Create a Google Cloud user with minimal permissions for the dynamic attributes connector

Create a service account with minimum permissions to send dynamic attributes to Security Cloud Control.

This task sets up a service account that provides the minimum permissions necessary for the dynamic attributes connector. For a list of these attributes, see Google cloud connector user permissions and imported data.

Before you begin

You must already have set up your Google Cloud account. For more information about doing that, see Setting Up Your Environment in the Google Cloud documentation.

Procedure


Step 1

Log in to your Google Cloud account as a user with the owner role.

Step 2

Click IAM & Admin > Service Accounts > Create Service Account.

Step 3

Enter the following information:

  • Service account name: A name to identify this account; for example, CSDAC.

  • Service account ID: Should be populated with a unique value after you enter the service account name.

  • Service account description: Enter an optional description.

For more information about service accounts, see Understanding Service Accounts in the Google Cloud documentation.

Click Create and Continue.

Step 4

Follow the prompts on your screen until the Grant users access to this service account section is displayed.

Grant the user the Basic > Viewer role.

Click Done.

A list of service accounts is displayed.

Step 5

Click More (more icon) at the end of the row of the service account you created.

Step 6

Click Manage Keys.

Step 7

Click Add Key > Create New Key.

Create a new key for your user

Step 8

Click JSON.

Step 9

Click Create.

The JSON key is downloaded to your computer.

Keep the key handy when you configure the GCP connector.

See Create a google cloud connector.