October 9, 2020
Use new APIs to understand and audit group memberships
What’s changing
Who’s impacted
Why it’s important
- A security team can quickly identify all group memberships and associated nested memberships when a bad actor account is identified.
- An admin could perform a deep-dive on group structure for audit and compliance. By using the APIs to list and validate direct and indirect members for groups with many nested groups.
- A developer could extract group information via the API and feed it to a visualization tool that supports DOT format to make auditing and visualizing complex nested structures easier.
Additional details
Getting started
- Admins and developers: This is available to all users in beta. See our developer documentation for more details on the Cloud Identity Groups API and the Membership Hierarchy and Visibility API Guide.
- End users: End users can use the API within the scope they have to create and manage groups. See our developer documentation for more details on how to use the Cloud Identity Groups API.
Rollout pace
- This feature is available now for all users in beta.
Availability
- Available to Enterprise Standard, Enterprise Plus, Enterprise for Education, and Cloud Identity Premium customers
- Not available to Essentials, Business Starter, Business Standard, and Business Plus, as well as G Suite Basic, Business, Education, and Nonprofits customers