Google BigQuery Prerequisites
Before configuring Google BigQuery:
-
Create or use an existing service account or client credentials in your GCP environment.
Tip
It is highly recommended to use a service account for easier integration.
-
Grant organization-level permissions.
When connecting to SailPoint using an organization ID, the service account requires permissions at the Organization level to browse the resource hierarchy.
-
Switch to Organization Context.
- Select the Project/Resource dropdown at the top of the GCP Console.
- Select your organization (e.g.,
sptechdev.com) instead of a specific project.
-
Add a principal.
- In the left menu, go to IAM & Admin > IAM.
- Select Grant Access (or Add).
- In the New principals field, paste the full email address of your Service Account (e.g.,
name@project-id.iam.gserviceaccount.com).
-
Select a browser role.
- Under Assign Roles, select Browser (
roles/browser). This grants read-only access to browse the GCP resource hierarchy (organizations, folders, and projects).
- Under Assign Roles, select Browser (
-
Select Save.
-
-
Add Google Workspace SaaS as an Identity Security Cloud source where your deployment requires it, using the above configuration.
- If you are using a service account, verify the following APIs are enabled:
- Google BigQuery
- Cloud Assess
- DLP
- Cloud Resource Manager
- IAM
- Dataform
- For client credentials, verify the same scopes are enabled.
Adding an Identity Collector
Perform the following steps to add an identity collector:
- Go to Admin > Identity Collectors.
- Select Create New on the top right corner to open wizard.
In General details:
- Type - Google Drive
- Name - Logical name for the Identity Collector (Example: Google BigQuery IDC)
In Connection Details, select the Identity Security Cloud created Google Workspace SaaS source.
- User and Group Dynamic Fields Mappings are optional.
- Select Save.
Best Practice
Verify the Identity Collector associated to this application has completed an aggregation initiated from Data Access Security by navigating to Admin > Identity Collector > locate IC > Actions > Run Aggregation. This ensures all permissions will be mapped properly to Identity Security Cloud identities.
Google BigQuery Permissions
To enable Data Access Security to interact with Google Apps, you must:
-
Enable the required APIs
- Google BigQuery
- Cloud Assest
- DLP
- Cloud Resource Manager
-
For Client credentials, enabling the required Scopes is done when creating the credentials.
- For more details refer to the Google Workspace Prerequisites.
Documentation Feedback
Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.