For the complete documentation index, see llms.txt. This page is also available as Markdown.

Onboard Your Google Workspace

Connect your Google Workspace account to Prisma Cloud to monitor your users, groups, and group memberships.

If you use Workspace as an IdP for user and group management and want visibility and security of those accounts, onboard the Workspace accounts to Prisma Cloud. After onboarding, you can configure alert rules for Workspace related custom policies.

You need to complete steps on your Workspace console and the Prisma Cloud console.

Before you begin, make sure to enable the admin.googleapis.com service in your Google Cloud project.

  1. Configure your Workspace Account

    1. Click Admin console on the top right of the page.

    2. Log in using your Google ID.

    3. Select Account > Admin roles from the left navigation.

      configure gcp workspace 1
    4. Create a prisma-gcp-workspace-readonly custom role with the following Admin API privileges:

      • Organizational Units - Read

      • Users - Read

      • Groups - Read

        configure gcp workspace 2
    5. Select the role and click Assign admin.

    6. Create a service account in the onboarded GCP project, generate a Service Account Key (JSON), and copy the client email.

    7. Under Admin, click Assign service accounts.

    8. Enter the service account client email that you created and copied in Step 7 above: <example>@<project-name>.iam.gserviceaccount.com

    9. Click Add.

      configure gcp workspace 3
    10. Click Assign Role.

      Your Service Account is now associated with the prisma-gcp-workspace-readonly Admin role and the configuration on the GCP Admin console is complete. Next, you need to connect your Google Workspace to Prisma Cloud.

  2. Connect your Workspace Account to Prisma Cloud

    1. Select Settings > Providers > Cloud Accounts.

    2. From the Connect Provider drop-down, select Cloud Account.

    3. Select Google Cloud Platform as the cloud provider you want to onboard and Get Started.

    4. Under Scope, select Workspace.

      gcp add workspace 1
    5. Under Security Capabilities and Permissions, the Foundational capabilities are enabled, by default:

      • Misconfigurations (CSPM) grants the permissions required to scan cloud resources and ingest metadata.

      • Identity Security grants the permissions required to calculate net effective permissions for identities and manage access.

    6. Click Next.

    7. To Configure Account, enter Domain Name and Account Name.

      Make sure that the Domain Name matches the Primary Domain Name in the GCP Workspace Admin console.

      gcp workspace domain 1

      An account name is auto-populated for you. You can replace it with an account name that uniquely identifies your Google Workspace on Prisma Cloud.

      gcp add workspace 2
    8. Upload the Service Account Key (JSON) file that you generated and saved while configuring your Workspace account in Step 1.7 above.

    9. Select the Account Group to associate with your Workspace.

    10. Click Next.

    11. Review Status.

      gcp add workspace 3

      Verify the Account Details of the GCP Workspace and the status checks for the Security Capabilities and Permissions. Ensure that all the selected security capabilities display a green Enabled icon.

    12. Click Save and Close to complete onboarding.

      After you sucessfully onboard your GCP Workspace on Prisma Cloud, you can view the account on the Providers > Cloud Accounts page.

      gcp add workspace 4

      If you encounter an issue with an onboarded account that displays a yellow or red cloud account Status, you have the option of reloading or refreshing the status of any onboarded cloud account and it’s associated security capabilities. Navigate to Home > Settings > Providers > Cloud Accounts and click on the Status of the cloud account you wish to refresh. Select the refresh button on the Status window to reload your cloud account.

Last updated

Was this helpful?