API & Integrations - Google Workspace Mail for Actual Phishing Integration

This article explains how to configure the integration between Mimecast's Human Risk Platform and Google Workspace to enhance Human Risk scoring, using End Users' phishing and mail-based threat behavior.

Overview

The integration with Mimecast's Human Risk Platform and Google Workspace enhances the robustness of Human Risk scoring, by adding human behavior relating to End Users' interactions with phishing and mail-based threats across their Google Workspace environment.
This allows you to send your users training and other information based on their phishing associated behavior.

The integration periodically reads phishing and mail-related security alerts from the Google Workspace Alert Center via API. These are forwarded to the Human Risk Platform, which associates each alert with a user and updates the phishing behavior score for that user.
This integration can be accessed from the Human Risk Command Center, which is available to all Mimecast Email Security - MX and Engage Core / Engage Pro customers.

Considerations

  • This feature is available to customers with a Human Risk Command Center subscription, available to all Mimecast Email Security - MX, and Engage Core / Engage Pro customers.
  • Historical events will not be pulled from Google Workspace Alert Center; only events from the point of integration onward. This simplifies Onboarding, and will not change historical scores.

Prerequisites

  • You must have a valid Google Workspace account, with access to the Google Workspace Alert Center API.
  • The service account must be granted the https://www.googleapis.com/auth/apps.alerts scope via domain-wide delegation in the Google Workspace Admin console.
  • You must have one of the following roles:
    • Global Sys Admin.
    • Sys Admin - SD Full.
    • Super Administrator.
    • Full Administrator.
    • Basic Administrator.
    • Partner Administrator.
    • Custom Role with Integrations Marketplace (Read/Write permissions must be enabled).

Configuring the Google Workspace: Mail integration


The integration is configured in the Google Cloud Platform console and Google Workspace Admin console, and then in the Mimecast Administration Console, in the Integrations Hub
To authenticate to the Google Workspace Alert Center API, you must create a service account with domain-wide delegation. These credentials are then used to create an integration with the Mimecast Human Risk Command Center.

Google-side configuration

You can enable the Google Workspace Alert Center API by using the following steps:

  1. Log in to your project in the Google Cloud console.
  2. Navigate to APIs and services | Library.

    Google - APIs and services | Library navigation
  3. Search for and select the Google Workspace Alert Center API. (If you're already logged in to the project in the Google Cloud console, you can navigate here using the following direct link).

    Google Workspace Alert Center API search results
  4. Click on Enable.

Add the integration in Mimecast Integrations Hub

You can add the Google Workspace: Mail for Actual Phishing Integration by using the following steps:

  1. Log in to the Mimecast Administration Console.
  2. Navigate to Integrations | Integrations Hub.

      Integrations Hub Navigation  
  3. From the available Integrations, locate and select Google Workspace: Mail integration.
  4. Provide the following two pieces of information:
Account Settings Customer ID
  1. Click on Authorize.
  2. Once the Google Workspace authentication screen is displayed, click on Go to Google Workspaces (which is at at https://admin.google.com/ac/owl/domainwidedelegation).
  3. Click on API clients: Add New.
    • Enter the Customer ID provided earlier.
    • Enter the scopes provided earlier.
Admin Add New API Client
  1. Continue saving the Google Workspace: Mail integration, with I've configured this.

Frequently asked questions

Q: How long does it take to deploy the integration?
A: The integration can be fully deployed in just a couple of minutes. It may take up to 24 hours for phishing behavior scores to appear in the Human Risk Dashboard.
Q: Is any historical data loaded from Google Workspace Alert Center?
A: Historical events will not be pulled from Google Workspace Alert Center; only events from the point of integration onward.
Q: Why do I not see many phishing events affecting users’ risk score?
A: A frequent concern users have with human risk is marking innocent users risky due to false positives in the security solutions we leverage for data. To mitigate this, only incidents with a true positive disposition are counted against users.

See Also...

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Please sign in to leave a comment.