: Onboard a Google Workspace App to SSPM
Focus
Focus

Onboard a Google Workspace App to SSPM

Table of Contents

Onboard a Google Workspace App to SSPM

Connect a Google Workspace instance to SSPM to detect posture risks.
The following instructions describe a newer method of onboarding Google Workspace, which was introduced in October 2023. This onboarding method uses OAuth 2.0 authorization to connect to your Google Workspace instance. This method replaces an earlier approach, which connected SSPM to your Google Workspace instance by using administrator login credentials. If you already connected to your Google Workspace instance using the earlier approach, your established connection will continue to work. However, if there is any change to the configuration information that you provided to SSPM (such as an updated login password), you will need to onboard Google Workspace by using this new method.
Palo Alto Networks' use and transfer of information received from Google APIs to any other app will adhere to Google API Services User Data Policy, including the Limited Use requirements. For more information on how information may be captured, processed and stored by and within the service, refer to the SaaS Security Privacy document.
For SSPM to detect posture risks in a Google Workspace organizational unit, you must onboard your Google Workspace instance to SSPM. Through the onboarding process, SSPM connects to a Google Workspace API and, through the API, scans a Google Workspace organizational unit for misconfigured settings. If there are misconfigured settings, SSPM suggests a remediation action based on best practices. If users have extended Google Workspace by installing third-party apps, SSPM also detects the third-party apps and the level of access that the apps were granted. This information helps you determine the risks posed by third-party apps so you can take action as needed.
SSPM gets access to your Google Workspace instance through OAuth 2.0 authorization. During the onboarding process, you are prompted to log in to Google Workspace and to grant SSPM the access it requires.
To onboard your Google Workspace instance, you complete the following actions:

Identify an Administrator Account and an Organizational Unit

During the onboarding process, you will specify a particular Google Workspace organizational unit to scan. Then, SSPM will redirect you to log in to Google Workspace. After you log in, Google Workspace will prompt you to grant SSPM the access it needs to your Google Workspace instance.
  1. Identify the administrator account that SSPM will use to access your Google Workspace instance. To grant SSPM the permissions that it needs to monitor your Google Workspace instance, the account must have administrator privileges.
  2. Identify the Google Workspace organizational unit to scan.
    An organizational unit is a grouping of users with common settings. During onboarding, you are prompted for the name of the organizational unit for SSPM to scan. If you want to scan multiple organizational units, you can onboard each one separately. To view the organizational units in your Google Workspace instance, from the Google Admin console, select
    Directory
    Organizational Units
    .
  3. Sign out of all Google Workspace accounts.
    Signing out of all Google Workspace accounts helps ensure that you sign in under the correct account during the onboarding process. Some browsers can automatically sign you in by using saved credentials. To ensure that the browser does not automatically sign you in to the wrong account, you can turn off any automatic sign-in option or clear your saved credentials. Alternatively, you can prevent the browser from using saved credentials by opening the Cloud Management Console in an incognito window.

Connect SSPM to Your Google Workspace Instance

By adding a Google Workspace app in SSPM, you enable SSPM to connect to your Google Workspace instance.
  1. From the Add Application page (
    Posture Security
    Applications
    Add Application
    ), click the Google Workspace tile.
  2. Under posture security instances,
    Add Instance
    or, if there is already an instance configured,
    Add New
    instance.
  3. Choose the option to
    Log in with Credentials
    .
  4. Enter the organizational unit name and
    Connect
    .
    SSPM redirects you to the Google Workspace login page.
  5. Enter the credentials for the administrator account that you identified earlier, and log in to Google Workspace.
    Google Workspace displays a consent form that details the access permissions that SSPM requires.
  6. Review the consent form and allow access.

Recommended For You