Google Workspace (G Suite)
  • 3 Minutes To Read
  • Print
  • Share
  • Dark
    Light

Google Workspace (G Suite)

  • Print
  • Share
  • Dark
    Light

Google Workspace (formerly G Suite) is a collection of cloud computing, productivity, collaboration, device, user, and data management tools developed by Google.

Types of Assets Fetched

This adapter fetches the following types of assets:

  • Devices
  • Users

Prerequisites

To connect Axonius to Google Workspace you need to:

  1. Enable Cloud APIs
  2. Create a service account and grant permissions to that service account


Parameters

  1. Email of an admin account to impersonate (required) – The email of your Google Workspace (G Suite) admin.
  2. JSON Key pair for the service account (required) – Upload the JSON file you have created for your service account. For more details, see the sections below.
  3. Get OAuth Apps (required, default: False) - Select to fetch the OAuth applications used by each user.
Note
This data requires the following additional privilege to your Google Workspace (G Suite) admin account: https://www.googleapis.com/auth/admin.directory.user.security
  1. Fetch Cloud Identity Devices (required, default: False) - Select whether to fetch Cloud Identity devices.
    • If enabled, the connection for this adapter will also fetch Cloud Identity devices.
    • If disabled, the connection for this adapter will not fetch Cloud Identity devices.
    NOTE

    Fetching Cloud Identity devices requires:

    • Cloud Identity API enabled.
    • Additional privilege to your Google Workspace (G Suite) admin account: https://www.googleapis.com/auth/cloud-identity.devices.readonly
  2. Fetch Chrome Browsers (required, default: False) - Select whether to fetch Chrome browsers information.
    • If enabled, the connection for this adapter will fetch information about Chrome browsers.
    • If disabled, the connection for this adapter will not fetch information about Chrome browsers.
    NOTE

    Fetching Chrome browsers information requires an additional privilege to your Google Workspace (G Suite) admin account: https://www.googleapis.com/auth/admin.directory.device.chromebrowsers.readonly

  3. For details on the common adapter connection parameters and buttons, see Adding a New Adapter Connection.

image.png

Advanced Settings

  1. Fetch MDM devices (required, default: True) - Select whether to fetch MDM devices from Google Workspace.
    • If enabled, all connections for this adapter will fetch MDM devices.
    • If disabled, all connections for this adapter will not fetch MDM devices.
NOTE

For details on general advanced settings under the Adapter Configuration tab, see Adapter Advanced Settings.

Enabling Cloud APIs

To enable the Cloud APIs:

  1. Go to the Google Cloud Console and select the project that you want Axonius to connect to.

  2. Go to APIs & Services -> Dashboard.
    image.png

  3. Verify the following APIs are listed:

    • Admin SDK API - Required the basic data fetch.
    • Cloud Identity API - Required only to fetch Cloud Identity devices.

If it does not appear in the list, click Enable APIs and Services at the top of the screen, search for Admin SDK. Then click Enable.

Creating a Service Account

To create a service account:

  1. Go to the Google Cloud Console and select the project that you want to create the service account in.

  2. Go to IAM & admin -> Service accounts.
    image.png

  3. Click Create Service Account and fill in the details.
    image.png

  4. In the next tab, continue without setting any roles.
    image.png

  5. Next, click Create Key and create a JSON type key:
    image.png

  6. Your JSON key will be downloaded. Finish creating the user and go back to the service accounts screen.

  7. Click on the newly created service account and then click the Edit link in the top.

  8. Click Show Domain-Wide Delegation and select Enable G Suite Domain-wide Delegation.

  9. Click Save to finalize the changes.
    image.png

  10. Go back to the service accounts list. you can now view the client-id for the service account. Copy it.

  11. Open the G Suite Admin Panel and search for Manage API Client Access, then open it.

image.png

  1. In the client name field , specify your client id of the service account. In the One or More API Scopes section, specify these scopes:

    • Required scopes:
    https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly
    
    • Additional scope to fetch OAuth applications:
    https://www.googleapis.com/auth/admin.directory.user.security
    
    • Additional scope to fetch Cloud Idendity devices:
    https://www.googleapis.com/auth/cloud-identity.devices.readonly
    
    • Additional scope to fetch Chrome browsers information:
    https://www.googleapis.com/auth/admin.directory.device.chromebrowsers.readonly
    

    image.png

  2. Click Authorize.

Was This Article Helpful?