G Suite (Google Workspace)
Integrate Google Workspace with Cloudaware to discover users, groups, org units, domains, and related directory assets for unified identity governance and reporting.
info
- Audience: Cloudaware administrators, IT
- Outcome: The Google Workspace account is connected, and directory objects are available in the CMDB for identity governance, access reviews, and organizational reporting
Capabilities
The integration supports:
- Read-only discovery of Google Workspace users, groups, roles, organizational units, domains, and privileges in the CMDB
- Relationships between users, groups, roles, domains, and related organizational structures
- Identity governance and directory reporting in Cloudaware
Prerequisites
Before you begin, make sure you have:
- Access to a Cloudaware account.
- A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
- Google service account with domain-wide delegation enabled.
- Authorized OAuth scopes for the Admin SDK Directory API:
https://www.googleapis.com/auth/admin.directory.device.chromeos.readonlyhttps://www.googleapis.com/auth/admin.directory.device.mobile.readonlyhttps://www.googleapis.com/auth/admin.directory.group.member.readonlyhttps://www.googleapis.com/auth/admin.directory.group.readonlyhttps://www.googleapis.com/auth/admin.directory.orgunit.readonlyhttps://www.googleapis.com/auth/admin.directory.user.readonlyhttps://www.googleapis.com/auth/admin.directory.user.alias.readonlyhttps://www.googleapis.com/auth/admin.directory.rolemanagement.readonlyhttps://www.googleapis.com/auth/admin.directory.userschema.readonlyhttps://www.googleapis.com/auth/admin.directory.customer.readonlyhttps://www.googleapis.com/auth/admin.directory.domain.readonlyhttps://www.googleapis.com/auth/admin.directory.resource.calendar.readonly
- Admin email in the target Google Workspace domain.
Add a Google Workspace Account to Cloudaware
To connect your Google Workspace account to Cloudaware:
- In Cloudaware, go to Admin.
- Find G Suite, then click + ADD.
- Enter the following values:
- Google Service Account: Select from the list
- Admin Email: The administrator email in the target Google Workspace domain.
- Click SAVE.
- Confirm that the integration status indicator is green.
View Google Workspace Data in CMDB
To browse discovered Google Workspace resources:
- In Cloudaware, open CMDB Navigator.
- In the left pane, select G SUITE ADMIN.
- Open an object list, e.g., Google G-Suite Users or Google G-Suite Groups, to view records.
Supported Objects
Cloudaware ingests the following Google Workspace objects:
| Google Workspace Object | CMDB Object API Name |
|---|---|
| Google G-Suite Customer | CA10GS__CaGoogleGSuiteCustomer__c |
| Google G-Suite Domain | CA10GS__CaGoogleGSuiteDomain__c |
| Google G-Suite Domain Alias | CA10GS__CaGoogleGSuiteDomainAlias__c |
| Google G-Suite Group | CA10GS__CaGoogleGSuiteGroup__c |
| Google G-Suite Member | CA10GS__CaGoogleGSuiteMember__c |
| Google G-Suite Organizational Unit | CA10GS__CaGoogleGSuiteOrganizationalUnit__c |
| Google G-Suite Privilege | CA10GS__CaGoogleGSuitePrivilege__c |
| Google G-Suite Role | CA10GS__CaGoogleGSuiteRole__c |
| Google G-Suite Role Assignment | CA10GS__CaGoogleGSuiteRoleAssignment__c |
| Google G-Suite Role Privilege Link | CA10GS__CaGoogleGSuiteRolePrivilegeLink__c |
| Google G-Suite User | CA10GS__CaGoogleGSuiteUser__c |
| Google G-Suite User Address | CA10GS__CaGoogleGSuiteUserAddress__c |
| Google G-Suite User Instant Messenger | CA10GS__CaGoogleGSuiteUserInstantMessenger__c |
| Google G-Suite User Location | CA10GS__CaGoogleGSuiteUserLocation__c |
| Google G-Suite User Organization | CA10GS__CaGoogleGSuiteUserOrganization__c |
| Google G-Suite User Posix Account | CA10GS__CaGoogleGSuiteUserPosixAccount__c |
Troubleshooting
note
Initial data collection may take time to complete.
Authentication Fails or Integration Shows Red Status
- Confirm that domain-wide delegation is enabled for the service account.
- Verify that the required Admin SDK read scopes are authorized in Google Workspace.
- Confirm that the admin email belongs to the target Google Workspace domain.
- Re-enter the service account details by editing the integration in Cloudaware.
Directory Objects Are Missing
- Confirm that the service account can read the expected users, groups, domains, roles, and organizational units.
- Review the authorized OAuth scopes and add any missing read scopes.
- In CMDB Navigator, verify that you are viewing the G SUITE ADMIN section and related resources.
Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.
Reconfigure or Remove the Integration
warning
To rotate credentials, edit the existing integration instead of deleting and re-creating it.
Update the Integration Details
- Go to Admin.
- Select G Suite.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Edit.
- Update the required fields.
- Click Save.
Remove the Integration from Cloudaware
- Go to Admin.
- Select G Suite.
- Select the specific integration.
- Open the three-dot menu (⋮), then click Delete.
- Confirm the deletion if prompted.
Security Notes
- Use a dedicated Google service account for Cloudaware discovery.
- Grant only the Admin SDK read scopes required for the directory data Cloudaware must discover.
- Store service account keys securely and restrict access to administrators who manage integrations.
- Rotate service account keys according to your organization's credential-rotation policy.
- Remove unused or stale service account keys from Google Cloud and update Cloudaware when keys are rotated.