Connect WatchGuard Total MDR with Google Workspace
Applies To: WatchGuard Total MDR
If you have a WatchGuard Total MDR license, to enable WatchGuard MDR to monitor your Google Workspace account endpoints, you must configure a connection from your Google Workspace environment to WatchGuard.
To connect WatchGuard MDR and your Google Workspace environment, complete these steps:
- Enable the Google Admin SDK API
- Create a Google Service Account
- Create an API Key
- Add the Client ID with OAuth Scopes
- Add the Integration in the Managed Services Portal
Enable the Google Admin SDK API
The WatchGuard MDR integration uses the Google Admin SDK API to connect to your Google Workspace. Before you configure the connection, you must enable the Google Admin SDK API.
To enable the Google Admin SDK API:
- Go to the Google Cloud Platform console at https://console.cloud.google.com/ and log in with a Super Admin account.
- From the console menu, select APIs & Services > Library.
The API Library page opens.
- In the search box, search for admin sdk.
- From the search results, select Admin SDK API.
The Admin SDK API page opens.
- Click Enable.
The API Library page opens. - In the search box, search for alert center api.
- From the search results, select Alert Center API.
The Google Workspace Alert Center API page opens.
- Click Enable.
Create a Google Service Account
For WatchGuard MDR to authenticate to your Google Workspace environment, you must create a Google Service Account.
To create a Google Service Account:
- Go to the Google Cloud Platform console at https://console.cloud.google.com/ and log in with a Super Admin account.
- From the console menu, select IAM & Admin > Service Accounts.
The Service Accounts page opens.
- Click Create Service Account.
The Create Service Account page opens. - Enter a Name and Description for the account. Click Create and Continue.
- From the Permissions section, assign the Service Account Token Creator role. Click Done.
- From the Service Account Details page, click the new account.
- Copy the Oauth2 Client ID to use later in these instructions.
Create an API Key
For WatchGuard MDR to authenticate to your Google Workspace environment, you must also create an API key.
To create an API key:
- Go to the Google Cloud Platform console at https://console.cloud.google.com/ and log in with a Super Admin account.
- From the console menu, select IAM & Admin > Service Accounts.
The Service Accounts page opens.
- Next to the service account you created, click
. - Select Manage Keys.
- In the Keys tab, from the Add Key menu, select Create New Key.
The Create Private Key pane opens.
- Select JSON.
- Click Create.
Your computer downloads the private key JSON file. Keep this file in a secure location in your local environment. - Click Close.
- Return to the Service Accounts page.
- Next to the service account, click
. - Click Manage Details.
The Service Account Details page opens.
- Copy the Unique ID to use later in these instructions.
Add the Client ID with OAuth Scopes
To add the client ID with OAuth Scopes:
- Go to the Google Admin console at https://admin.google.com/ac/home and log in with a Super Admin account.
- From the console menu, select Security > API Controls > Domain-wide Delegation.
The API Clients page opens.
- Click Add New.
The Add a New Client ID page opens. - Enter the Unique ID you copied from the Create a Google Service Account section.
- Enter the OAuth Scopes for the connector:
- For Alert reports, type: https://www.googleapis.com/auth/apps.alerts
- For Application reports, type: https://www.googleapis.com/auth/admin.reports.audit.readonly
- Click Authorize.
Add the Integration in the Managed Services Portal
To add the integration:
- In WatchGuard Cloud, select Monitor > Managed Services.
The Managed Services portal opens in a new browser tab. - If you are a Service Provider, select your Subscriber account from the drop-down list.
- In the upper, right corner of the Managed Services portal, click
. - From the drop-down list, select Onboarding.
- From the navigation menu, select Integrations.
The Integrations page opens.
- Click Add Service > G Suite.
The G Suite tab opens.
- In the Google Admin Email text box, type the primary email address associated with your Google Workspace environment.
Do not use the Service Account email address. You must use the primary email address for your environment or the connection will fail.
- In the Private Key JSON File Content text box, copy and paste the contents of the JSON file you saved in Create an API Key.
- (Optional) In the Label text box, type a unique name for the integration.
- Click Add.











