How to Configure a Google Data Source
The Hydden Google collectors integrate with the Google Cloud Platform and the Workspace modules.
GCP Module | Google Workspace Module |
---|---|
Data collected: | |
Service Accounts | User Accounts |
Roles | Roles |
Groups | Groups |
APIs to enable: | |
Cloud Resource Manager API | Admin SDK API |
Identity and Access Management (IAM) API |
Setting Up Google Service Account Credential
- Navigate to https://console.cloud.google.com/iam-admin
- Setup a new service account in your project for Hydden.
- Add a key and save the json file that is generated.
Grant Directory Admin Role in Google Admin Console
- Navigate to admin.google.com and sign in with a super administrator account
- Navigate to Roles and Privileges, click Account | Admin Roles.
- Create or Edit a Role.
- If a custom role for the service account does NOT exist:
- Click Create New Role.
- Name the role (e.g., Directory Admin API).
- If a role already exists, select it.
- If a custom role for the service account does NOT exist:
- Assign Privileges under role settings, check the boxes for:
- User Management
- Group Management
- Organization Units
- Any additional privileges required for your use case.
- Assign the Role, under Admins | Role Settings.
- Click Assign Admins and enter the service account email.
Verify Domain-wide Delegation
If the service account is assigned via Admin Console, ensure domain-wide delegation is properly set up.
- Navigate to Security | API Controls | Manage Domain-wide Delegation.
- Add the Client ID of the service account and the necessary scopes.
Grant Roles in Google Cloud Console
If needed, grant the Directory Admin role in the Google Cloud Console.
- Navigate to the IAM & Admin Page.
- Select your service account’s project.
- At the top of the IAM table, click Add.
- Enter the service account email.
- Assign the role Directory Admin.
Roles Required
https://www.googleapis.com/auth/admin.directory.customer, https://www.googleapis.com/auth/admin.directory.domain, https://www.googleapis.com/auth/admin.directory.group, https://www.googleapis.com/auth/admin.directory.group.member, https://www.googleapis.com/auth/admin.directory.orgunit, https://www.googleapis.com/auth/admin.directory.rolemanagement, https://www.googleapis.com/auth/admin.directory.user, https://www.googleapis.com/auth/admin.directory.user.alias, https://www.googleapis.com/auth/admin.directory.user.security, https://www.googleapis.com/auth/cloud-platform
Configuring the Data Source
Navigate to Configuration | Discover and select the Data Sources tab.
Click + Add Data Source.
On the Add Data Source modal, from the Data Source drop-down select the Google collector you wish to configure. The options are:
- Google Cloud
- Google Workspace
Depending on your data collection needs, one or the other or both might be required for your organization. Repeat the steps in this procedure for both collectors if needed.
Enter a Name for your data source.
Depending on the collector selected you have to provide either detail:
- a Provider ID for the Google Cloud collector.
- a Domain for the Google Workspace collector.
You may ignore Preset and Schedule for now. The first time you will use a manual run action to use the collector.
To the right of Credentials, click +.
- The Add credential modal opens and the drop-down selection should shows JSON Credential credential, if not, change it to JSON Credential.
- Enter a name for your Google credential.
- Copy and paste your JSON Object as previously saved/vaulted.
- Click Add.
A Site entry is not needed for the Google Data Sources.
Under the Select Account Mapping Rule Set drop-down, select from the following options:
- Default Rules Only
- Add All Rules
- Add All Default Rules
- Add All Custom Rules
- Manual Selection: Rules need to be selected from a drop-down menu.
Any rules added, can be removed by clicking on the x on the rule name label.
NOTE: Rules need to be set to enabled on the rule add/edit modal to work in your tenant, refer to Account Mapping.
To enable account mapping or identity creation, select the Enable Automatic Account Mapping and Enable Automatic Identity Creation checkboxes respectively. Both options can be enabled at the same time.
In the Automatic Mapping Rules (Match Account to Identity using) field, rules are either automatically populated based on your selection under the Automatic Account Mapping Rules step or you have to manually add rules from the drop-down menu. Any rules added, can be removed by clicking on the x on the rule name label.
From the Automatic Identity Creation Rules (Create New Identity when) drop-down, select which rules you want to use in your environment. Custom rules are listed first. Any rules added, can be removed by clicking on the x on the rule name label.
Click Add to save the data source. You have an option to manually run the data collection via the Run Now button.
At this point, you can run a collection from the Data Sources page and shortly after, you will see your Google data listed on the Identity Posture dashboard, in Global Search and the Search Library.