The documentation below outlines the requirements for the Barracuda XDR Automated Threat Response (ATR) for Google Workspace.
Requirements
You must have:
Access to the Barracuda XDR Dashboard set up and working properly
Access to Google Workspace set up and working properly
Setting up ATR for Google Workspace
To set up ATR for Google Workspace, do the following procedures:
To create a service account and add a new Private key
To enable the Google Workspace Admin SDK
To enable SOAR in the XDR Dashboard
To create a service account and add a new Private key
Using a web browser, log in to the Google Cloud Console using the admin account.
Do one of the following:
Choose an existing project.
Create a new project.
In the left sidebar, navigate to IAM & Admin > Service Accounts.
Click Create Service Account.
Type a Name and Description for the service account.
Assign the Service Account User and Service Account Admin roles to the admin ID.
Click the three dots next to the newly created account, then click Manage Keys.
Click Add Key > Create New Key.
Copy the key and save it in a safe place.
You will use the key in the To configure XDR Dashboard procedure, below.
To enable the Google Workspace Admin SDK
Using a web browser, navigate to https://console.cloud.google.com/apis/library.
Search for Admin SDK API, then click it.
If Admin SDK API isn't enabled, enable it.
When Admin SDK API is enabled, validate it.
To update Domain Wide Delegation
Using a web browser, log in to the Google Cloud Console using the admin account.
Navigate to Security > API Controls > Manage Domain Wide Delegation.
Click Add New and type the Client ID of your service account.
Add the required scopes:
https://www.googleapis.com/auth/admin.directory.user
https://www.googleapis.com/auth/admin.directory.user.security
To configure XDR Dashboard
In Barracuda XDR Dashboard, click SOAR Settings > Cloud.
In the table, click Google Workspace.
Click Edit Config.
Do the following:
In Service Account ID, type the account id created in the previous setup steps.
In Administrator Account Email, type the email address of the admin account that was assigned the Service Account Admin role for the service account.
In Service Account Private Key, enter the API key of the service account in this field.
Click Save.
In the left navigation bar, click SOAR Settings > Cloud.
In the table, click Google Workspace.
Click Disable/Enable User.
Click one of the following:
Disable
Enable
In Disable/Enable, type the User ID of the user you wish to disable or enable.
Click Submit.