Why does Forseti need GSuite scopes?

49 views
Skip to first unread message

Austin Whipple

unread,
Mar 31, 2020, 4:11:46 PM3/31/20
to Forseti Security Discussion
I'm at the following spot in the installation:

Later it says:

Forseti is a GCP scanner. Why does it need access to end user GSuite group, user, and app read privileges? This seems unnecessary and is a roadblock to finishing this installation.

Hannah Shin

unread,
Apr 1, 2020, 5:44:23 PM4/1/20
to Forseti Security Discussion
Hi Austin, 

Enabling GSuite is an optional feature for users who are looking to collect GSuite data that can be used in scanners like Groups and Groups Settings. Not enabling GSuite will not be a blocker to your installation.

Hope this helps!

Henry Chang

unread,
Apr 1, 2020, 8:12:22 PM4/1/20
to Hannah Shin, Forseti Security Discussion
Additionally, security in G Suite will affect the security in GCP.  For example, there are entry points to GCP via G Suite, such as adding G Suite Groups as members of IAM policies.  If you only look at GCP, there would be no visibility as to who are the members of the G Suite Group in the IAM policy, or how the G Suite Group is controlled.

--
You received this message because you are subscribed to the Google Groups "Forseti Security Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to discuss+u...@forsetisecurity.org.
To view this discussion on the web visit https://groups.google.com/a/forsetisecurity.org/d/msgid/discuss/ca3ac604-c95d-485d-a9ba-447c652c109c%40forsetisecurity.org.

Jean MERCIER

unread,
Jul 9, 2020, 5:34:17 AM7/9/20
to Forseti Security Discussion, Henry Chang, Forseti Security Discussion, Hannah Shin
Hello,

 but why is this field mandatory for terraform input ? gsuite_admin_email

thanks

Reply all
Reply to author
Forward
0 new messages