LoFP LoFP / google workspace admin role privileges, may be modified by system administrators.

Techniques

Sample rules

Google Workspace User Granted Admin Privileges

Description

Detects when an Google Workspace user is granted admin privileges.

Detection logic

condition: selection
selection:
  eventName:
  - GRANT_DELEGATED_ADMIN_PRIVILEGES
  - GRANT_ADMIN_PRIVILEGE
  eventService: admin.googleapis.com