Follow these steps to create a G Suite Connector:
1) Enable Access to APIs in API library
2) Create Service Account and Download Configuration File
3) Grant Scope access to Service Account
4) Create Connector in SaaSDR with GSuite as application
1) Navigate to the Google Cloud Platform (GCP) console. (https://console.cloud.google.com/)
2) Select the organization.
3) Select a project or create a new project. Ensure that you select the correct project.
4) In the left sidebar, navigate to APIs & Services > Library.
5) In API library, click the following APIs and enable them. To find the API, use the search field.
a. Google Drive API
b. Admin SDK API
1) From the left navigation pane of the GCP console, navigate to IAM & Admin > Service Accounts and click Create Service Account.
2) Provide a name and description (optional) for the service account and click Create.
3) Choose the Viewer role and the Security Reviewer role to assign at least reader permissions to the service account. Click Continue and click Done.
4) From the Actions column, click Create Key and select JSON as Key type and click Create.
A message saying “Private key saved to your computer” is displayed and the JSON file is downloaded to your computer.
5) Click Close > Done.
Note: Save the configuration (JSON) file to a secure folder and open it in a text editor. This would be needed in subsequent steps.
6) Edit the service account again, select Enable GSuite Domain-wide Delegation (provide an App Name - ex: QualysSaaSDR), click Save.
1) Log in to your G Suite Admin console (https://admin.google.com/)with the administrator credentials
2) Click Security and expand API controls.
3) Click Manage Domain Wide Delegation.
4) Click Add new.
5) Add the Client ID (client_id value) from the downloaded JSON file and following scopes:
6) Finally, click Authorize. The added scopes should appear on the UI.
You are now ready to start scanning your G Suite.
1) Now, on the SaaSDR UI, go to Configuration > Connectors and click Create Connector.
2) Select GSuite from the SaaS Application type drop-down option.
3) Provide the information in the required fields. Service Account ID, Private Key ID, and Private Key - these are fetched from the JSON downloaded in the previous steps.
4) Click Create Connector.
You will be redirected to the login page of the application where you need to login using your administrator credentials. Once your connector is created, it is listed in the Configurations > Connectors list. Here you can check the status and other details of the connector.
Once the application is connected, a scan is initiated to pull metadata from the application. This step may take some time to complete based on the number of resources to be cataloged in your application.