Information
Google Workspace and Cloud Identity maintain audit logs for administrative actions, such as user creation, password changes, and modifications to security settings. By default, these logs are only available within the Google Admin Console.
Enabling the "Sharing of data with Google Cloud Services" setting allows these logs to flow into the Google Cloud (GCP) Organization's Cloud Logging. This is critical for centralized security monitoring, long-term log retention, and the creation of automated alerts for high-risk identity events like privilege escalation.
Without centralized logging of identity provider events, security teams cannot easily correlate Workspace/Identity administrative changes with GCP resource changes. If a Super Admin account is compromised, the audit trail must be preserved in a secure, centralized location to prevent an attacker from deleting evidence within the Workspace console.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
-
Log in to the Google Admin Console as a Super Admin.
-
From the Home page, go to Account > Account settings.
-
Click on the Legal and compliance section.
-
Locate the setting titled Sharing options - Google Cloud Platform Sharing Options.
- Click on Enabled
- Click on Save
-
(Optional but Recommended) Navigate to the GCP Console > Logging > Logs Explorer and verify that the logs are arriving from the admin portal.