Fetch and store Google Workspace user data to use in detections and search
Overview
You can configure your Google Workspace log source integration in Panther to pull user profiles into Panther-managed Lookup Tables. This means you can use profile data in detection logic and search queries.
You can customize user profiles in Google Workspaces by following their documentation. You might consider adding custom attributes that would be useful in detection logic, such as the level of permissions expected for that user.
How to set up Google Workspace user profiles in Panther
You can configure Google Workspace user profiles while you are initially setting up your Google Workspace log source integration in Panther, or later, by editing the source.
During either flow, you'll toggle the Google Workspace profile pulling setting on, then set the cadence at which you'd like profile data to be refreshed.
In order to enable Google Workspace user profiles in Panther, you must first (or concurrently) onboard Google Workspace as a log source. It is not possible to set up an Google Workspace user profiles integration without onboarding Google Workspace as a log source in Panther.
Prerequisites for Google Workspace user profiles
In order to pull Google Workspace user profiles into Panther, the following configurations must be set:
Your Google Workspace Cloud App must have the https://www.googleapis.com/auth/admin.directory.user.readonly scope.
The user who created the Google Cloud App must have read users privileges.
Configure Google Workspace profiles in Panther during Google Workspace source setup