Integration: Kaseya SIEM and Google Workspace
Kaseya SIEM
NAVIGATION Organizations > Edit Organization (pencil icon) > + New Application > Google Workspace
PERMISSIONS Administrator permissions
Google Workspace
NAVIGATION Google Admin Console
PERMISSIONS Super Administrator permissions
The Kaseya SIEM and Google Workspace integration enables organizations to connect a Google Workspace tenant to Kaseya SIEM through Google's authentication and authorization workflow. Once connected, Google Workspace becomes available as an application within the organization and can be managed from the organization's Applications tab.
Prerequisites
Before configuring the integration, make sure the following requirements are met:
-
A Google Workspace tenant
-
A Google Workspace Super Administrator account
-
A Google Workspace license that supports third-party integrations
-
Administrative access to Kaseya SIEM
Supported licenses
Google Workspace licenses that support third-party integrations include:
-
Google Workspace Enterprise
-
Google Workspace Business Starter
-
Google Workspace Business Standard
-
Google Workspace Business Plus
-
Google Workspace Education Fundamentals
-
Google Workspace Education Standard
-
Google Workspace Education Plus
-
Cloud Identity Premium
Unsupported licenses
The following licenses do not support third-party integrations and cannot be connected:
-
Google Workspace Essentials Starter
-
Google Workspace Enterprise Essentials
How to...
-
Sign in to Google Admin Console using a Super Administrator account.
-
Navigate to Security > Access and data control > API controls.
-
Click Manage Third-Party App Access.
-
From the Add app drop-down menu, select OAuth App Name Or Client ID.
-
Enter the application name provided for the integration, click Search, and then click Select.
-
Select all three web apps in the OAuth client IDs section.
-
Select the organization(s) that will be managed through the integration.
-
Select Trusted.
-
If prompted, select the allowlist checkbox.
-
Click Continue.
-
Review the configuration and click Finish.
The required permissions are now configured and the Google Workspace tenant is ready to be connected.
-
In Kaseya SIEM, from the side navigation menu, go to Organizations.
-
Click Edit Organization (pencil icon) for the organization you want to configure.
-
Click + New Application.
-
Locate Google Workspace and click Connect.
-
Complete the Google sign-in and authorization process using a Super Administrator account.
-
Review the requested permissions and authorize the connection.
When the connection is successful, Google Workspace appears under the organization's Applications tab.
To disable the integration, complete the following steps:
-
From the side navigation menu, go to Organizations.
-
Click Edit Organization (pencil icon).
-
On the Applications tab, select the Google Workspace tile.
-
Select Disconnect Application.
-
Confirm the action.
Kaseya SIEM stops collecting data from the connected Google Workspace tenant.
Troubleshooting
Verify that the Google Workspace tenant is using a supported license. Google Workspace Essentials Starter and Enterprise Essentials licenses do not support third-party integrations and cannot be connected.
Verify that the application was set to Trusted in Google Admin Console before completing the connection process. Applications that are not marked as Trusted may not receive the permissions required for the integration.