If your organization uses Google Workspace, you can establish a secure integration with BreachBits to keep the list of emails used for credential threat testing and social engineering current. Before each BreachRisk Assessment, our Platform will use your Google Workspace integration to refresh the emails used by BreachBits.
Note: To set up your Google Workspace integration, you must be logged in with an account that holds Super Admin privileges for your Google Workspace. For more details, refer to Google’s documentation on Controlling API access with domain-wide delegation.
To establish the integration, you will need to register a client ID and assign OAuth permissions in your Google Workspace Admin Console. Follow the steps below to complete this configuration:
Go to admin.google.com.
In the Admin Console, select the Security section.
Note: If you don’t see Security as an option, click Show more at the bottom of the menu.
In the Security section, click Overview.
Scroll down the page and select API Controls.
Under the Domain-wide delegation area, click Manage Domain Wide Delegation.
Click the Add new button.
In the Client ID field, enter:
102753487502903440447
In the OAuth Scopes field, enter:
https://www.googleapis.com/auth/admin.directory.user.readonly
If you are using BreachBits for social engineering testing, also add the following OAuth Scope:
https://www.googleapis.com/auth/gmail.insert
Click Authorize to complete the process.
In your BreachRisk Portal, go to the Scope page at portal.breachrisk.co/app/v2/breachrisk/scope
Click the Add Email Integration button.
Select Google Workspace as your mail provider.
Add the email address of the Google Workspace Super Admin that performed steps 1-9. If you also added the second OAuthScope for social engineering testing, click the Email Whitelisting Configured checkbox.
Click Create Integration.
Your Google Workspace Integration is now complete. For more information about the OAuth Permissions required for the integration, visit the links below.
admin.directory.user.readonly: https://developers.google.com/identity/protocols/oauth2/scopes#admin-directory