About WatchGuard SaaS DR Cloud Integration — Google Workspace

Applies To: WatchGuard SaaS DR, Total NDR

WatchGuard SaaS DR enables you to monitor user activity from third-party Software as a service (SaaS) and cloud environments, such as Google Workspace. WatchGuard SaaS DR integrates with Google Workspace to collect user activity logs from Google Workspace to monitor, respond to, and report on, anomalous user activity and logins by authorized and unauthorized users. The Google Workspace integration provides secure, read‑only access to audit logs and security alert data through Google Workspace APIs and a Google service account with domain‑wide delegation to collect security telemetry.

The integration process includes these steps:

  • Enable the required Google Workspace APIs in a Google Cloud project
  • Create a Google service account and generate a private key
  • Grant domain‑wide delegation to the service account in the Google Admin console
  • Upload the service account credentials to NDR

WatchGuard SaaS DR for Google Workspace includes:

  • Defense controls in two main categories:
    • Exfiltration by an Internal Actor
    • Suspicious Access Behavior
  • Google Workspace Defense Goal Report
  • Google Workspace user activity monitoring
  • Google Workspace policy alerts

For more information, go to these sections:

Licensing

To use WatchGuard SaaS DR, you must purchase and activate a WatchGuard SaaS DR license or a Total NDR license. WatchGuard SaaS DR is licensed for each user.

For more information about licensing, go to About WatchGuard SaaS DR Licenses and About Total NDR Licenses.

Reports

Reports are a critical part of monitoring your organization for threats. WatchGuard SaaS DR for Google Workspace provides the Google Workspace Defense Goals Report to help you monitor user activity, unusual logins, and suspicious file sharing activity for your users.

For more information, go to WatchGuard SaaS DR Reports.

To add the default WatchGuard NDR reports, additional defense control reports, plus the ability to generate custom reports, we recommend you add a WatchGuard NDR license and a WatchGuard Compliance Reporting license. You can also purchase the Total NDR license that includes all NDR licenses and includes Compliance Reporting. For more information about Total NDR, go to About Total NDR.

For more information, go to WatchGuard NDR Reports and About WatchGuard Compliance Reporting.

Add a NDR Cloud Integration

To add a cloud integration, you use the NDR Integrations UI in WatchGuard Cloud. To add a NDR cloud integration, select Configure > NDR Integrations.

Screenshot of a successful cloud integration added to NDR that shows the Active status

For more information, go to Configure a WatchGuard SaaS DR Cloud Integration — Google Workspace.

NDR UI

To configure and monitor WatchGuard SaaS DR, you use the NDR UI in WatchGuard Cloud. To connect to WatchGuard Cloud, go to cloud.watchguard.com.

Available pages and features vary and depend on your license type. Throughout this documentation, NDR refers generally to all products. If you do not see a page or feature in the NDR UI, it is not supported by your product.

Monitor WatchGuard SaaS DR

To monitor your NDR cloud integration, use these pages:

  • Network Summary — Provides an overview of trends in your network and includes links to detailed information about policy alerts, and user activity. For more information, go to About the NDR Summary Page.
  • Policy Alerts — Shows alerts for policy violations on your network. For more information, go to About Policy Alerts.
  • Users — Shows details about user activity and threat detection.
  • NDR Audit Logs — Shows details of configuration activity performed for WatchGuard SaaS DR policies, zones, users, IP addresses, and collector changes. For more information, go to NDR Audit Logs.

Configure WatchGuard SaaS DR

To configure WatchGuard SaaS DR, select Configure > NDR.

You can use these pages to configure WatchGuard SaaS DR:

Related Topics

Configure a WatchGuard SaaS DR Cloud Integration — Google Workspace

Configure NDR

Monitor NDR