Google Workspace Advanced Permissions

OAuth Scopes

The following tables summarize all OAuth scopes and permissions required for the Google Workspace adapter in Axonius.

Google Cloud APIs to Enable

APIWhen to EnableRequired For Scopes
Admin SDK APIAlwaysAll admin.directory.* and admin.reports.* scopes
Cloud Identity APIIf using Cloud Identity featurescloud-identity.devices.readonly, cloud-identity.groups
Chrome Management APIIf enriching browser extensionschrome.management.reports.readonly
Chrome Policy APIIf enriching browser policieschrome.management.policy.readonly
Google Calendar APIIf fetching calendarscalendar
Groups Settings APIIf fetching group settingsapps.groups.settings
Service Usage APIIf fetching usage reportsadmin.reports.usage.readonly
Enterprise License Manager APIIf fetching licensesapps.licensing

Permissions for Connection Settings

Additional permissions

Connection NameScopeAPI
Get OAuth Appsadmin.directory.user.securityAdmin SDK API
Fetch Cloud Identity Devicescloud-identity.devices.readonlyCloud Identity API
Fetch Chrome Browsersadmin.directory.device.chromebrowsers.readonlyAdmin SDK API
Fetch CalendarscalendarGoogle Calendar AP

Permissions for Advanced Configurations

Configuration NameScopeAPI
Fetch MDM Devicesadmin.directory.device.mobile.readonlyAdmin SDK API
Fetch ChromeOS Devicesadmin.directory.device.chromeos.readonlyAdmin SDK API
Fetch user groupsadmin.directory.group.readonlyAdmin SDK API
Enrich Groups settingsapps.groups.settingsGroups Settings API
Fetch user rolesadmin.directory.rolemanagement.readonlyAdmin SDK API
Fetch Disk Usageadmin.reports.usage.readonlyAdmin SDK API + Service Usage API
Fetch Licensesapps.licensingEnterprise License Manager API
Fetch User Audit Logsadmin.reports.audit.readonlyAdmin SDK API
Fetch Extensionschrome.management.reports.readonlyChrome Management API
Fetch Settings (Policies)chrome.management.policy.readonlyChrome Policy API
Fetch Cloud Identity Device Userscloud-identity.devices.readonlyCloud Identity API
Fetch Applications (OAuth)admin.directory.user.securityAdmin SDK API

Scopes to Copy and Paste

These are the scopes that you can copy and paste.

Minimum Scopes to Copy

https://www.googleapis.com/auth/admin.directory.user.readonly,
https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,
https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly

Recommended for Standard Use to Copy

https://www.googleapis.com/auth/admin.directory.user.readonly,
https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,
https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly,
https://www.googleapis.com/auth/admin.directory.device.chromebrowsers.readonly,
https://www.googleapis.com/auth/admin.directory.group.readonly,
https://www.googleapis.com/auth/admin.directory.customer.readonly,
https://www.googleapis.com/auth/admin.directory.domain.readonly,
https://www.googleapis.com/auth/cloud-identity.devices.readonly,
https://www.googleapis.com/auth/admin.reports.usage.readonly,
https://www.googleapis.com/auth/apps.groups.settings

All Cyber Asset Scopes with Axonius SaaS Application to Copy

https://www.googleapis.com/auth/admin.directory.user.readonly,
https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,
https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly,
https://www.googleapis.com/auth/admin.directory.device.chromebrowsers.readonly,
https://www.googleapis.com/auth/admin.directory.group.readonly,
https://www.googleapis.com/auth/admin.directory.customer.readonly,
https://www.googleapis.com/auth/admin.directory.domain.readonly,
https://www.googleapis.com/auth/cloud-identity.devices.readonly,
https://www.googleapis.com/auth/admin.reports.usage.readonly,
https://www.googleapis.com/auth/apps.groups.settings,
https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly,
https://www.googleapis.com/auth/admin.directory.user.security,
https://www.googleapis.com/auth/admin.reports.audit.readonly,
https://www.googleapis.com/auth/calendar,
https://www.googleapis.com/auth/cloud-identity.groups,
https://www.googleapis.com/auth/chrome.management.reports.readonly,
https://www.googleapis.com/auth/chrome.management.policy.readonly,
https://www.googleapis.com/auth/chat.admin.spaces

Enforcement Center Actions (Write Scopes)

Enforcement AreaScopePurpose
User managementadmin.directory.userAdd, remove, suspend users, change OU, reset cookies
Group managementadmin.directory.groupAdd/remove users from groups
Role managementadmin.directory.rolemanagementCreate/delete role assignments
Send Chat messageschat.messages.createSend Google Chat messages
Browser managementadmin.directory.device.chromebrowsersMove Chrome browsers to OU
Device managementcloud-identity.devicesDelete Cloud Identity devices