Skip to content

Commit cb9960d

Browse files
authored
Merge pull request #146123 from memildin/asc-melvyn-containerwork
Tweaks to GCP connector description
2 parents 4fc2a35 + 5a0e228 commit cb9960d

File tree

1 file changed

+16
-7
lines changed

1 file changed

+16
-7
lines changed

articles/security-center/quickstart-onboard-gcp.md

Lines changed: 16 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -40,12 +40,16 @@ In the screenshot below you can see GCP projects displayed in Security Center's
4040

4141
## Connect your GCP account
4242

43-
Follow the steps below to create your GCP cloud connector. A connector connects your Google Cloud resources at the *organization* level. When you connect an organization, all projects within that organization are added to Security Center.
44-
4543
Create a connector for every organization you want to monitor from Security Center.
4644

47-
> [!TIP]
48-
> Learn about the Google Cloud resource hierarchy in their online docs [here](https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy).
45+
When connecting your GCP accounts to specific Azure subscriptions, consider the [Google Cloud resource hierarchy](https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy#resource-hierarchy-detail) and these guidelines:
46+
47+
- You can connect your GCP accounts to ASC in the *organization* level
48+
- You can connect multiple organizations to one Azure subscription
49+
- You can connect multiple organizations to multiple Azure subscriptions
50+
- When you connect an organization, all *projects* within that organization are added to Security Center
51+
52+
Follow the steps below to create your GCP cloud connector.
4953

5054
### Step 1. Set up GCP Security Command Center with Security Health Analytics
5155

@@ -62,7 +66,7 @@ When you first enable Security Health Analytics, it might take several hours for
6266

6367
### Step 2. Enable GCP Security Command Center API
6468

65-
1. From Google's **Cloud Console API Library**, select the project you want to connect to Azure Security Center.
69+
1. From Google's **Cloud Console API Library**, select each project in the organization you want to connect to Azure Security Center.
6670
1. In the API Library, find and select **Security Command Center API**.
6771
1. On the API's page, select **ENABLE**.
6872

@@ -71,7 +75,11 @@ Learn more about the [Security Command Center API](https://cloud.google.com/secu
7175

7276
### Step 3. Create a dedicated service account for the security configuration integration
7377

74-
1. In the **GCP Console**, select the project you want to connect to Security Center.
78+
1. In the **GCP Console**, select a project from the organization in which you're creating the required service account.
79+
80+
> [!NOTE]
81+
> When this service account is added at the organization level, it'll be used to access the data gathered by Security Command Center from all of the other enabled projects in the organization.
82+
7583
1. In the **Navigation menu**, Under **IAM & admin** options, select **Service accounts**.
7684
1. Select **CREATE SERVICE ACCOUNT**.
7785
1. Enter an account name, and select **Create**.
@@ -130,7 +138,7 @@ Yes. Security Center's GCP connector connects your Google Cloud resources at the
130138

131139
Create a connector for every GCP organization you want to monitor from Security Center. When you connect an organization, all projects within that organization are added to Security Center.
132140

133-
Learn about the Google Cloud resource hierarchy in Google's online docs [here](https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy).
141+
Learn about the Google Cloud resource hierarchy in [Google's online docs](https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy).
134142

135143

136144
### Is there an API for connecting my GCP resources to Security Center?
@@ -141,3 +149,4 @@ Yes. To create, edit, or delete Security Center cloud connectors with a REST API
141149
Connecting your GCP account is part of the multi-cloud experience available in Azure Security Center. For related information, see the following page:
142150

143151
- [Connect your AWS accounts to Azure Security Center](quickstart-onboard-aws.md)
152+
- [Google Cloud resource hierarchy](https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy)--Learn about the Google Cloud resource hierarchy in Google's online docs

0 commit comments

Comments
 (0)