Skip to content
All integrations
Google Workspace

Review Google Workspace access and sharing.

Synchronize users and groups. With the separate Google security connection, review third-party app grants and Drive sharing, then remove unnecessary permissions.

Directory sync · Separate grant for app and Drive security

Product illustration · Example data and workflow.

Capabilities

What this integration covers.

01

Synchronize users and groups.

Use directory records to identify the people involved in an access review.

02

Find unnecessary app access.

Review supported third-party OAuth grants and revoke access your team no longer needs.

03

Resolve overshared files.

Ask the file owner for context, then remove unnecessary Drive permissions through Elba.

Example workflow

Review and remove an unnecessary Drive permission.

How the integration supports a specific security task.

  1. 01

    Identify the sharing issue

    Elba identifies a Drive file with an eligible external-sharing issue.

  2. 02

    Review with the owner

    The owner reviews who still needs access to the file.

  3. Remove the permission

    An unnecessary permission is removed through the connected Google security source.

Related capability

Explore this part of the platform.

Explore data protection

Before you connect

Coverage, permissions, and requirements.

Directory synchronization is the base connection. OAuth-grant and Drive security capabilities use a separate Google security-source grant and are available only when enabled for your workspace.

Explore security & privacy
Which Google role is required?

Use a Google Workspace Super Admin. Only that role can grant the domain-wide delegation required by the setup flow.

Does connecting the directory automatically inspect Drive?

No. Directory synchronization is separate from the Google security-source grant used for supported OAuth-grant and Drive workflows.

Can elba revoke every OAuth grant or Drive permission?

No. Direct changes apply only to supported grants, permissions and objects exposed as eligible by the live connection.

Where should administrators verify requested access?

Review the scopes displayed in elba and the live Google Admin delegation entry. Those current screens take precedence over copied or older scope lists.

Coverage and requirements
  • The base directory connection does not by itself enable OAuth-grant or Drive security analysis.
  • Google uses separate grants for sign-in, directory synchronization, security analysis and optional capabilities.
  • The Drive scope is broad; review the live delegation entry and provider authorization details before approval.
  • Available findings and actions vary by workspace configuration, source state and object type.

Other applications

Review more integrations.

All integrations

Discuss your requirements

Evaluate Elba for Google Workspace.

Review the available capabilities, required permissions, and setup for your environment with our team.

Request a demo