Google Workspace

Samurai [Local] CollectorSamurai [Cloud] Collector
Picture1.svg

To complete this Integration you will need to perform steps in both Google Workspace and the Samurai MDR portal.

Follow the steps below:

1. From Google Workspace

2. From the Samurai MDR portal

Enable the Admin SDK API

Follow the Google API Console Help documentation:

Ensure you login to the Google Console as a super administrator and use the following parameters when completing the steps:

Documentation StepField NameParameter
2Project NameAnything you want but we recommend “SamuraiAPI”
2OrganizationThe name of your organization
2LocationAnything you want
4API LibrarySelect and enable against the project created in Step 2:

“Admin SDK API”

“Google Workspace Alert Center API”

Create a service account

Follow the steps outlined within the Google documentation:

Use the following parameters when completing the steps:

Documentation StepField NameParameter
3Service Account NameAnything you want but we recommend “SamuraiAPI”
3Service Account IDAnything you want but we recommend “SamuraiAPI”
3Service Account DescriptionAnything you want but we recommend “SamuraiAPI”

Create credentials for the service account

Follow the steps outlined within the Google documentation:

Documentation StepField NameParameter
2ProjectSelect the project created in Enable the Admin SDK API
2Service AccountSelect the service account you created in Create a service account
4Key TypeEnsure “JSON” is selected.

Delegate domain-wide authority to the service account

Follow the steps outlined within the Google documentation:

Use the following parameters when completing the steps:

Documentation StepField NameParameter
2Service AccounrtEnsure you select the service account created in Create a service account
5eOAuth scopeshttps://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/admin.reports.usage.readonly
https://www.googleapis.com/auth/apps.alerts

Complete the Google Workspace integration

You will need:

  1. Login to the Samurai MDR portal
  2. Click Telemetry and select Integrations from the main menu
  3. Select Create
  4. Locate and click Google Workspace 
  5. Click Next (we leverage a Samurai Cloud Collector)
  6. Enter a Name of Integration
  7. Enter a Description (Optional)
  8. Enter your Service Account JSON (copy and paste from the json file you downloaded)
  9. Enter your Domain-Wide delegation account (the admin account email used for domain-wide delegation)
  10. Click Finish

Our Integration guide was accurate at the time of writing but vendors change things frequently! If you find errors or anything is outdated, let us know by raising a request in the Samurai MDR application and we shall get it updated.