Google Cloud Platform | Insights

Prerequisites

Before you configure the Google Cloud Platform connector, ensure the following requirements are met.

Google Cloud access

  • You have organization-level administrator access to the Google Cloud Console.
  • You can create projects, service accounts, and enable APIs within your GCP organization.
  • You can assign IAM roles at the organization scope.
  • (Optional) If using Google Workspace: You have Super Admin access to the Google Admin Console to configure domain-wide delegation.

Identity Security Insights access

  • Administrator access to Identity Security Insights.
  • Your Insights site is provisioned and active.

APIs to enable

Detailed steps follow

  • Cloud Asset API
  • Cloud Logging API
  • Cloud Resource Manager API
  • Cloud IAM API
  • Service Usage API
  • Secret Manager API
  • Cloud KMS API
  • API Keys API
  • Discovery Engine API
  • (Optional) Admin SDK API, Google Drive API, Google Drive Activity API, Drive Labels API (if using Google Workspace)
  • (Optional) Vertex AI API (if enabling Vertex AI)
🚧

Important

Third-party documentation is subject to change. Updates might not be reflected in BeyondTrust documentation. For the most up-to-date information, visit the Google Cloud website.

Configuration paths

Installation method

MethodWhen to use
Option A Manual configurationYou prefer to configure resources step by step in the Google Cloud console
Option B Google Cloud ShellYou prefer to use CLI commands for faster setup

Both methods produce the same result. Choose the one that matches your team's workflow.

Optional integrations

IntegrationWhen to enable
Google WorkspaceYour organization uses Google Workspace and you want to collect user, group, drive, and audit data
Vertex AIYou want to collect AI agent and model data from Vertex AI

Cloud environment (if applicable)

EnvironmentWhen to select
FedRAMP HighYour organization operates FedRAMP High assured workloads
FedRAMP ModerateYour organization operates FedRAMP Moderate assured workloads only
CommercialAll other environments
⚠️

FedRAMP Compliance Notice

Insights Commercial is not FedRAMP-compliant. Using it in combination with the following cloud environments may result in data residency issues and loss of compliance:

  • FedRAMP High
  • FedRAMP Moderate

Step 1: Create the connector in Insights

  1. From Insights Home, select > Connectors.

  2. Select the Available tab.

  3. Click Create Connector beside Google Cloud Platform.


    Create Google Cloud connector settings
  4. Enter a human-readable name for your connector.

  5. Select your cloud environment (Commercial, FedRAMP Moderate, or FedRAMP High).

  6. Select your installation method:

    • Manual Configuration: If you chose Option A
    • Google Cloud Shell: If you chose Option B

Step 2: Retrieve your Organization ID

  1. In the Google Cloud Console, click the project selector in the top navigation bar.
  2. Select your organization.
  3. Navigate to IAM & Admin > Settings.
  4. Copy your Organization ID.

Paste your Organization ID in the Organization ID field in Identity Security Insights.

Step 3: Create a new project

  1. In the Google Cloud Console, click the project selector and select your organization.
  2. In the project window, click New Project.
  3. Enter a human-readable name for your project.
  4. Click Create.

Step 4: Enable required services

  1. From your new project's navigation menu, go to APIs & Services > Library.
  2. Search for and enable the following APIs:
    • Cloud Asset API
    • Cloud Logging API
    • Cloud Resource Manager API
    • Cloud IAM API
    • Service Usage API
    • Secret Manager API
    • Cloud KMS API
    • API Keys API
    • Discovery Engine API

Google Workspace (if applicable)

Also enable:

  • Admin SDK API
  • Google Drive API
  • Google Drive Activity API
  • Drive Labels API

Vertex AI (if applicable)

Also enable:

  • Vertex AI API

Ensure all projects within your organization have the same APIs enabled.

Step 5: Create a service account

  1. From the navigation menu, go to IAM & Admin > Service Accounts.
  2. Click Create Service Account.
  3. Enter a human-readable display name.
  4. Enter a unique service account ID.
  5. Note the email address generated by Google Cloud — you'll need it in the next step.
  6. Click Done.

Step 6: Assign service account roles

  1. In the top navigation toolbar, click the project selector and select your organization.
  2. Navigate to IAM & Admin > IAM and click Grant Access.
  3. In the New principals field, enter the service account email generated in Step 5.
  4. Under Assign roles, at organization scope, select:
    • Cloud Asset Viewer
    • Security Reviewer
    • Logs Viewer
    • Organization Viewer
    • Secret Manager Secret Accessor
    • Secret Manager Viewer
    • Cloud KMS Viewer
    • API Keys Viewer

Vertex AI (if applicable)

Also assign:

  • Discovery Engine Viewer
  • Storage Object Viewer (if you enabled Allow access to agent model details)
  1. Click Save.

Step 7: Generate a key for the service account

  1. In the top navigation toolbar, click the project selector and select your project.
  2. Go to IAM & Admin > Service Accounts and select your service account.
  3. Click the Keys tab.
  4. Click Add Key > Create new key.
  5. Select JSON as the key type.
  6. Click Create.
  7. A new key downloads automatically. Store the JSON key in a secure location.

Step 8: Set up Google Workspace permission (optional)

Complete this step only if your organization uses Google Workspace and you want to collect user, group, drive, and audit data.

Configure Domain-Wide Delegation

  1. Navigate to Admin Console > Security > API Controls > Domain-wide Delegation.
  2. Click Add new.
  3. Enter the service account's Client ID (the 21-digit number from the client_id field in the key JSON file).
  4. Add the following OAuth scopes (comma-separated):
https://www.googleapis.com/auth/admin.directory.user.readonly
https://www.googleapis.com/auth/admin.directory.group.readonly
https://www.googleapis.com/auth/admin.directory.orgunit.readonly
https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly
https://www.googleapis.com/auth/admin.directory.customer.readonly
https://www.googleapis.com/auth/admin.directory.user.security
https://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/admin.reports.usage.readonly
https://www.googleapis.com/auth/apps.alerts
https://www.googleapis.com/auth/cloud-identity.groups.readonly
https://www.googleapis.com/auth/drive.readonly
https://www.googleapis.com/auth/drive.metadata.readonly
https://www.googleapis.com/auth/drive.activity.readonly
https://www.googleapis.com/auth/drive.labels.readonly
https://www.googleapis.com/auth/drive.admin.labels.readonly
https://apps-apis.google.com/a/feeds/domain/
  1. Click Save.

Final step: Create the connector

  1. In Identity Security Insights, paste the Service Account Key (the full JSON key from Step 7).
  2. (If using Google Workspace) Select Yes on the Use Google Workspace dropdown and enter an organization admin email in the Admin User Email field.
  3. Click Create Connector.

Navigate to ☰ > Connectors > Configured to confirm connector creation was successful and review connector settings.


©2003-2026 BeyondTrust Corporation. All Rights Reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.