> For the complete documentation index, see [llms.txt](https://help.datadefender.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.datadefender.io/getting-started/linking-google-workspace.md).

# Linking Google Workspace

Connecting your Google Drive environment to DataDefender enables automated inventorying, sensitive data discovery, and continuous classification across your organization’s files.

To ensure least privilege and maintain a keyless, zero-trust architecture, the onboarding process is split into two distinct steps:

1. Infrastructure & Workspace Setup: Deploying the required identity infrastructure in Google Cloud (GCP) and granting delegated API permissions in Google Workspace.
2. Platform Connection: Inputting your environment details into the DataDefender web application to establish and verify the active connection.

#### Integration Steps

Choose a step below to get started, or share these links directly with the team members responsible for each environment:

**Step 1: Configure GCP & Google Workspace**\
Primary Audience: GCP Project Admins / DevOps & Google Workspace Super Admins

Where It Happens: Terminal (`gcloud` / Terraform) & Google Workspace Admin Console (`admin.google.com`)

Deploy the underlying GCP identity infrastructure and configure Google Workspace permissions.&#x20;

This step:

* Provisions a keyless Workload Identity Pool and dedicated Service Accounts via Terraform.
* Authorizes Domain-Wide Delegation for required Drive and Directory scopes.
* Sets up isolated Impersonation Admin and Crawler user accounts.

👉 Go to Step 1: [GCP & Google Workspace Setup Guide](/getting-started/linking-google-workspace/connecting-google-workspace-to-datadefender.md)

**Step 2: Connect Google Drive in DataDefender**\
Primary Audience: DataDefender Administrators

Where It Happens: DataDefender Web Application (Settings -> Cloud Connectivity)

Finalize your tenant connection within the DataDefender platform.&#x20;

This step:

* Maps your Google Workspace Customer ID and service account credentials.
* Links your environment to an active AWS scanning account and region.
* Executes an automated handshake to verify keyless authentication and permissions.

👉 Go to Step 2: [DataDefender Connection Guide](/getting-started/linking-google-workspace/linking-google-drive-to-datadefender.md)

***

#### Frequently Asked Questions

Why does this setup require both GCP and Google Workspace?

> DataDefender uses Google Cloud's Workload Identity Federation (WIF) to authenticate keylessly without static secrets or long-lived passwords. The GCP project acts as the secure identity bridge, while Google Workspace holds the actual Drive data and Domain-Wide Delegation permissions.

Can one person complete both steps?

> Yes. If an individual has administrative access to your GCP project, Google Workspace Admin Console, and DataDefender, they can complete both steps sequentially in about 15 minutes.

What permissions does DataDefender require in our environment?

> DataDefender adheres to strict least-privilege principles. Access is limited strictly to Google Drive and Directory read/inventory scopes granted via Domain-Wide Delegation and constrained to a custom administrator role.
