Microsoft Defender for Cloud Apps
Cloud and workloads

Protect your Google Cloud Platform environment | Microsoft Defender for Cloud Apps

In brief

The Defender for Cloud Apps GCP protection page was refreshed with clearer descriptions, an updated section anchor, and more explicit setup instructions for the service account email, Organization ID, and JSON private key file.

What Defender admins need to know

Administrators configuring the GCP connector can follow more precise setup guidance; no configuration change is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

How Defender for Cloud Apps helps protect your Google Cloud Platform (GCP) environment

Google Cloud Platform (GCP) is an IaaSa cloud provider that enableslets your organization to host and manage their entire workloads in the cloud. Along with the benefits of leveraging infrastructure in the cloud, your organization's mostThe cloud offers many benefits, but it can also expose critical assets might be exposed to threats. ExposedThese assets include storage instances with potentially sensitive information,data, compute resources that operate some of your most critical applications,run key apps, ports, and virtual private networks that enable access to your organization.networks.

ConnectingWhen you connect GCP to Defender for Cloud Apps helpsApps, you can better secure your assets and detect potential threats by monitoring administrativethreats. The service monitors admin and sign-in activities, notifying on possibleactivities. It alerts you to brute force attacks, malicious usemisuse of a privileged user account,accounts, and unusual deletions of virtual machines (VMs).

Main threats to your GCP environment

Connecting GCP to Defender for Cloud Apps helps you detectfind and address the followingthese GCP threats:

  • Abuse of cloud resources
  • Compromised accounts and insider threats

Connect Google Cloud Platform to Microsoft Defender for Cloud Apps

The following instructions describe how to connect Microsoft Defender for Cloud Apps to your existing Google Cloud Platform (GCP) account using the connector APIs. This connectionThe connector gives you visibility into and control over GCP use. For information about how Defender for Cloud Apps protects GCP, see Protect GCP.

We recommend that you use a dedicated project for the Defender for Cloud Apps–GCP integration and restrict access to the project to maintain stable integration and prevent deletions/deletions or modifications of the setup process.

To create a service account and assign the required roles, perform the following steps:

  1. Create a dedicated service account.
  2. Copy the Email value, youvalue. You'll need thisthe service account email address later.
  3. Assign the Pub/Sub Admin role to the service account.
  4. Assign the Logs Configuration Writer role to the service account at the organization level.

Retrieve your Organization ID

Make a note of your Organization ID, you. You'll need thisthe Organization ID later. For more information, see Getting your organization ID.

Connect Google Cloud Platform auditing to Defender for Cloud Apps

  1. In the Enter details page, do the following, and then select Submit.

    1. In the Organization ID box, enter the organizationOrganization ID you made a note of earlier.saved previously.
    2. In the Private key file box, browse to the JSON private key file you downloaded earlier.when you created the service account key.

    :::image type="content" source="media/connect-gcp-app-audit.png" alt-text="Screenshot that shows where to enter the organization ID and private key file in the Defender portal." lightbox="media/connect-gcp-app-audit.png":::

  2. In the list of connectors, on the row in which the GCP connector appears, select Edit settings.

  3. In the Enter details page, do the following, and then select Submit.

    1. In the Organization ID box, enter the organizationOrganization ID you made a note of earlier.saved previously.
    2. In the Private key file box, browse to the JSON private key file you downloaded earlier.when you created the service account key.

    :::image type="content" source="media/connect-gcp-app-audit.png" alt-text="Screenshot that shows where to enter the organization ID and private key file in the Defender portal." lightbox="media/connect-gcp-app-audit.png":::