> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/content-collections/connect/connect-cloud-accounts/onboard-gcp/onboard-gcp-project.md).

# Onboard Your GCP Project

Add a single GCP project or multiple GCP projects to Prisma Cloud.

Begin here to add a GCP project to Prisma Cloud. If you want to add multiple projects, you must either repeat this process for each project you want to onboard or you allow Prisma Cloud to automatically monitor all GCP projects—current and future—that use the Service Account attached to the project you are adding to Prisma Cloud. Prisma Cloud refers to this service account as a *Master Service Account*.

After you start monitoring your project using Prisma Cloud, if you delete the project on GCP, Prisma Cloud automatically deletes the account from the list of monitored accounts on **Settings > Cloud Accounts**. To track the automatic deletion of the project, an audit log is generated with information on the name of the deleted account and the date that the action was performed.

1. Select Settings > Providers > Cloud Accounts.
2. Next select Connect Provider > Cloud Account.
3. Select **Google Cloud Platform** as the cloud account you want to onboard and **Get Started**.

   <figure><img src="/files/LQ5iEBqQirWFq4CAQFU8" alt="gcp add proj 1"><figcaption></figcaption></figure>

   1. Select **Project** under **Scope**.
   2. Select the **Security Capabilities and Permissions** that you want to enable for the GCP project.

      The capabilities are grouped in to **Foundational** and **Advanced**. Based on your selection, Prisma Cloud dynamically generates a Terraform script that includes the associated permissions for the service account.

      * Use the **Foundational** (recommended) capabilities during the start of your organization’s cloud adoption journey to effectively manage assets in the cloud and on-premises.

        The **Foundational** capabilities are enabled, by default:

        * **Misconfigurations** grants the permissions required to scan cloud resources and ingest metadata.
        * **Identity Security** grants the permissions required to calculate net effective permissions for identities and manage access.
        * Enable and add permissions for [Agentless Workload Scanning](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/agentless-scanning) (selected by default) to scan hosts and containers for vulnerabilities and compliance risks without having to install a defender. If you do not want the Agentless Workload Scanning capability, you can deselect the checkbox. Scans start automatically once you onboard your organization. You can also update the scanning [configuration](https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-12/prisma-cloud-compute-edition-admin/agentless-scanning/onboard-accounts) for agentless scans.
      * Use the **Advanced** (additional) capabilities to proactively control your cloud operations and identify and remediate issues before they manifest within your runtime environments.

        The **Advanced** capabilities that you can choose to enable are:

        * **Threat Detection** (enabled by default) grants the permissions required to detect Network and Identity threats.
        * Enable and add permissions for **Serverless Function Scanning** to scan cloud provider functions such as, AWS Lambda, Azure, and Google functions for [vulnerabilities](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/vulnerability_management/serverless_functions) and [compliance](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/compliance/serverless). Scans start automatically once you onboard your organization. You can also update the scanning [configuration](https://docs.paloaltonetworks.com/prisma/prisma-cloud/22-12/prisma-cloud-compute-edition-admin/agentless-scanning/onboard-accounts) for serverless scans.
        * Add permissions for **Agent-Based Workload Protection** to allow for [automated deployment of defenders](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/deploy-defender/defender_types) to provide protection to secure cloud [VMs](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/deploy-defender/host/auto-defend-host), [containers](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/deploy-defender/container/container), and [Kubernetes orchestrators](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin-compute/install/deploy-defender/orchestrator/orchestrator). Registry scanning, Kubernetes audits, and other features required by defenders are also enabled.
   3. Click **Next**.
4. **Configure Account**.

   <figure><img src="/files/5Ow3mMinYLM6eK3YiLVZ" alt="gcp add proj 2"><figcaption></figcaption></figure>

   1. Enter **Project ID** and **Account Name**. An account name is auto-populated for you. You can replace it with an account name that uniquely identifies your GCP project on Prisma Cloud.

      Make sure to enter your Project ID and not your Project Number.

      <figure><img src="/files/KEQ1D9YeRgk0vM66kXsV" alt="gcp projects id"><figcaption></figcaption></figure>
   2. (tt:\[Optional]) Select **Remediation** to address policy violations reported for remediable configuration policies on Prisma Cloud. This feature is not enabled by default. After you enable it, the Prisma Cloud role gets read-write access permissions to your Google cloud account to successfully execute remediation commands.
   3. (tt:\[Optional]) Enable **Flow Logs** and enter the name of your **Flow Logs Storage Bucket**. Optionally, select the **Use Dataflow to generate compressed logs** checkbox.

      The Terraform template does not enable flow logs, and you must complete the workflow in [Enable Flow Logs for GCP Project](/content-collections/connect/connect-cloud-accounts/onboard-gcp/enable-flow-logs-for-gcp-project.md) for Prisma Cloud to retrieve flow logs. Additionally, if you want to enable [flow logs compression](/content-collections/connect/connect-cloud-accounts/onboard-gcp/flow-logs-compression.md) on Prisma cloud and address the lack of native compression support for flow logs sink setup on GCP, you must do it manually too. When you select **Use Dataflow to generate compressed logs**, Prisma Cloud sets up the network and compute resources required for flow log compression. This process can take up to five minutes to complete.

      When you enable flow logs, the service ingests flow log data for the last seven days. Later if flow logs become unavailable for any reason such as, if you manually disable flow logs, modify API permissions, or an internal error occurs, when access is restored, only the logs from the preceding seven days are ingested.
   4. (tt:\[Optional]) Allow Prisma Cloud to monitor all current and future GCP projects associated with the service account. This only applies to the Master Service Account.

      If you have multiple GCP projects, enable **Automatically onboard projects that are accessible by this service account** to allow Prisma Cloud to monitor all current and future GCP projects associated with the Service Account. For every project that you want to onboard, you must provide the same set of permissions to the service account.

      A project you onboard or a project that you had onboarded is in the varname:\[\<sys-26-digit number>] format, it will be deleted.
   5. Configure the **Service Account** for Prisma Cloud.
   6. **Download Terraform Script** and follow the **Steps** to upload your **Service Account Key (JSON) file**.

      Prisma Cloud recommends that you create a directory to store the Terraform template you download. This allows you to manage the templates when you add a different Google project to Prisma Cloud. Give the directory a name that uniquely identifies the project for which you’re using it (for example, onboard-\<project-name>).
   7. Select the [Account Groups](/content-collections/administration/create-manage-account-groups.md) to associate with your project.

      Make sure to assign each cloud account to an account group and [create an Alert Rule for run-time checks](/content-collections/alerts/create-an-alert-rule-cloud-infrastructure.md) to associate the account group with it to generate alerts when a policy violation occurs.
   8. Click **Next**.
5. **Review Status**.

   <figure><img src="/files/W4Adz0roIQaTWtxHKpi5" alt="gcp add proj 3"><figcaption></figcaption></figure>

   Verify the **Details** of the GCP project and the status checks for the **Security Capabilities** you selected while onboarding the project on Prisma Cloud.

   * Ensure that all the security capabilities you selected display a green **Enabled** icon.
   * For the security capabilities that display a red **Checks Failed** icon, click the corresponding drop-down to view the cause of failure.

     It takes between 4-24 hours for the flow log data to be exported and analyzed before you can review it on Prisma Cloud. To verify if the flow log data from your GCP project has been analyzed, you can run a network query on the **Investigate** page.

     If Prisma Cloud GCP IAM role does not have adequate permissions to ingest data on the monitored resources within your project, the status icon displays as red or amber and it lists the permissions that are missing.
6. Click **Save and Close** to complete onboarding or **Save and Onboard Another Account**.

   If an onboarded account displays a yellow or red status, you can either reload or refresh the cloud account and it’s associated security capabilities. Select **Home > Settings > Providers > Cloud Accounts** and click on the **Status** of the cloud account you want to refresh. Next, select the refresh button on the **Status** window to reload your cloud account.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/content-collections/connect/connect-cloud-accounts/onboard-gcp/onboard-gcp-project.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
