Question

How do I configure AD eDiscovery to collect from Google Drive?

 

Prerequisites

  • A Google G Suite account for your organization
  • Administrator account credentials for your organization's G Suite account
  • The credentials to the Google Drive you wish to collect from

 

Answer

  1. Login to the G Suite Admin Console at https://admin.google.com/AdminHome with your organization's G Suite Administrator account
  2. Click "Security"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876517/original/2017-05-18_16_31_54-Admin_console.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=ab445d5daabd336575638dd1b3f27865c5578f3ee2828612e89b284816e2a079
  3. Click "API reference"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876518/original/2017-05-18_16_33_21-Admin_console.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=38e1c3b81405c00a56adfb56727fb98e6598f1d9da29674a56ae88fa9f837887
  4. Check "Enable API access" and click "Save"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876519/original/2017-05-18_16_34_47-Admin_console.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=4da0f7d5ee9a41bc84a32e663753b40847d9b0624aa744470a052413afcd26a0
  5. Open the Google API Console at https://code.google.com/apis/console/
  6. Expand the upper-left menu, then select "API Manager" and "Credentials"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876520/original/2017-05-18_16_47_09-Projects___Folders_Manager.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=542d76465f59384d8a5680b8df9bf6e696043a55281382b66f5a8a3d0b47ff14
  7. When prompted to select or create a project, click "Create"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876521/original/2017-05-18_16_51_29-API_Manager.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=fc7953d27d909fdca5395a53a56fe30eec65583eb1e62c7bd915894877acdb7d
  8. Give your project a name and click "Create"
  9. When prompted, select "OAuth client ID" from the "Create credentials" drop-down
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876522/original/2017-05-18_16_53_03-Credentials_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=de188267f9fdc8b55c6edaf1a62ac7c966478531c4e2ba8948eb368bc921d049
  10. Follow the prompts to Configure the OAuth consent screen and click "Save"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876523/original/2017-05-18_16_57_17-Consent_screen_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=50fd071d07f586b0d7530e5367d418a33918b0c87c053f87bfbf949324381cf7
  11. For the Application Type, select "Other", give it a name, and click "Create"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876524/original/2017-05-18_17_02_51-Create_client_ID_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=06e76b820813ff48952f6b4c8ba560cff8546b3775d81a007fd3f59508c0b7ee
  12. Take note of your Client ID and Client Secret
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876525/original/2017-05-18_17_03_37-Credentials_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=e9845a8f43dd6feda0496ce71648d0e140c06ee46d2cdc67cf95b23443f28207
  13. Log into eDiscovery and go to Data Sources > Gmail
  14. Click the Add button in the upper-right
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876526/original/2017-05-18_17_07_07-mRemoteNG_-_confCons.xml_-_eDisco_6.1.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=c1c5ab818d08639ed11281836dada1e8dbeac4010f9d28a2787a72d5ed87fa03
  15. Give the connector a Name
  16. Enter you Client ID and Client Secret, and click the "Google" button
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876527/original/2017-06-16_12_53_57-mRemoteNG_-_confCons.xml_-_APSEDB.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165720Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=362efbc2309a6fe709f99de18d8532b972c3df7a274c1b2ce88bc228e1f10083
  17. In the resulting browser window, sign in with the credentials to the Google Drive you wish to collect from
  18. When prompted, click "ALLOW" to allow the connector to audit emails of the users on your domain
  19. Copy the resulting Authorization Code, paste it into the connector details in eDiscovery, and click "OK"

 

Notes

  • Separate Google Drive connectors are required for each user's Drive you wish to collect from.