You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用Java编程为任意邮箱创建Google Cloud Identity?

用Java编程创建Google Cloud Identity用户

要创建仅包含Google Cloud Identity的用户(而非完整Google Workspace账号),核心是在调用Directory API的users.insert时不分配任何Workspace许可证,同时保持必要的用户基础属性。以下是具体实现步骤和代码示例:

关键区别说明

Google Cloud Identity用户是域内的基础身份实体,仅提供身份管理能力(如SSO、2FA),无Workspace应用(Gmail、Drive等)访问权限;而Workspace用户会被分配对应的服务许可证。

实现步骤

  • 确认权限与API启用:确保服务账号已被授予User Management Admin或Identity Administrator角色(在Google Admin Console的IAM设置中配置),且已启用Admin Directory API(在Google Cloud Console中启用)
  • 复用现有服务初始化代码:你之前创建Workspace用户时的服务认证逻辑完全可以复用,无需修改
  • 调整用户创建参数:仅设置Cloud Identity所需的基础字段,不添加Workspace许可证

代码示例

import com.google.api.services.admin.directory.Directory;
import com.google.api.services.admin.directory.model.User;
import com.google.api.services.admin.directory.model.UserName;
import java.util.Collections;

public class CloudIdentityCreator {
    public static void main(String[] args) throws Exception {
        // 初始化Directory服务(复用你已有的认证逻辑)
        Directory directoryService = initializeDirectoryService();

        // 构建Cloud Identity用户对象
        User cloudIdentityUser = new User();
        
        // 核心字段:必须是你的域下的邮箱
        cloudIdentityUser.setPrimaryEmail("jane.doe@your-domain.com");
        // 设置临时密码,强制用户登录时修改
        cloudIdentityUser.setPassword("TempPass_2024!");
        cloudIdentityUser.setChangePasswordAtNextLogin(true);
        // 同意服务条款
        cloudIdentityUser.setAgreedToTerms(true);

        // 设置用户姓名
        UserName userName = new UserName();
        userName.setGivenName("Jane");
        userName.setFamilyName("Doe");
        cloudIdentityUser.setName(userName);

        // 关键:不分配任何Workspace许可证(显式设为空或不设置该字段)
        cloudIdentityUser.setLicenses(Collections.emptyList());

        // 执行创建请求
        User createdUser = directoryService.users().insert(cloudIdentityUser).execute();
        
        System.out.println("Cloud Identity用户创建完成:" + createdUser.getPrimaryEmail());
    }

    // 复用你已有的Directory服务初始化方法
    private static Directory initializeDirectoryService() throws Exception {
        // 这里替换为你的实际服务账号认证代码
        // 示例:
        /*
        GoogleCredentials credentials = ServiceAccountCredentials.fromStream(
                new FileInputStream("your-service-account-key.json"))
                .createScoped(Collections.singleton(DirectoryScopes.ADMIN_DIRECTORY_USER));
        
        return new Directory.Builder(GoogleNetHttpTransport.newTrustedTransport(),
                JacksonFactory.getDefaultInstance(), request -> credentials.initialize(request))
                .setApplicationName("Cloud Identity Creation Tool")
                .build();
        */
        return null;
    }
}

验证方式

创建完成后,可在Google Admin Console的「用户」列表中找到该用户,查看其「许可证」标签页,会显示「无已分配的许可证」,表明这是一个仅含Cloud Identity的用户。

内容的提问来源于stack exchange,提问作者user1108687

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 00:53:11