1. Go to the Domain-wide delegation settings in Google Workplace's Admin console (admin.google.com), you can get here by navigating to -> Security -> API Controls -> Domain-wide delegation.
2. Find the entry for OnINBOX, press edit, add a new scope "https://www.googleapis.com/auth/admin.directory.group.readonly" and press "Authorise" to confirm.
1. Go to the App registrations page on the Microsoft Azure Active Directory Portal (portal.azure.com)
2. Find the entry for OnINBOX and click on it
3. On the left hand side menu, select API Permissions
4. Press "Add a permission" -> "Microsoft Graph" -> "Application permissions" and select "GroupMember.Read.All"
5. Check that admin consent is granted for the new configured permission, if it isn't, press the "Grant admin consent" button.