You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/cloud-infrastructure-entitlement-management/onboard-gcp.md
+21-19Lines changed: 21 additions & 19 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,24 +8,24 @@ ms.service: active-directory
8
8
ms.subservice: ciem
9
9
ms.workload: identity
10
10
ms.topic: how-to
11
-
ms.date: 06/16/2023
11
+
ms.date: 08/09/2023
12
12
ms.author: jfields
13
13
---
14
14
15
15
# Onboard a Google Cloud Platform (GCP) project
16
16
17
-
This article describes how to onboard a Google Cloud Platform (GCP) project on Permissions Management.
17
+
This article describes how to onboard a Google Cloud Platform (GCP) project in Microsoft Entra Permissions Management.
18
18
19
19
> [!NOTE]
20
20
> A *global administrator* or *super admin* (an admin for all authorization system types) can perform the tasks in this article after the global administrator has initially completed the steps provided in [Enable Permissions Management on your Azure Active Directory tenant](onboard-enable-tenant.md).
21
21
22
22
## Explanation
23
23
24
-
For GCP, permissions management is scoped to a *GCP project*. A GCP project is a logical collection of your resources in GCP, like a subscription in Azure, albeit with further configurations you can perform such as application registrations and OIDC configurations.
24
+
For GCP, Permissions Management is scoped to a *GCP project*. A GCP project is a logical collection of your resources in GCP, like a subscription in Azure, but with further configurations you can perform such as application registrations and OIDC configurations.
25
25
26
26
<!-- Diagram from Gargi-->
27
27
28
-
There are several moving parts across GCP and Azure, which are required to be configured before onboarding.
28
+
There are several moving parts across GCP and Azure, which should be configured before onboarding.
29
29
30
30
* An Azure AD OIDC App
31
31
* A Workload Identity in GCP
@@ -39,7 +39,7 @@ There are several moving parts across GCP and Azure, which are required to be co
39
39
40
40
- In the Permissions Management home page, select **Settings** (the gear icon), and then select the **Data Collectors** subtab.
41
41
42
-
1. On the **Data Collectors** tab, select **GCP**, and then select **Create Configuration**.
42
+
1. On the **Data Collectors** tab, select **GCP**, then select **Create Configuration**.
43
43
44
44
### 1. Create an Azure AD OIDC app.
45
45
@@ -50,7 +50,7 @@ There are several moving parts across GCP and Azure, which are required to be co
50
50
1. To create the app registration, copy the script and run it in your command-line app.
51
51
52
52
> [!NOTE]
53
-
> 1. To confirm that the app was created, open **App registrations** in Azure and, on the **All applications** tab, locate your app.
53
+
> 1. To confirm the app was created, open **App registrations** in Azure and, on the **All applications** tab, locate your app.
54
54
> 1. Select the app name to open the **Expose an API** page. The **Application ID URI** displayed in the **Overview** page is the *audience value* used while making an OIDC connection with your GCP account.
55
55
> 1. Return to the Permissions Management window, and in the **Permissions Management Onboarding - Azure AD OIDC App Creation**, select **Next**.
56
56
@@ -73,15 +73,15 @@ Choose from three options to manage GCP projects.
73
73
74
74
#### Option 1: Automatically manage
75
75
76
-
The automatically manage option allows projects to be automatically detected and monitored without extra configuration. Steps to detect list of projects and onboard for collection:
76
+
The automatically manage option allows you to automatically detect and monitor projects without extra configuration. Steps to detect a list of projects and onboard for collection:
77
77
78
-
1.Firstly, grant **Viewer** and **Security Reviewer**role to service account created in previous step at organization, folder or project scope.
78
+
1.Grant **Viewer** and **Security Reviewer**roles to a service account created in the previous step at a project, folder or organization level.
79
79
80
-
To enable controller mode 'On' for any projects, add following roles to the specific projects:
80
+
To enable Controller mode **On** for any projects, add these roles to the specific projects:
81
81
- Role Administrators
82
82
- Security Admin
83
83
84
-
2. Once done, the steps are listed in the screen, which shows how to further configure in the GPC console, or programmatically with the gCloud CLI.
84
+
The required commands to run in Google Cloud Shell are listed in the Manage Authorization screen for each scope of a project, folder or organization. This is also configured in the GPC console.
85
85
86
86
3. Select **Next**.
87
87
@@ -93,34 +93,36 @@ You have the ability to specify only certain GCP member projects to manage and m
93
93
94
94
2. You can choose to download and run the script at this point, or you can do it via Google Cloud Shell.
95
95
96
-
To enable controller mode 'On' for any projects, add following roles to the specific projects:
96
+
To enable controller mode 'On' for any projects, add these roles to the specific projects:
97
97
- Role Administrators
98
98
- Security Admin
99
99
100
100
3. Select **Next**.
101
101
102
102
#### Option 3: Select authorization systems
103
103
104
-
This option detects all projects that are accessible by the Cloud Infrastructure Entitlement Management application.
104
+
This option detects all projects accessible by the Cloud Infrastructure Entitlement Management application.
105
105
106
-
1. Firstly, grant Viewer and Security Reviewer role to service account created in previous step at organization, folder or project scope
106
+
1. Grant **Viewer** and **Security Reviewer** roles to a service account created in the previous step at a project, folder or organization level.
107
+
108
+
To enable Controller mode **On** for any projects, add these roles to the specific projects:
109
+
- Role Administrators
110
+
- Security Admin
111
+
112
+
The required commands to run in Google Cloud Shell are listed in the Manage Authorization screen for each scope of a project, folder or organization. This is also configured in the GPC console.
107
113
108
-
To enable controller mode 'On' for any projects, add following roles to the specific projects:
109
-
- Role Administrators
110
-
- Security Admin
111
-
2. Once done, the steps are listed in the screen to do configure manually in the GPC console, or programmatically with the gCloud CLI
112
114
3. Select **Next**.
113
115
114
116
115
117
### 3. Review and save.
116
118
117
119
- In the **Permissions Management Onboarding – Summary** page, review the information you've added, and then select **Verify Now & Save**.
118
120
119
-
The following message appears: **Successfully Created Configuration.**
121
+
The following message appears: **Successfully Created Configuration**.
120
122
121
123
On the **Data Collectors** tab, the **Recently Uploaded On** column displays **Collecting**. The **Recently Transformed On** column displays **Processing.**
122
124
123
-
You have now completed onboarding GCP, and Permissions Management has started collecting and processing your data.
125
+
You've completed onboarding GCP, and Permissions Management has started collecting and processing your data.
0 commit comments