<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GCP workspace (gsuite) information in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/527033#M884</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Our administrator added group reader to the prisma account&lt;/P&gt;
&lt;P&gt;.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CLimachi1_0-1673651450294.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47005i863C8715DA467FD2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CLimachi1_0-1673651450294.png" alt="CLimachi1_0-1673651450294.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But reading through the docs can´t find the RQL for getting the workspace specific information&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/iam-query/iam-query-examples" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/iam-query/iam-query-examples&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example changing the following with a group in workspace returns no results&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;config &lt;SPAN class=""&gt;from&lt;SPAN&gt; iam where dest.cloud.type = &lt;SPAN class=""&gt;'GCP' &lt;SPAN class=""&gt;and&lt;SPAN&gt; source.cloud.resource.type = &lt;SPAN class=""&gt;'user' &lt;SPAN class=""&gt;and&lt;SPAN&gt; grantedby.cloud.entity.name = &lt;SPAN class=""&gt;'your group name'&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CLimachi1_1-1673652371725.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47006iE3E30791CAE3B177/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CLimachi1_1-1673652371725.png" alt="CLimachi1_1-1673652371725.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 13 Jan 2023 23:28:39 GMT</pubDate>
    <dc:creator>CLimachi1</dc:creator>
    <dc:date>2023-01-13T23:28:39Z</dc:date>
    <item>
      <title>GCP workspace (gsuite) information</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/526968#M879</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enabled the IAM module and added the&amp;nbsp;&lt;SPAN&gt;Google Workspace (GSuite) group reader role to the prisma service account but have been not able to find the query to get group members or other workspace information.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Only information I currently get is the cloudresourcemanager api results.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also is it possible to get from workspace reports which accounts have 2SV enabled?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 13:48:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/526968#M879</guid>
      <dc:creator>CLimachi1</dc:creator>
      <dc:date>2023-01-13T13:48:34Z</dc:date>
    </item>
    <item>
      <title>Re: GCP workspace (gsuite) information</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/526994#M881</link>
      <description>&lt;P&gt;You must have administrator access to Google Workspace (GSuite) to grant Prisma Cloud Service Accounts the permissions to ingest data from groups on Google Workspace (GSuite). The permissions required for ingesting data on groups is either the predefined role Group Reader, or a custom role with groups:read permission.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please provide me the RQL you are using.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 18:14:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/526994#M881</guid>
      <dc:creator>BCastillo</dc:creator>
      <dc:date>2023-01-13T18:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: GCP workspace (gsuite) information</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/527033#M884</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Our administrator added group reader to the prisma account&lt;/P&gt;
&lt;P&gt;.&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CLimachi1_0-1673651450294.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47005i863C8715DA467FD2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CLimachi1_0-1673651450294.png" alt="CLimachi1_0-1673651450294.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;But reading through the docs can´t find the RQL for getting the workspace specific information&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/iam-query/iam-query-examples" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-rql-reference/rql-reference/iam-query/iam-query-examples&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example changing the following with a group in workspace returns no results&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;config &lt;SPAN class=""&gt;from&lt;SPAN&gt; iam where dest.cloud.type = &lt;SPAN class=""&gt;'GCP' &lt;SPAN class=""&gt;and&lt;SPAN&gt; source.cloud.resource.type = &lt;SPAN class=""&gt;'user' &lt;SPAN class=""&gt;and&lt;SPAN&gt; grantedby.cloud.entity.name = &lt;SPAN class=""&gt;'your group name'&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CLimachi1_1-1673652371725.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/47006iE3E30791CAE3B177/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="CLimachi1_1-1673652371725.png" alt="CLimachi1_1-1673652371725.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 23:28:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/527033#M884</guid>
      <dc:creator>CLimachi1</dc:creator>
      <dc:date>2023-01-13T23:28:39Z</dc:date>
    </item>
    <item>
      <title>Re: GCP workspace (gsuite) information</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/527439#M886</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There was fix that was going on for this. Could you please give it a try again and see if you are able to get any results.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jan 2023 18:26:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/gcp-workspace-gsuite-information/m-p/527439#M886</guid>
      <dc:creator>BCastillo</dc:creator>
      <dc:date>2023-01-17T18:26:56Z</dc:date>
    </item>
  </channel>
</rss>

