Skip to main content

Google Workspace: 400 Admin Policy Enforced error

Written by Brady Price

If Secureframe appears in Accessed apps

This error appears when connecting or reconnecting the Google Workspace integration in Secureframe. Google is blocking Secureframe’s OAuth consent because of your organization’s third-party app access settings.

You need a Google Workspace Super Admin to complete these steps. Google Workspace SSO in Secureframe is not required to connect the integration.

  1. Sign in to admin.google.com as a Super Admin.

  2. Go to SecurityAccess and data controlAPI controls.

  3. Click Manage third-party app access.

  4. In the Accessed apps list, find Secureframe.

  5. Hover over Secureframe and click Change access.

  6. Click Next.

  7. Set access to Trusted (can access Google services), then save or confirm your changes.

  8. Return to Secureframe → Integrations and connect or reconnect Google Workspace.


If Secureframe is not listed

This is common when Google never completed OAuth for Secureframe, or when policies block new apps before they appear under Accessed apps. Add Secureframe as a trusted app first.

  1. Sign in to admin.google.com as a Super Admin.

  2. Go to SecurityAccess and data controlAPI controls.

  3. Click Manage third-party app access.

  4. Click Configure new app (or Add app) → OAuth App Name Or Client ID.

  5. Search for Secureframe, or paste this Client ID and click Search: 38013396501-r6ckr41c3b79acpsa48497jcinq7jkph.apps.googleusercontent.com

  6. Select the matching Secureframe app → Select.

  7. For Scope, choose Entire organization (or the organizational units that need the integration).

  8. For Access to Google data, choose Trusted: Can access all Google services.

  9. Click Configure (or finish the flow so Secureframe shows as Trusted).

  10. Return to Secureframe → Integrations and connect or reconnect Google Workspace.

Configure new OAuth app by name or Client ID in Google Admin
Search for Secureframe OAuth app in Google Admin

Note: The same Client ID often appears in the Google error’s request details next to client_id=. Searching by Client ID is usually more reliable than searching by app name.

If you also want to restrict other third-party OAuth apps while keeping Secureframe connected, see Restrict third-party OAuth apps in Google Workspace while keeping Secureframe connected.


Frequently Asked Questions (FAQ)

Do I need to set up Google Workspace SSO in Secureframe to connect the integration?

  • No. SSO is separate. Connecting Google Workspace as an integration only requires Google Workspace Super Admin permissions and Trusted third-party app access for Secureframe.

Secureframe still does not appear after I search by name. What should I try?

  • Paste the Client ID from the steps above (or from the client_id= value in the Google error details), then set the app to Trusted for your organization.

How is this different from “Unable to connect to Google Workspace due to insufficient admin permissions”?

  • 400 Admin Policy Enforced / admin_policy_enforced means Google’s app access policy is blocking Secureframe. The insufficient admin message means the signed-in Google user is not a Super Admin (or lacks the needed admin role). Use a Super Admin account and reconnect.

I set Secureframe to Trusted and still cannot connect. What next?

  • Confirm you finished saving in Google Admin, wait a few minutes for policy changes to apply, then reconnect from Secureframe. If it still fails, contact [email protected] with a screenshot of the Google error and a screenshot of Secureframe’s access setting in Manage third-party app access.

Did this answer your question?