SailPoint IIQ App Onboarding Approach: CIEM for GCP and GCP Based apps

Hello All,

We are planning to onboard GCP based apps and CIEM for GCP to SailPoint IIQ 8.3P4.
I have observed some recommending using Webservices connector while some suggesting Google Suite (G Suite) Connector - what is the ideal approach to achieve provisioning and deprovisioning taking into considering both human and non human accounts?

Thanks

@pritishmhrn AFAIK I know GoogleSuite connector is designed for Google Workspace like gmail, drive, etc..not for GCP IAM Resource Management. You need to make separate API calls to GCP to manage this which would be outside the scope of GSuite Connector. You might want to go with Webservices connector only where you can configure endpoints as per your requirement which you’ll not get it in Google Apps connector.

Thank you! I will wait for a day to see if anyone else has different opinion and mark it as solution.

Use the Google Workspace (G Suite) connector.
why not web service connector: webb Services connector has no native GCP/IAM object model — you’d be manually building schema, REST calls to Cloud Resource Manager/IAM APIs, and OAuth/service-account auth that the Google Workspace connector already ships with. It’s only justified if you deliberately choose to bypass the OOTB connector , which is not the case here.

Do you agree with @neel193 's response?

You have posted a question in community, and we have given you our responses, It is you, who have to agree on responses. Which one is more likely a fit for your requirements.

Few observations:
SailPoint CIEM is the modern cloud-native capability documented for Identity Security Cloud (ISC). However, IdentityIQ also supports GCP cloud governance through its OOTB Google Workspace Connector, provided the applicable IIQ Cloud Governance or legacy CAM license is available.

Therefore:

  • IIQ without Cloud Governance/CAM: Use the Google Workspace Connector for Google Workspace users, groups, and roles.
  • IIQ with Cloud Governance/CAM: Use the same Google Workspace Connector to manage additional GCP objects, including service accounts, IAM roles, projects, folders, and resource permissions.
  • ISC: Use the modern SailPoint CIEM capability and its associated ISC integrations.