Fix Google Workspace API Permission Errors
If your Google Workspace migration stalls with an "insufficient permission" or "unauthorized_client" message the moment you try to authenticate, you're dealing with one of the most common roadblocks in Google Workspace migrations. It almost always comes down to a Google Cloud project that isn't fully wired up for domain-wide access, not a problem with the migration tool itself.
This guide walks through why the error shows up, how to trace it back to its actual source in Google Admin Console and Google Cloud Console, and how to get EdbMails Google Workspace Migration Tool re-authenticated once the permissions are corrected. EdbMails uses a service account with domain-wide delegation to migrate mailboxes without needing individual user passwords, which means the entire migration depends on Google authorizing that service account correctly. Get one scope or one policy wrong, and authentication fails before a single mailbox even starts moving.


