Assigning Roles to an Impersonated User

Manage G-Suite Users/Groups/Roles

To assign the Roles (Built-in/Custom) to an Impersonated User for managing G-Suite Users/Groups/Roles, complete the following:

  1. Go to Google Admin page.

  2. In the left pane, go to the Directory and select Users tab.

  3. Select the configured Impersonated user (used as jwt subject).

  4. Expand the Admin roles and privileges section for that user.

    Assign all the required roles here to this user mentioned in the documentation under the G-Suite section.

Manage Google Cloud Resources

To assign the Roles (Built-in/Custom) to an Impersonated User for managing cloud resources (When Manage Cloud Resources is enabled on the ISC user-interface), complete the following:

  1. Go to Google Console.

  2. Select IAM & Admin tab and make sure you are viewing it for the Organization (domain which is configured as organization ID) (such as, dev.sailpoint.com)

  3. Select Grant Access button.

  4. Under Add Principal, select the Impersonated User (IAM user) which is configured as jwt subject during source configuration(Google Workspace connector).