Connect Google Workspace with your GCP cloud instance
Connect Google Workspace with a Google Cloud Platform instance in Cortex Cloud.
To gain full visibility into GCP permissions and identity relationships, highlight risks, and offer proper remediation, Cortex Cloud must ingest user, group, and group membership data from your Google Workspace. You need to create a custom role in Google Workspace, assign it specific privileges, and then assign your Cortex Cloud service account to this newly created role.
1. Create a Cortex Cloud role in Google Workspace
Log in to your Google Admin Console.
In the left menu, select Account → Admin roles.
Click Create new role.
In the Role info page, enter a name for the role, such as
cortex-cloud-security-role.(Optional) Enter a description.
Click Continue.
In the Select Privileges page, in the Privilege Name list, under Admin API, select the following privileges:
Organization Units > Read (This automatically selects the Organizational Units > Read permission. Leave it selected.)
Users > Read
Groups > Read
Click Continue and then click Create Role.
2. Assign the Cortex Cloud service account to the created role
In Cortex Cloud, navigate to Settings → Data Sources & Integrations and select Google Cloud Platform (GCP) → View details.
Identify the GCP cloud instance and click the instance name to open the details pane for that instance.
In the details pane, click the more options icon at the top right corner and then select Authorization Details.
Copy the value of Cortex discovery role.
Log in to your Google Admin Console.
In the left menu, select Account → Admin roles.
Select the role created previously and click Assign role.
Click Assign service accounts and paste the value of the Cortex discovery role. Click Add.
Click Assign role.
Your Cortex Cloud service account has been successfully granted the necessary permissions in Google Workspace to ingest user, group, and group membership data. It may take several hours for the results to appear in Cortex Cloud, depending on the size of your cloud estate.
3. Enable Google Workspace in your GCP cloud instance
In Cortex Cloud, navigate to Settings → Data Sources & Integrations and select Google Cloud Platform (GCP) → View details.
Identify the GCP cloud instance and click Configuration at the right end of the cloud instance row.
In the Google Cloud Provider (GCP) onboarding wizard, click Show advanced settings.
Under Discovery Enhancements, select Connect to GCP Workspace.
Enter the organization ID of your Google Workspace. You can enter more than one organization ID.
Click Save.
You have successfully enabled the Google Workspace in your GCP cloud instance.
Last updated
Was this helpful?
