Question

How do I configure AD eDiscovery to collect from GMail?

 

Prerequisites

  • A Google G Suite Basic, Business, or Enterprise account for your organization
  • Administrator account credentials for your organization's G Suite account
  • Access to GMail from the Collections Work Manager machine
  • One of the following versions of Outlook installed on the Collections Work Manager machine:
    Outlook 2007 32-bit Standard & Professional
    Outlook 2010 32-bit Standard & Professional
    Outlook 2013 32-bit Professional Plus
    Outlook 2016 32-bit Professional Plus

 

Answer

  1. Login to the G Suite Admin Console at https://admin.google.com/AdminHome with your organization's G Suite Administrator account
  2. Click "Security"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876539/original/2017-05-18_16_31_54-Admin_console.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=32a2ba72fad4057b4d0d616c2691784c0a80ae7756e156776001dd56aa1ac599
  3. Click "API reference"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876540/original/2017-05-18_16_33_21-Admin_console.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=ea4a76df8c27fbefa73703dfa5f43f0245949186ade4a3d2e7656c52f93a31e1
  4. Check "Enable API access" and click "Save"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876541/original/2017-05-18_16_34_47-Admin_console.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=c4be77213f6190328c933303e51b44e8b1f16879fd3b9265a5e44d6bd992a442
  5. Open the Google API Console at https://code.google.com/apis/console/
  6. Expand the upper-left menu, then select "API Manager" and "Credentials"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876542/original/2017-05-18_16_47_09-Projects___Folders_Manager.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=6043a3e907595ee996f7e0433067bf62a441f2089a0894b7dfc33e1b599013ca
  7. When prompted to select or create a project, click "Create"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876543/original/2017-05-18_16_51_29-API_Manager.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=a5408d05e6351e6ac8e45f0032fdf25875e45ed27bf4732d657caca35c843b15
  8. Give your project a name and click "Create"
  9. When prompted, select "OAuth client ID" from the "Create credentials" drop-down
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876544/original/2017-05-18_16_53_03-Credentials_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=5832ed59c2e3b1c66af3008b1c22a6a2e1e744fd2da4a7b90c0ca8d69b8aca42
  10. Follow the prompts to Configure the OAuth consent screen and click "Save"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876545/original/2017-05-18_16_57_17-Consent_screen_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=6cc7af307a808dbdae90bf67f6c95cdf092b6dfe97d48a41322aa46842fb7d12
  11. For the Application Type, select "Other", give it a name, and click "Create"
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876546/original/2017-05-18_17_02_51-Create_client_ID_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=ed129e590d131aebbd35ade9f9df3d7f1aee05ed72b79bda7f52be5d6645fda9
  12. Take note of your Client ID and Client Secret
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876547/original/2017-05-18_17_03_37-Credentials_-_connectortest.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=56b60147346f11c7799e2e73f4ade728c21487a16226ebfd3e2a1a6d9da78250
  13. Log into eDiscovery and go to Data Sources > Gmail
  14. Click the Add button in the upper-right
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876548/original/2017-05-18_17_07_07-mRemoteNG_-_confCons.xml_-_eDisco_6.1.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=a38a7606ed684d434437a6e2f0c80768a55be3ee203226eedcff4baa5cc418c4
  15. Enter you Gmail Domain, Client ID, and Client Secret, and click the "Google" button
    https://s3.amazonaws.com/cdn.freshdesk.com/data/helpdesk/attachments/production/69009876549/original/2017-05-18_17_08_52-mRemoteNG_-_confCons.xml_-_eDisco_6.1.png?X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS6FNSMY2XLZULJPI%2F20210926%2Fus-east-1%2Fs3%2Faws4_request&X-Amz-Date=20210926T165732Z&X-Amz-Expires=300&X-Amz-SignedHeaders=host&X-Amz-Signature=8604c68529b00efa671ae722d9747ce8a753f56c22fefb0822a00bb3233aa18d
  16. In the resulting browser window, sign in with your organization's G Suite Administrator account
  17. When prompted, click "ALLOW" to allow the connector to audit emails of the users on your domain
  18. Copy the resulting Authorization Code, paste it into the connector details in eDiscovery, and click "OK"

 

Notes

  • GMail collections may spend a while "Waiting for Service" while eDiscovery waits for the collection request to be processed and packaged up by the queue on Google's end.