Google Workspace
Connect Google Workspace to Radiant Security to ingest email, authentication, and IAM activity for AI triage.
Radiant connects to Google Workspace to ingest email activity, authentication activity, and user and group IAM information. The connector uses a Google Cloud service account with domain-wide delegation, and reads Workspace activity logs from BigQuery. Configuration is a one-time setup performed in Google Cloud, Google Admin, and Radiant Security.
If you do not have Google BigQuery, use Google Workspace IAM only to enable just the IAM and email data feeds.
At the end of this configuration, you provide Radiant Security with the following values:
BigQuery Project ID
BigQuery Dataset Name
Delegate User Email
Service account JSON key file
Prerequisites
The Google Workspace account must have one of the following plans for email activity log collection:
To verify your current license plan, sign in to an account with admin access and visit https://admin.google.com/ac/billing/subscriptions.
The user performing this configuration must hold the following permissions and roles:
Create a project in Google Cloud
Sign in to the Google Cloud console.
From the Select organization drop-down at the top of the page, click New project.
In the Project name field, enter a descriptive name. Radiant recommends
{your organization's name}-workspace-logs. For details on project naming and identifiers, see Google's Creating and managing projects.The Google Cloud console generates a Project ID from the project name. To customize it, click Edit next to the Project ID. The Project ID is permanent after the project is created.
Copy the Project ID for later use.
Click Create.
Select the newly created project from the drop-down at the top of the page.
From the navigation menu, select APIs & Services > Library.

In the API Library, search for and enable the following APIs, one at a time:
Admin SDK API
Cloud Identity
Gmail API
Google Calendar API
Google Workspace Alert Center API

Open the OAuth consent screen for your project. From the navigation menu, select APIs & Services > OAuth consent screen. With the project selected, Google routes you to the Google Auth Platform.
Configure the consent screen. The path depends on whether the Google Auth Platform is already configured for this project: If you see the message "Google Auth platform not configured yet": click Get Started and complete the wizard:
Under App Information, enter the following:
App name:
radiant-security-workspace-logsUser support email: select the appropriate user.
Click Next.
Under Audience, select Internal as the user type.
Click Next.
Under Contact Information, enter an email address where Google can notify you about changes to your project.
Click Next.
Under Finish, review the Google API Services User Data Policy, select I agree to the Google API Services: User Data Policy, and click Continue.
Click Create.
If the Google Auth Platform is already configured: verify the existing configuration in the left navigation:
Branding: confirm App name is
radiant-security-workspace-logsand that User support email and Developer contact information are populated.Audience: confirm User type is Internal. If it shows External, contact your Google Workspace administrator before continuing.
Create a service account
A dedicated service account in Google Cloud ingests the data. The service account holds the permissions required to read the data fed into Radiant Security.
In the Google Cloud console, navigate to IAM & Admin > Service Accounts.

Click + Create service account and enter the Service account name:
radiant-security-connector.Optional: Enter a description of the service account.
Click Create and Continue.
Under Grant this service account access to project, assign the following roles. Click + Add another role to add the second role:
BigQuery Data Viewer
BigQuery Read Session User
Click Done.
Click the
radiant-security-connectorservice account to open it.On the Service Accounts page, click the email address of the
radiant-security-connectorservice account.Click the Keys tab.
Click Add key and select Create new key.
Select JSON as the Key type and click Create. The JSON key file downloads automatically.
The downloaded JSON key file is the only copy. Store it securely. You upload this file to Radiant Security at the end of this guide. For guidance, see Google's Best practices for managing service account keys.
Grant access to the service account
To call APIs in Google Workspace, the service account must be granted domain-wide delegation of authority in the Google Workspace Admin console by a super administrator. For background, see Google's Delegating domain-wide authority to a service account.
On the Service Accounts page in Google Cloud, click the
radiant-security-connectorservice account.On the Details tab, expand Advanced settings and copy the Client ID.
Click View Google Workspace Admin Console.
Navigate to Security > Access and data control > API controls.
Click Manage Domain Wide Controls.
Click Add new and paste the Client ID you copied in step 2.
In the OAuth Scopes field, copy and paste the following permissions:
The specific permissions for each Google OAuth scope are listed in the following table:
OAuth ScopeFunctionalityadmin.directory.domain.readonly
Get users on the domain
admin.directory.group.readonly
Get user group memberships
admin.directory.rolemanagement.readonly
Get user roles
admin.directory.user.readonly
Get user profile information
admin.reports.usage.readonly
Get usage status (Account status, MFA enablement, etc)
admin.reports.audit.readonly
Get user audit activity (Google services accessed, login times, etc)
gmail.settings.basic
Mailbox settings - Get and Set email forwarding rules - Block sender action
apps.alerts
Get phishing alert reports from google
bigquery
Read BigQuery tables (Workspace activity)
gmail.readonly
Get Email raw body (Mail reports Based on Google alerts)
gmail.modify
Soft Delete email action
mail.google.com
Hard Delete email action
calendar.readonly and calendar.events.readonly
Get user calendar events - Out Of Office events
Click Authorize.
Two of the scopes grant write access and support automated response actions in Radiant Security:
https://www.googleapis.com/auth/gmail.modify— soft-delete an email from a user's mailbox.https://mail.google.com— hard-delete an email from a user's mailbox.
To configure the Google Workspace action connector that uses these scopes, see Execute response actions with Google Workspace.
Enable BigQuery export
Sign in to the Google Workspace Admin console.
Navigate to Reporting > Data Integrations > BigQuery Export.
Click on the export box and fill the required fields:
Project ID: the Project ID you copied when creating the Google Cloud project.
In the New dataset within project field, enter a name for the dataset:
google_workspace_log
Click Save.
Create a Google Workspace read-only admin role and delegated user
The Google Workspace APIs require a delegate Google Workspace account that holds all privileges needed by the APIs. This is an account inside the Google Workspace environment and is distinct from the Google Cloud service account created earlier. For background, see Google's Delegating domain-wide authority to the service account.
Radiant recommends creating a dedicated, named user account in Google Workspace for this purpose (for example, radiant-delegate@yourdomain.com) rather than reusing a personal admin account.
Sign in to the Google Workspace Admin console.
Navigate to Account > Admin Roles.
Click on Create new role.
Name the role
Radiant Security Read Onlyand click Continue.Select the following privileges:
Organizational Units>ReadUsers>ReadAlert Center>View AccessReportsGroups>ReadDLP>View DLP ruleSecurity Center>Activity Rules>View
On the review screen, click Create Role.
Assign the role to a delegate user
In the Google Workspace Admin console, create a dedicated user account if one does not already exist. For guidance, see Google's Add an account for a new user.
On the Admin Roles page, open the
Radiant Security Read Onlyrole.Click Assign members and assign the role to the delegate user account created in step 1.
Record the delegate user's email address. You enter this value as the Delegate User Email in the final section of this guide.
Add the data connector in Radiant Security
Log in to Radiant Security.
From the navigation menu, select Settings > Data Connectors and click + Add Connector.
Search for and select the Google Workspace option and then click Data Feeds.
Add the following values from the previous steps:
BigQuery Project ID: the Project ID of the Google Cloud project you created.
BigQuery Dataset Name:
google_workspace_logDelegate User Email: the email address of the dedicated Workspace user account assigned the Radiant Security Read Only role.
JSON File: upload the service account JSON key file
Click Add Connector to save the connector configuration.
Verify ingestion
After Google Workspace begins forwarding, confirm alerts and events are reaching Radiant.
In Radiant, navigate to Log Management.
Filter by the
rs_connectorTypefor each data feed you enabled:Data feedFilterAuthentication Logs
rs_connectorType:"google_logs_authentication"Email Logs
rs_connectorType:"google_logs_email"User Activity Logs
rs_connectorType:"google_logs_user_accounts"Google IAM
rs_connectorType:"google_iam"Google Email Alerts
rs_connectorType:"google_alerts"Google Identity Alerts
rs_connectorType:"google_identity_alerts"Google Workspace Alerts
rs_connectorType:"google_workspace_alerts"Confirm recent alerts and events appear for each enabled feed.
Allow several minutes for alerts and events to be parsed, indexed, and available for search.
Last updated
Was this helpful?