Enable Gmail BCC integration
To enable Gmail BCC integration:
- Log in to Zero Trust ↗.
- Select Zero Trust > Settings.
- Select SaaS Integrations.
- Select Add integration > Google Workspace.
- Select Select Integration.
Name your integration, then select Next.
- Once you have named your integration, select Next.
- On the Google Cloud Console ↗, go to the sidebar, select APIs & Services, then select Credentials.
- Select CREATE CREDENTIALS > Service account.
- Fill in the details to create a service account:
- Service account name: Enter
Message Retraction Service Account
. - Service account ID: Enter
message-retraction-service-acc
. - Service account description: Enter
Email Security Message Retraction
. - Select CREATE AND CONTINUE.
- Service account name: Enter
- In Grant this service account access to project, select Select a role > Choose Owner. Select CONTINUE, then select DONE.
- Go back to Credentials on the sidebar, and select your service account under Service Accounts. In Details, take note of the Unique ID.
- Select Advanced settings > VIEW GOOGLE WORKSPACE ADMIN CONSOLE, then enter your password. This will redirect you to the Google admin portal.
- On the sidebar, select Security > Access and data control > API controls > Select MANAGE DOMAIN WIDE DELEGATION.
- Select Add new > Add a new client ID:
-
Client ID: Enter the Unique ID you took note of in step 5.
-
OAuth scopes: Enter the following URLs:
-
Select AUTHORIZE.
-
On the Google Cloud Console ↗, select Service Accounts on the sidebar:
- Select the three dots, then:
- Select Manage keys.
- Select ADD KEY > Create new key.
- Select JSON > Select CREATE. This downloads a
.json
file which you will use at a later stage.
On the Zero Trust dashboard ↗, upload the .json
file downloaded on step 3.
Enable the following APIs on the Google Cloud Console:
- Enable Google Calendar API ↗
- Enable Google Drive API ↗
- Enable Google Admin SDK API ↗
- Enable Gmail API ↗
- Enable Google Service Usage API ↗
Log in to Google Workspace Admin Console: Enter your password and log in to the Google Workspace Admin Console.
- Copy the Client ID and Scopes displayed on the Zero Trust dashboard.
- On Google Admin, go to Security > Access and data control > API controls.
- Select MANAGE DOMAIN WIDE DELEGATION > Add new.
- Use the Client ID and copy the scopes to create a new API client. Refer to Delegate domain-wide authority to your service account ↗. Then, select Next.
Enter the email associated with the Google Workspace Administrator account. Your email must match the email associated with your Google Workspace account, or else your integration will not work.
- Select Create integration.
- Once you created your integration, you will be redirected to the Review details page, where you will be able to review Integration details.
- Review your details, then select Complete Email Security set up > Continue to Email Security.
Now that you have created an integration, you will need to connect your domains for Email Security to start scanning your inbox.