Google Workspace Admin Audit

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for admin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNN
google.admin.AdminService.inboundSsoProfileCreatedCreates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings.activityNY
google.admin.AdminService.inboundSsoProfileUpdatedUpdates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings.activityNY

any: admin.googleapis.com (any method)

#
ServiceName
admin.googleapis.com

Description

Catch-all entry for admin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

google.admin.AdminService.inboundSsoProfileCreated: Inbound SSO profile created

#
ServiceName
admin.googleapis.com

Description

Creates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

google.admin.AdminService.inboundSsoProfileUpdated: Inbound SSO profile updated

#
ServiceName
admin.googleapis.com

Description

Updates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #