The issue is likely related to the Directory API and GCDS bug where when GCDS created a google group it set the "adminCreated" to false, which is what GCDS relies on to sync AD groups to their corresponding Google groups.
It appears on June 1st they will be fixing this bug and there may be some unexpected or increase in processing of changes through GCDS.
I'm waiting on Google Support to confirm that this is the issue we're seeing, and if they're able to make the change on the backend (which they'll do June 1st anyways) as it's a read-only value to my knowledge.
The reason I am 99.999% certain this is the bug/issue is that several groups were created through GCDS and all but the one group in question have adminCreated be True. All the groups were created at the same time during the same run, so it would be odd that GCDS would make 5/6 groups True and 1/6 false..
--
Dear Google Workspace for Education administrator,
You are receiving this communication because your organization uses Google Cloud Directory Sync (GCDS).
We’re writing to let you know about the upcoming updates to Directory API and GCDS. This update ensures that your synchronization process correctly identifies and includes security groups created directly in the Google Admin console, starting June 1, 2026.
We’ve provided additional information to guide you through this change and how it impacts your environments.
What this means for your organization
Key changes: Previously, a technical issue in the Directory API prevented some security groups created in the Admin console from receiving the "adminCreated” flag. Because GCDS uses this flag to determine which groups it should manage, these groups were often omitted from the sync scope.
Starting June 1, 2026:
- Directory API Update: The API will now correctly flag security groups created directly in the Admin console as adminCreated.
- GCDS Sync Scope: During future synchronizations, GCDS will recognize these groups. If they fall within your defined Search Rules, GCDS will attempt to manage them, including synchronizing their members from your LDAP directory.
Potential impact:
- New Sync Scope: Security groups newly created in the Admin console starting June 1, 2026 that were previously ignored will now be evaluated by the GCDS sync engine.
- Unintended Deletions: If your GCDS Google Group deletion policy is set to "Delete Google Workspace groups not found in LDAP", GCDS may now attempt to delete these newly recognized security groups if a matching group does not exist in your LDAP server.
- Membership Overwrites: For groups now recognized by the sync, GCDS will update the membership list to match your LDAP source, which may overwrite any memberships previously added manually in the Admin console.
What you need to do
Action advised:
- Review Sync Settings: Review your GCDS Google Group configuration, specifically the deletion policies under the "Google Group Search Rule" and "General" tabs.
- Perform a Simulated Sync: After the fix is deployed, run a Simulated Sync to identify if any existing security groups are now being flagged for deletion or modification before attempting an actual sync.
- Update Exclusion Rules: If you have security groups in Google Workspace that you do not want GCDS to manage or delete, implement Google Group Exclusion Rules to protect them.
Timelines:
This update will take effect in 35 days. Ensure your configuration is reviewed and updated by June 1, 2026 to avoid any unintended data loss.
We’re here to help
For more information on managing groups and exclusion rules, refer to our
If you have questions, or require additional help, please contact (Issue Number: 489456912).
Thanks for choosing Google Workspace for Education.
– The Google Workspace for Education Team