Supported Features
The SailPoint Google Workspace connector supports the following features:
Account Management
-
Manage GCP members as Accounts
Supported GCP member types are as follows:
-
Google Account (Google Workspace Identities and Cloud Identities [managed only] )
-
Service account
-
Domain (Google Workspace Or Cloud Identity Domain)
-
Google Group
-
-
Create, update, and delete accounts
-
Aggregate and refresh accounts
-
Aggregate and provision custom schema attributes
-
Delta aggregation
Only for Google Account Type
-
Partitioning aggregation
Only for Google Account Type
-
Enable and disable accounts
Only for Google Account Type
-
Change password
Only for Google Account Type
-
Add and remove entitlements
-
Archive and unarchive Google Workspace Users
Note
This is only applicable to Google Workspace Users from the managed system itself. This doesn't apply to other account types.
Group Management
-
Manage Google Workspace groups as Account - Groups
-
Aggregate and refresh roles
-
Create, update, and delete groups
-
Add or remove entitlements, and group entitlements for Google Accounts and Service Accounts
Role Management
-
Manage Google Workspace roles as Account - Roles
-
Aggregate and refresh roles
-
Create, update, and delete roles
IAM Role Management
-
Manage GCP Iam roles as iamRole
-
Aggregate and refresh roles
-
Create, update, and delete roles
IAM Resource Permission Management
-
Manage GCP resource permissions as
iamResourcePermission
-
Aggregate and refresh IAM resource permissions
Folder Management
-
Manage GCP Folder as – folder
-
Aggregate and refresh folders
Project Management
-
Manage GCP Project as – project
-
Aggregate and refresh projects
-
Manage delegated administrators (supported with Service Account Authorization only) and Aliases on accounts
Other Features
-
Transfer Data from One Google Account to Another Before Deleting the Account
For information on the attributes to be configured for data transfer, refer to Additional Configuration Parameters.
-
The Google Workspace/GCP Connector Supports Proxy Authentication
Supported Features Comparison with Cloud Governance
Important
If you want to enable additional cloud governance features (for example, visualization of effective access) for your GCP Cloud Infrastructure, you must have a
Supported Features |
Google Workspace Connector (Standard Features) |
Google Workspace Connector (With Cloud Governance) |
---|---|---|
Account Management
|
Yes |
Yes |
GCP Accounts
|
No |
Yes |
Group Management
|
Yes |
Yes |
Role Management
|
Yes |
Yes |
IAM Role Management
|
No |
Yes |
Project Management
|
No |
Yes |
Folder Management
|
No |
Yes |
IAM Resource Permission Management
|
No |
Yes |