Veritas Alta™ SaaS Protection Administrator's Guide
- Section I. Introduction to Veritas Alta™ SaaS Protection
- Section II. Administration portal
- Section III. Manage users and roles
- Section IV. Manage searches/eDiscovery/cases
- Section V. Configure policies
- Section VI. Perform restores
- About restore
- Prerequisites for restore
- Restore dashboard
- Restore Exchange Online mailboxes
- Restore SharePoint Online Sites and data
- Restore SharePoint/OneDrive/Teams Sites and data
- Restore Teams chats and Teams Channel conversations
- Restore Audit logs
- Restore Box data
- Restore Google Drive data
- Restore Gmail data
- Restore Salesforce data and Metadata
- Restore Entra ID objects
- Restore Slack data
- Restore data to File server
- Restore options
- Section VII. Perform data share
- Section VIII. Perform data downloading
- Section IX. Add and configure connectors
- About connectors
- About connectors
- Overview of connectors
- Configuring the capture scope
- Configuring credentials
- Apps Consent Grant Utility
- Exchange Online connector
- Adding Exchange Online connectors
- Configuring the capture scope for Exchange connectors
- Configuring the capture scope for Exchange connectors
- SharePoint Online connector
- Teams Sites collections connector
- OneDrive connector
- Teams chat connector
- Audit log connector
- Google Drive connector
- Gmail connector
- Salesforce connector
- Entra ID (Azure AD) connector
- Box connector
- Slack connector
- EML connector
- Managing connectors
- About connectors
- Section X. Perform backups
- Section XI. Backup limitations
- Section XII. Events
- Section XIII. Manage Stors (Storages)
- Section XIV. Manage Scopes
- Section XV. Manage auditing
- Section XVI. Known Issues
API permissions for Gmail and Google Drive
Veritas Alta SaaS Protection requires API permissions on the target Google Drive and Gmail environment to backup and restore its data:
Table:
API name | Requested scope | Used by Veritas Alta SaaS Protection: | Description by Google |
---|---|---|---|
API Access | Domain-wide delegation for Domain | To back up users' data from Google Drive and Gmail mailboxes. | Domain-wide delegation is a powerful feature that allows apps to access users' data across your organization's Google Workspace environment. For example, grant domain-wide delegation to a migration app that duplicates user content from another service to Google Workspace. For this reason, only super admins can manage domain-wide delegation, and they must specify each API scope that the app can access. |
Directory API | https://www.googleapis.com/auth/admin.directory.user.readonly | To enumerate the organization's users and discover users of Google Drives and Gmail mailboxes. | Scope for only retrieving users or user aliases. |
Drive API | https://www.googleapis.com/auth/admin.directory.group.member.readonly | To get the list of members/users present in the group to verify if the user is part of the group. If the Shared drive admin is in the group then using this scope you can get one of the users from the group and generate a token to backup the Shared drive. | Scope for only retrieving users/members presents in the group. |
Drive API | https://www.googleapis.com/auth/drive | To back up and restore Google Drive content. | View and manage all of your Drive files. |
Gmail API | https://www.googleapis.com/auth/gmail.readonly | To back up Gmail content. | Read all (Gmail) resources and their metadata. |
Gmail API | https://www.googleapis.com/auth/gmail.modify | To restore Gmail content. | All read/write operations except immediate, permanent deletion of threads and messages, bypassing Trash. |