Google Workspace Admin Audit
| methodName | Description | Log type | Sample | Rule |
|---|---|---|---|---|
| any | Catch-all entry for admin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation. | activity | N | N |
| google. | Creates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings. | activity | N | Y |
| google. | Updates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings. | activity | N | Y |
any: admin.googleapis.com (any method)
#Description
Catch-all entry for admin.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.
google.admin.AdminService.inboundSsoProfileCreated: Inbound SSO profile created
#Description
Creates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
google.admin.AdminService.inboundSsoProfileUpdated: Inbound SSO profile updated
#Description
Updates an inbound SSO profile in the organization's Google Workspace or Cloud Identity settings.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #