separate NIM filter for every license population. Build each filter from imported source-system data—such as Skyward or PowerSchool—and compare it with Google user data as needed.
Common patterns include:
- A fundamental license for all students.
- A Plus license for users matching an employee ID or staff condition.
- A Gmail-only license for a specific student population.
Create the Google licensing role
- Create a role for the license population, then select the filter you created for it.
- Under Role items, select Add three times.
- Remove the Active Directory group and Google group role items, leaving Google > licenses > license_assignments > primaryEmail.
- Open the remaining role item and select the licenses that should apply to users in this role. The available SKU IDs vary by Google Workspace tenant.
Archive and restore licenses
To archive a user's license, update the disable mapping to set archive to true. When the user returns, have the enable filter set archive to false. The user receives a fundamental license until an applicable licensing role assigns a different one.
Verify the result
Run the appropriate synchronization or licensing job, then confirm that users matching each filter have the expected Google Workspace license assignment.