Synchronize users and groups.
Use directory records to identify the people involved in an access review.
Synchronize users and groups. With the separate Google security connection, review third-party app grants and Drive sharing, then remove unnecessary permissions.
Directory sync · Separate grant for app and Drive security
Product illustration · Example data and workflow.
Capabilities
Use directory records to identify the people involved in an access review.
Review supported third-party OAuth grants and revoke access your team no longer needs.
Ask the file owner for context, then remove unnecessary Drive permissions through Elba.
Example workflow
How the integration supports a specific security task.
Elba identifies a Drive file with an eligible external-sharing issue.
The owner reviews who still needs access to the file.
An unnecessary permission is removed through the connected Google security source.
Related capability
Before you connect
Directory synchronization is the base connection. OAuth-grant and Drive security capabilities use a separate Google security-source grant and are available only when enabled for your workspace.
Explore security & privacyUse a Google Workspace Super Admin. Only that role can grant the domain-wide delegation required by the setup flow.
No. Directory synchronization is separate from the Google security-source grant used for supported OAuth-grant and Drive workflows.
No. Direct changes apply only to supported grants, permissions and objects exposed as eligible by the live connection.
Review the scopes displayed in elba and the live Google Admin delegation entry. Those current screens take precedence over copied or older scope lists.
Discuss your requirements
Review the available capabilities, required permissions, and setup for your environment with our team.