如何使用Java编程为任意邮箱创建Google Cloud Identity?
用Java编程创建Google Cloud Identity用户
要创建仅包含Google Cloud Identity的用户(而非完整Google Workspace账号),核心是在调用Directory API的users.insert时不分配任何Workspace许可证,同时保持必要的用户基础属性。以下是具体实现步骤和代码示例:
关键区别说明
Google Cloud Identity用户是域内的基础身份实体,仅提供身份管理能力(如SSO、2FA),无Workspace应用(Gmail、Drive等)访问权限;而Workspace用户会被分配对应的服务许可证。
实现步骤
- 确认权限与API启用:确保服务账号已被授予
User Management Admin或Identity Administrator角色(在Google Admin Console的IAM设置中配置),且已启用Admin Directory API(在Google Cloud Console中启用) - 复用现有服务初始化代码:你之前创建Workspace用户时的服务认证逻辑完全可以复用,无需修改
- 调整用户创建参数:仅设置Cloud Identity所需的基础字段,不添加Workspace许可证
代码示例
import com.google.api.services.admin.directory.Directory; import com.google.api.services.admin.directory.model.User; import com.google.api.services.admin.directory.model.UserName; import java.util.Collections; public class CloudIdentityCreator { public static void main(String[] args) throws Exception { // 初始化Directory服务(复用你已有的认证逻辑) Directory directoryService = initializeDirectoryService(); // 构建Cloud Identity用户对象 User cloudIdentityUser = new User(); // 核心字段:必须是你的域下的邮箱 cloudIdentityUser.setPrimaryEmail("jane.doe@your-domain.com"); // 设置临时密码,强制用户登录时修改 cloudIdentityUser.setPassword("TempPass_2024!"); cloudIdentityUser.setChangePasswordAtNextLogin(true); // 同意服务条款 cloudIdentityUser.setAgreedToTerms(true); // 设置用户姓名 UserName userName = new UserName(); userName.setGivenName("Jane"); userName.setFamilyName("Doe"); cloudIdentityUser.setName(userName); // 关键:不分配任何Workspace许可证(显式设为空或不设置该字段) cloudIdentityUser.setLicenses(Collections.emptyList()); // 执行创建请求 User createdUser = directoryService.users().insert(cloudIdentityUser).execute(); System.out.println("Cloud Identity用户创建完成:" + createdUser.getPrimaryEmail()); } // 复用你已有的Directory服务初始化方法 private static Directory initializeDirectoryService() throws Exception { // 这里替换为你的实际服务账号认证代码 // 示例: /* GoogleCredentials credentials = ServiceAccountCredentials.fromStream( new FileInputStream("your-service-account-key.json")) .createScoped(Collections.singleton(DirectoryScopes.ADMIN_DIRECTORY_USER)); return new Directory.Builder(GoogleNetHttpTransport.newTrustedTransport(), JacksonFactory.getDefaultInstance(), request -> credentials.initialize(request)) .setApplicationName("Cloud Identity Creation Tool") .build(); */ return null; } }
验证方式
创建完成后,可在Google Admin Console的「用户」列表中找到该用户,查看其「许可证」标签页,会显示「无已分配的许可证」,表明这是一个仅含Cloud Identity的用户。
内容的提问来源于stack exchange,提问作者user1108687
相关产品推荐
相关产品推荐

