Skip to main content

G Suite (Google Workspace)

Integrate Google Workspace with Cloudaware to discover users, groups, org units, domains, and related directory assets for unified identity governance and reporting.

info
  • Audience: Cloudaware administrators, IT
  • Outcome: The Google Workspace account is connected, and directory objects are available in the CMDB for identity governance, access reviews, and organizational reporting

Capabilities

The integration supports:

  • Read-only discovery of Google Workspace users, groups, roles, organizational units, domains, and privileges in the CMDB
  • Relationships between users, groups, roles, domains, and related organizational structures
  • Identity governance and directory reporting in Cloudaware

Prerequisites

Before you begin, make sure you have:

  • Access to a Cloudaware account.
  • A user with access to the Admin Console and permissions to manage cloud accounts, organizations, and integrations (Cloudaware Administrator).
  • Google service account with domain-wide delegation enabled.
  • Authorized OAuth scopes for the Admin SDK Directory API:
    • https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly
    • https://www.googleapis.com/auth/admin.directory.device.mobile.readonly
    • https://www.googleapis.com/auth/admin.directory.group.member.readonly
    • https://www.googleapis.com/auth/admin.directory.group.readonly
    • https://www.googleapis.com/auth/admin.directory.orgunit.readonly
    • https://www.googleapis.com/auth/admin.directory.user.readonly
    • https://www.googleapis.com/auth/admin.directory.user.alias.readonly
    • https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly
    • https://www.googleapis.com/auth/admin.directory.userschema.readonly
    • https://www.googleapis.com/auth/admin.directory.customer.readonly
    • https://www.googleapis.com/auth/admin.directory.domain.readonly
    • https://www.googleapis.com/auth/admin.directory.resource.calendar.readonly
  • Admin email in the target Google Workspace domain.

Add a Google Workspace Account to Cloudaware

To connect your Google Workspace account to Cloudaware:

  1. In Cloudaware, go to Admin.
  2. Find G Suite, then click + ADD.
  3. Enter the following values:
    • Google Service Account: Select from the list
    • Admin Email: The administrator email in the target Google Workspace domain.
  4. Click SAVE.
  5. Confirm that the integration status indicator is green.

View Google Workspace Data in CMDB

To browse discovered Google Workspace resources:

  1. In Cloudaware, open CMDB Navigator.
  2. In the left pane, select G SUITE ADMIN.
  3. Open an object list, e.g., Google G-Suite Users or Google G-Suite Groups, to view records.

Supported Objects

Cloudaware ingests the following Google Workspace objects:

Google Workspace ObjectCMDB Object API Name
Google G-Suite CustomerCA10GS__CaGoogleGSuiteCustomer__c
Google G-Suite DomainCA10GS__CaGoogleGSuiteDomain__c
Google G-Suite Domain AliasCA10GS__CaGoogleGSuiteDomainAlias__c
Google G-Suite GroupCA10GS__CaGoogleGSuiteGroup__c
Google G-Suite MemberCA10GS__CaGoogleGSuiteMember__c
Google G-Suite Organizational UnitCA10GS__CaGoogleGSuiteOrganizationalUnit__c
Google G-Suite PrivilegeCA10GS__CaGoogleGSuitePrivilege__c
Google G-Suite RoleCA10GS__CaGoogleGSuiteRole__c
Google G-Suite Role AssignmentCA10GS__CaGoogleGSuiteRoleAssignment__c
Google G-Suite Role Privilege LinkCA10GS__CaGoogleGSuiteRolePrivilegeLink__c
Google G-Suite UserCA10GS__CaGoogleGSuiteUser__c
Google G-Suite User AddressCA10GS__CaGoogleGSuiteUserAddress__c
Google G-Suite User Instant MessengerCA10GS__CaGoogleGSuiteUserInstantMessenger__c
Google G-Suite User LocationCA10GS__CaGoogleGSuiteUserLocation__c
Google G-Suite User OrganizationCA10GS__CaGoogleGSuiteUserOrganization__c
Google G-Suite User Posix AccountCA10GS__CaGoogleGSuiteUserPosixAccount__c

Troubleshooting

note

Initial data collection may take time to complete.

Authentication Fails or Integration Shows Red Status

  • Confirm that domain-wide delegation is enabled for the service account.
  • Verify that the required Admin SDK read scopes are authorized in Google Workspace.
  • Confirm that the admin email belongs to the target Google Workspace domain.
  • Re-enter the service account details by editing the integration in Cloudaware.

Directory Objects Are Missing

  • Confirm that the service account can read the expected users, groups, domains, roles, and organizational units.
  • Review the authorized OAuth scopes and add any missing read scopes.
  • In CMDB Navigator, verify that you are viewing the G SUITE ADMIN section and related resources.

Still stuck? Contact Cloudaware Support at support@cloudaware.com with the integration name and a brief description of the issue.

Reconfigure or Remove the Integration

warning

To rotate credentials, edit the existing integration instead of deleting and re-creating it.

Update the Integration Details

  1. Go to Admin.
  2. Select G Suite.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Edit.
  5. Update the required fields.
  6. Click Save.

Remove the Integration from Cloudaware

  1. Go to Admin.
  2. Select G Suite.
  3. Select the specific integration.
  4. Open the three-dot menu (), then click Delete.
  5. Confirm the deletion if prompted.

Security Notes

  • Use a dedicated Google service account for Cloudaware discovery.
  • Grant only the Admin SDK read scopes required for the directory data Cloudaware must discover.
  • Store service account keys securely and restrict access to administrators who manage integrations.
  • Rotate service account keys according to your organization's credential-rotation policy.
  • Remove unused or stale service account keys from Google Cloud and update Cloudaware when keys are rotated.