SaaSセキュリティ態勢管理のためにGoogle Workspaceを設定するには、以下の手順に従ってください。
Prerequisite
SaaSセキュリティ態勢管理のためにGoogle Workspaceを設定する前に、前提条件を確認してください。
- Google Workspace(ビジネスエディションのライセンスが付与されているもの)
- Netskopeとの連携のためのGoogleスーパー管理者アカウント
Netskope 、OAuth 2.0トークンベースをサポートするトークンリソースを取得するためにスーパー管理者ロールが必要です。 (OAuthトークンに関連するルールなど)
Step 1 : Grant Scopes to the Netskope Service Account
このセクションでは、 NetskopeウェブアプリケーションとAPIクライアントをGoogleに登録して、Google Workspace内のデータにアクセスできるようにするために必要な手順について説明します。
-
スーパー管理者としてadmin.google.comにログインしてください。
-
Security > Access and data control > API controlsへ移動してください。
-
API controls ページのDomain wide delegationの下にあるManage Domain Wide Delegationをクリックします。

-
Add newをクリックして新しいAPIクライアントを作成します。新しいポップアップウィンドウが開きます。

-
Client IDの場合は、
115103394993879524295を入力してください。
-
以下のカンマ区切りのOAuth scopesリストを入力してください:
https://www.googleapis.com/auth/admin.directory.user.readonly,https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly,https://www.googleapis.com/auth/admin.directory.orgunit.readonly,https://www.googleapis.com/auth/admin.directory.customer.readonly,https://www.googleapis.com/auth/admin.directory.user.security,https://www.googleapis.com/auth/admin.directory.group.readonly,https://www.googleapis.com/auth/admin.reports.audit.readonly,https://www.googleapis.com/auth/admin.directory.device.mobile.readonly,https://www.googleapis.com/auth/admin.directory.domain.readonly,https://www.googleapis.com/auth/admin.directory.device.chromeos.readonly,https://www.googleapis.com/auth/admin.directory.userschema.readonly,https://www.googleapis.com/auth/admin.directory.resource.calendar.readonly,https://www.googleapis.com/auth/apps.groups.settings

-
Authorizeをクリックしてください。
-
上記の手順が正しく行われたことを確認するには、 Netskope for Google アプリが API クライアントのリストに表示されるかどうかを確認してください。
Step 2 : Configure Google Workspace Instance in Netskope UI
NetskopeがGoogle Workspaceインスタンスにアクセスすることを承認するには、以下の手順に従ってください。
- Log in to the Netskope tenant UI and go to Settings > Configure App Access > Next Gen > Security Posture.
- Appsの下でGoogle Workspace を選択し、 Setup Security Posture Instanceをクリックします。Setup Instance ウィンドウが開きます。
- API Admin Emailに、特権管理者の Google アカウントの電子メールを入力します。
- Google Workspace administrator emailの下に、 セキュリティ態勢に関する調査結果を受け取るユーザーのアドレスを入力してください。 これは、セキュリティ態勢ポリシーを作成する際に追加できます。
- Security Scan Interval ドロップダウンリストから、必要なスキャン間隔を選択してください。これは、Netskopeがポリシーを定期的に実行する間隔です。
- Grant Accessをクリックしてください。使うスーパー管理者または同じGoogle Workspaceドメインに属する任意のユーザーにログインするよう促され、 Sign Inをクリックします。 設定結果ページが開いたら、 Closeをクリックします。
- ブラウザを更新すると、そのインスタンスが表示されます。

