CASB: Google drive onboarding to Data Security fails with error "invalid_grant: java.security.SignatureException: Invalid signature for token"

CASB: Google drive onboarding to Data Security fails with error "invalid_grant: java.security.SignatureException: Invalid signature for token"

174
Created On 06/18/26 00:45 AM - Last Modified 06/18/26 01:29 AM


Symptom


  • The Google Drive integration with Data Security fails with the error message: "invalid_grant: java.security.SignatureException: Invalid signature for token"

invalid grant 

  • The permissions are all configured as per the public documentation, but the issue occurs because the region for the app on Google Workspace and the tenant's region do not match.
  • For example, if a customer is located in South Korea but the Data Security tenant is in the Japan region, as per the documentation, the app "Palo Alto Networks Gdrive- JP" should be installed since the tenant is in the Japan region.
  • But due to a restriction from the Google side, if the Workspace account is in South Korea, installing "Palo Alto Networks Gdrive- JP" is not allowed.
  • The user then installs app from another region (Example  Palo Alto Networks Gdrive- Aus) and uses the corresponding Client ID for domain wide delegation.
  • When using same app Palo Alto Networks Gdrive- Aus and JP client ID for this app, the onboarding still fails. 


Environment


  • Palo Alto Data Security
  • Strata Cloud Manager
  • CASB-X/CASB-PA (Cloud Access Security Broker)


Cause


  • As the error message indicates, this is an issue where the Google workspace is rejecting the authentication during onboarding.
  • Since the data security region is in Japan, the Google Workspace expects the domain wide delegation from JP client ID. 
  • But since the JP app is not allowed in non Japan region (when the customer's google account is not in Japan region), this cannot be done. 


Resolution


  1. Follow the documentation to onboard the Google drive as it is and on the domain wide delegation step, Add 2 entries.
  2. One would be correspond to the region whose app is installed. For example, here we used  Palo Alto Networks Gdrive- Aus so the client ID will be 117916877802214783504
  3. Another entry needs to be created for the same app but with the Japan/JP client ID 105441676635767149048 since the tenant is in JP region.
  4. Both of these client ID needs to have the same permissions as per per the document
  5. Both these client ID's are required and missing either one would cause the permission issue. 


Additional Information


The same logic can be applied for other regions as well if the region app isn't available for a customer located in another country.

 



Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA1Ki000000sYy3KAE&lang=en_US&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail