Google Workspace | Dropzone AI Documentation

Integration Overview

The Dropzone AI platform integrates with Google Workspace APIs for ingesting alerts such as phishing reports and enriching investigations with data from Google Workspace such as directory information. This document describes how to set up API credentials and install them into the Dropzone platform.

To enable these integrations you will perform the following actions:

The Dropzone platform has a dedicated service account for your organization. This service account uses domain-wide delegation to gain access to specific API scopes within your organization.

Enable Domain-Wide Delegation

To grant access to the Google service account used by your Dropzone platform, do the following:

Next, enable the Dropzone AI application domain-wide delegation access to your Google Workspace environment.

As a full Google Workspace admin, do the following:

Choose or Create a Google Workspace Admin Account

Dropzone uses the Google Workspace Admin API to find information from your environment using a user within your org that has an Admin Role with necessary privileges.

The user you select could be a real human or a dedicated integration user. We suggest the latter to assure that personnel changes do not affect your integration. The integration user does not need a Google Workspace license, so it may be a free "Cloud Identity" user.

Note that Dropzone may request more permissions in the future as we add features.

Regardless of which privileges you enable for your admin role, the Dropzone platform is restricted to the scopes that you granted in the "Set Up Domain Wide Delegation" section above.

To create and associate the new role, do the following:

There are two sections of this user interface, the "Admin Console Privileges" at top and "Admin API Privileges" further down the page; make sure you configure all the permissions from both sections.

Enable Google Workspace

The Alert source integration allows Dropzone AI to pull alerts from Exchange Online and Microsoft Defender for investigation. Dropzone can investigate phishing emails via multiple mechanisms. An overview of them is shown below.

Method Notes Requirements Configuration
Google Workspace Phishing Alerts Dropzone processes Google Workspace phishing alerts. [Google phishing alerts may take up to 4 hours to appear](https://support.google.com/a/answer/9104586) after users click the "Report Phishing" button in Gmail) None - this is a built-in Google Workspace capability Leave "Enable mailbox-based phishing analysis" unchecked
Dedicated phishing mailbox Dropzone polls a dedicated Google Workspace account for phishing emails to analyze You must instruct your employees to forward suspected emails to a dedicated email box, or have a third-party reporting tool (typically a Gmail add-on) that creates the emails in the target mailbox Check "Enable mailbox-based phishing analysis" and fill out "Phishing Processing via Mailbox" section

To enable the Alert Source integration, you'll need the following information:

To enable the Alert Source integration, do the following:

If you wish to utilize Google Workspace Phishing Alerts, you do not need to perform any extra steps, and may proceed to inputting your desired poll interval and lookback. If you want to process phishing emails from a dedicated mailbox, do the following:

You should begin ingesting alerts immediately.

If you have any errors engage your Dropzone AI support representative.