A GCP service account was delegated domain-wide authority in Google Workspace
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
2 Days
Required Data
Google Workspace Audit Logs
Detection Modules
Identity Threat Module, SaaS Threat Detection
Detector Tags
Google Workspace
ATT&CK Tactic
Privilege Escalation (TA0004)
ATT&CK Technique
Domain or Tenant Policy Modification (T1484)
Severity
Low
Description
A Google Workspace admin has enabled domain-wide delegation to a GCP service account.
Attacker's Goals
Malicious Apps can be used to access the organization's Google data.
Investigative actions
Check if the identity intended to perform this action or look for signs that the user account is compromised (e.g. abnormal logins, unusual activity).
Check if the new settings look suspicious.
Follow further actions done by the account.
Variations
Was this helpful?
