Configure Google Workspace Account
The Google Workspace account to be added to FortiCWP requires a Super Admin Role or Custom User Role (recommended) assigned.
It is recommended to create a user within the Google Workspace account that is designated to be added to FortiCWP and assigned it with Custom User Role.
Follow the configurations below to create a Custom User Role, then assign it to a Google Workspace account user.
Create Custom User Role
- Log into Google Admin Console with your Google Workspace Super Administrator Account. (Only Super Administrator Account can create roles)
- From Google Admin navigation menu, go to Account > Admin roles, then click Create new role.
- Fill in a name for the role, a short description, and click Continue.
- Select the role privileges according to the table below, then click Continue.
- Review all the role privileges selected, then click Create Role.
Privilege | Permission |
---|---|
Admin console privileges | |
Organization Units | Read |
Users | Read |
Groups | |
Domain Settings | |
Reports | |
Admin API privileges | |
Organization Units | Read |
Users | Read |
Groups | Create, Read, Update, Delete |
Billing Management | Billing Read |
Domain Management | |
Domain Allowlist Management | Domain Allowlist Read |
The custom role can now be assigned to a Google Workspace user that is designated to be added to FortiCWP.
Assign Custom User Role
- Log into Google Admin Console with your Google Workspace Super Administrator Account.
- From the Google Admin navigation menu, go to Directory > Users.
- Click on the user that will be added to FortiCWP Workload Protection.
- Scroll down and click on Admin roles and privileges.
- Click on the edit button to reveal all available roles.
- Click on the toggle switch button to assign the custom user role created. Make sure Super Admin role is not assigned.
- Click Save to finish assigning the custom user role to the user.
After Google Workspace user configuration is completed, continue with the rest of the configurations.