To configure Google Workspace for SaaS Security Posture Management, follow the instructions below.
Prerequisite
Before configuring Google Workspace for SaaS Security Posture Management, review the prerequisites:
- A Google Workspace with any Business edition license.
- A Google super admin account for Netskope integration
Step 1 : Grant Scopes to the Netskope Service Account
This section describes the steps required to register the Netskope web application and API client with Google to enable access to data in Google Workspace.
-
Log in to admin.google.com as a super admin.
-
Navigate to Security > Access and data control > API controls.
-
On the API controls page, under Domain wide delegation, click Manage Domain Wide Delegation.

-
Click Add new to create a new API Client. A new pop-up window opens.

-
For Client ID, enter
115103394993879524295.
-
Enter the following comma separated list of OAuth scopes:
https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly,https://www.googleapis.com/auth/admin.directory.orgunit.readonly,https://www.googleapis.com/auth/admin.directory.customer.readonly,https://www.googleapis.com/auth/admin.directory.user.security,https://www.googleapis.com/auth/admin.directory.group.readonly,https://www.googleapis.com/auth/admin.reports.audit.readonly,https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,https://www.googleapis.com/auth/admin.directory.domain.readonly,https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly,https://www.googleapis.com/auth/admin.directory.userschema.readonly,https://www.googleapis.com/auth/admin.directory.resource.calendar.readonly,https://www.googleapis.com/auth/apps.groups.settings

-
Click Authorize.
-
Verify the steps above by checking if the Netskope for Google app appears in the API clients list.
Step 2 : Configure Google Workspace Instance in Netskope UI
To authorize Netskope to access your Google Workspace instance, follow the steps below:
- Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > Security Posture.
- Under Apps, select Google Workspace and click Setup Security Posture Instance. The Setup Instance window opens.
- Under API Admin Email, enter the Google account email of the super admin.
- Under Google Workspace administrator email, enter the email address of the user who will receive the findings related to security posture. This can be added when creating security posture policies.
- From the Security Scan Interval drop-down list, select the required scan interval. This is the interval at which Netskope runs the policy periodically.
- Click Grant Access. You will be prompted to log in using a super admin or any user (belonging to the same Google Workspace domain), and then click Sign In. When the configuration results page opens, click Close.
- Refresh your browser, and you will see the instance.

