Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    SaaS Security Posture Management
    Onboard Supported SaaS Apps
    Onboard Google Workspace

    Onboard Google Workspace

    To configure Google Workspace for SaaS Security Posture Management, follow the instructions below.

    Prerequisite

    Before configuring Google Workspace for SaaS Security Posture Management, review the prerequisites:

    • A Google Workspace with any Business edition license.
    • A Google super admin account for Netskope integration

    Netskope requires the super admin role to fetch the token resources which support OAuth 2.0 token-based use cases like rules related to OAuth tokens, etc.

    Step 1 : Grant Scopes to the Netskope Service Account

    This section describes the steps required to register the Netskope web application and API client with Google to enable access to data in Google Workspace.

    1. Log in to admin.google.com as a super admin. 

    2. Navigate to Security > Access and data control > API controls. 

    3. On the API controls page, under Domain wide delegation, click Manage Domain Wide Delegation. 

    4. Click Add new to create a new API Client. A new pop-up window opens.

    5. For Client ID, enter 115103394993879524295.

    6. Enter the following comma separated list of OAuth scopes:

      https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly,https://www.googleapis.com/auth/admin.directory.orgunit.readonly,https://www.googleapis.com/auth/admin.directory.customer.readonly,https://www.googleapis.com/auth/admin.directory.user.security,https://www.googleapis.com/auth/admin.directory.group.readonly,https://www.googleapis.com/auth/admin.reports.audit.readonly,https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,https://www.googleapis.com/auth/admin.directory.domain.readonly,https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly,https://www.googleapis.com/auth/admin.directory.userschema.readonly,https://www.googleapis.com/auth/admin.directory.resource.calendar.readonly,https://www.googleapis.com/auth/apps.groups.settings
    7. Click Authorize.

    8. Verify the steps above by checking if the Netskope for Google app appears in the API clients list.

    Step 2 : Configure Google Workspace Instance in Netskope UI 

    To authorize Netskope to access your Google Workspace instance, follow the steps below:

    1. Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > Security Posture.
    2. Under Apps, select Google Workspace and click Setup Security Posture Instance. The Setup Instance window opens. 
    3. Under API Admin Email, enter the Google account email of the super admin. 
    4. Under Google Workspace administrator email, enter the email address of the user who will receive the findings related to security posture. This can be added when creating security posture policies. 
    5. From the Security Scan Interval drop-down list, select the required scan interval. This is the interval at which Netskope runs the policy periodically.
    6. Click Grant Access. You will be prompted to log in using a super admin or any user (belonging to the same Google Workspace domain), and then click Sign In. When the configuration results page opens, click Close. 
    7. Refresh your browser, and you will see the instance.

    References

    • Scopes Required for Google Workspace

    • SaaS Security Posture Management Policy Wizard

    In this Topic
    • Onboard Google Workspace