# Google Workspace integration - logs-sdk admin

**URL:** <https://discuss.elastic.co/t/google-workspace-integration-logs-sdk-admin/347257>\
**Category:** SIEM\
**Created:** [November 15, 2023, 8:41pm UTC](https://discuss.elastic.co/t/google-workspace-integration-logs-sdk-admin/347257 "2023-11-15T20:41:16Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Eldr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eldr/32/122166_2.png) [@Eldr](https://discuss.elastic.co/u/Eldr)\
**Post date:** [November 15, 2023, 8:41pm UTC](https://discuss.elastic.co/t/google-workspace-integration-logs-sdk-admin/347257/1 "2023-11-15T20:41:16Z")

</div>

I get this error despite following Elastic's documentation to the letter.  
this is the error (No authentication credentials were configured or detectec (ADC) accesing 'auth.oauth2')

 ![image (9)](https://us1.discourse-cdn.com/elastic/original/3X/7/5/75653f25e2dbef1620feb929e4fc896b19f8c72b.png)

Also, I don't understand what this point refers to in the documentation.

Requirements

In order to ingest data from the Google Reports API you must:

- Have an _administrator account_.
- [Set up a ServiceAccount]) using the administrator account.
- [Set up access to the Admin SDK API] for the ServiceAccount.
- [Enable Domain-Wide Delegation] for your ServiceAccount.

This integration will make use of the following _oauth2 scope_:

Once you have downloaded your service account credentials as a JSON file, you are ready to set up your integration.

**Click the Advanced option of Google Workspace Audit Reports. The default value of "API Host"** is googleapiscom`. The API Host will be used for collecting `access\_transparency`, `admin`, `device`, `context\_aware\_access`, `drive`, `gcp`, `groups`, `group\_enterprise`, `login`, `rules`, `saml`, `token`and`user accounts` logs.

Has anyone had the same thing happen to them?

---

<div class="post-metadata">

**Author:** ![jamie.hynds](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jamie.hynds/32/84205_2.png) [@jamie.hynds](https://discuss.elastic.co/u/jamie.hynds)\
**Post date:** [November 16, 2023, 12:23pm UTC](https://discuss.elastic.co/t/google-workspace-integration-logs-sdk-admin/347257/2 "2023-11-16T12:23:29Z")

</div>

Hi @Eldr - [this blog post](https://www.elastic.co/security-labs/google-workspace-attack-surface-part-two) goes into great detail on how to set up everything on the Workspace and integration side. I'd recommend going through it step by step, to ensure no steps were missed.

Also pinging @marc.guasch for guidance, as he may have seen the common causes for this error in the past.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2023, 12:24pm UTC](https://discuss.elastic.co/t/google-workspace-integration-logs-sdk-admin/347257/3 "2023-12-14T12:24:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
