Google Workspace
You can find this module at the Company level only.
Setting up Google Workspace scanning requires configuration in the Google Workspace Console, the Admin portal, and the ConnectSecure integration.
Google Workspace - Table of Contents
Visit our YouTube Channel for more video content: https://www.youtube.com/@connectsecure
Google Workspace - Overview
Access the Google Workspace from the company-level module, Cloud Assessments.
Google Workspace Setup
Login to your Google Workspace account using an account with super admin permissions.
https://cloud.google.com
Tap on the Console option
Navigate to IAM & Admin and select Create a Project.
Create a new project. Enter a project name. By default, the Organization and Location should auto-populate. Your project name is your choice, you can use something like ConnectSecure.
Once the new project is created, navigate to API & Services > Library from the left navigation menus.
Use the search box and query for Google Workspace Events API and Admin SDK API. You will need to tap into each of these selections and tap the Enable button.
Repeat these steps for the Admin SDK API
Next, we will create service accounts for the project. Tap on the left menu and choose IAM. If you do not see this option, you can search for it at the top, as shown below.
Near the top, top on the + Create service account button.
Enter the service account details and click the Create and continue button. You only need to set the name up, which is a name of your choice. The service account ID will fill itself in based on your service account name.
Assign the Owner role to the project service account.
Tap on Continue.
The following section is optional, simply tap on Done.
Select the created Service Account and navigate to Keys, where you will need to Add Key.
Use the Add key > Create new key option menu.
Select JSON as the Key Type and click on Create.
This will download the credentials JSON. Keep a copy of the JSON. This is required in the ConnectSecure portal for integration setup.
Once the credential.json is downloaded, go back to the Service Account, and you can see the OAuth2 Client ID; please copy this for the next steps.
Browse to admin.google.com
Navigate to Security > Access and data Control > API Controls
Tap on Domain Wide Delegations.
Add New Client ID.
Copy/paste in the OAuth2 Client ID from the steps above.
We must assign the 5 permissions scopes below to this new Client ID. You can add them with a single copy/paste using the box below. The individual URL’s are also available below.
https://www.googleapis.com/auth/admin.reports.audit.readonly, https://www.googleapis.com/auth/admin.directory.user.security, https://www.googleapis.com/auth/admin.directory.user.readonly, https://www.googleapis.com/auth/admin.directory.user, https://www.googleapis.com/auth/admin.directory.rolemanagement
https://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/admin.directory.user.security
https://www.googleapis.com/auth/admin.directory.user.readonly
https://www.googleapis.com/auth/admin.directory.user
https://www.googleapis.com/auth/admin.directory.rolemanagement
Proceed to the ConnectSecure Portal to continue setup
ConnectSecure Setup
Login to the ConnectSecure portal and navigate to Global > Settings > Integrations > Google Workspace.
Credentials
Enter a name to the integration, use the super credential username, and upload the credentials.json downloaded from the Google Workspace account from the steps above.
Once the credentials are saved, please finish the company mapping, navigate to Company>>Cloud Assessment module>>Google Workspace, and click SYNC.
Google Workspace - Action Toolbar Overview
Google Workspace - Action Toolbar Details
Jobs
Tap to view the Google Workspace-related jobs data.
Alerts
Tap to view the timeline style of System Events with filtering options.
Info
Tap to view the Getting Started info; see the link below for additional information.
https://cybercns.atlassian.net/wiki/x/MIDKfw
Need Support?
You can contact our support team by emailing support@connectsecure.com or visiting our Partner Portal, where you can create, view, and manage your tickets.
https://cybercns.freshdesk.com/en/support/login