Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

Unable to Add Email from Custom Domain to Google Cloud Project

Hi,

I’m trying to add a coworker to my Google Cloud project, but I keep encountering the following error:

"Email addresses and domains must be associated with an active Google Account, Google Workspace account, or Cloud Identity account."

The email address I’m trying to add is active. 

I’ve checked the following:

  • The email is correctly set up and can receive and send emails.
  • The email address is associated with an active Google Account (we’ve verified this through login attempts).
  • I’ve double-checked for typos in the email address, and there are none.

Despite these steps, I’m unable to add the coworker to the project in the Google Cloud Console.

Has anyone encountered a similar issue or can provide advice on how to resolve this? Any assistance would be greatly appreciated.

Thank you!

2 6 777
6 REPLIES 6

Hello @PtrBld  ,Welcome on Google Cloud Community.


@PtrBld wrote:

The email address is associated with an active Google Account (we’ve verified this through login attempts).


What does it mean ? Does it mean that your email is ended with @gmail.com ( in example damian@gmail.com) or you have Google Workspace with active domain and your account is created with @your_google_workspace_domain (damian@example.com) ? 

--
cheers,
Damian Sztankowski
LinkedIn medium.com Cloudskillsboost Sessionize Youtube

Hi,

I am experiencing the same issue. Did you manage to get this resolved? 

@DamianS, in my case the account does not end with "gmail.com". I am able to go to: https://accounts.google.com and perform a login. I  can even go to: https://console.cloud.google.com/ after having logged in and I see that it recognized the google account.

Thanks.

Hi @DamianS, thanks for your response. 

The email is not ending in gmail.com and is also no Google Workspace email. We have created a new google account and associated it with our existing work email. I assume that @Ton1 did the same thing? We can also login to accounts.google.com and console.cloud.google.com.

As a workaround you can use googlegroups but it not ideal and makes it harder to provide the correct roles to my colleagues.

Hello Gents,

 See, IAM is relying either only on GMAIL accounts ( <PII removed by staff>) OR emails / groups associated with Google Workspace ( this is the reason why you are able to grant access based on groups ).  Even, if you are using SSO, from Entra ID or Okta, you have to have replication to Google Workspace.  So if you don't have those emails ( accounts, being more precisely) at Google Workspace, you will not be able to handle IAM permissions to such accounts. 


@PtrBld wrote:

As a workaround you can use googlegroups but it not ideal and makes it harder to provide the correct roles to my colleagues.


Using groups instead of single principal, is according to Google Cloud best practices in terms of handling IAM cases. So, if you want to follow vendor's best practice, you should utilize email groups ( associated with workspace ) instead of single principal. 

 

Hi Damian,

Thanks for this answer. We have enabled GMAIL for the Google account we were trying to add and I have been able to add this principal now (by specifying his gmail address).

Thanks again.

@Ton1 ,
Fantastic ! Happy to help 🙂 

Top Labels in this Space
Top Solution Authors