Access Management for Google Groups in Native Tag Based Masking
Google Groups simplify access control in Google Cloud by allowing administrators to manage permissions for multiple users at once. In BigQuery's native tag-based masking, these groups define who can access sensitive data once associated with tag based masking.
Privacera supports access management for custom group.
This group must be created at the service side, and users must be added to it.
Access for this group can then be granted in BigQuery.
Info
For instructions on how to create a custom group in Google Cloud, refer to the link
Configuration Steps:
-
Open the vars.connector.bigquery.yml file located in the connector’s instance directory.
-
Add or update the following property:
-
Description: Identity name for native public groups in tag-based masking.
- Property:
CONNECTOR_BIGQUERY_NATIVE_PUBLIC_GROUP_MASKING_IDENTITY_NAME
-
Value for example:
connectorDev@googlegroups.com
Note
If this property is not set, the default value will be
null
. -
Save the file and update the privacera manager
-
In PrivaceraCloud, go to Settings -> Applications.
-
On the Applications screen, select BigQuery.
-
Enter the application Name and Description. Click Save. Name could be any name of your choice. E.g.
BigQuery Connector for account 123456
. -
Open the BigQuery application.
-
Enable the Access Management option with toggle button.
-
Under the ADVANCED tab, go to bottom in
Add New Custom Properties
Note
The values shown below are for example purposes only. Replace them with your actual configuration values.
Add new property
YAML -
Click SAVE.
-
The configured BigQuery connector appears under Applications.
-
Once saved and enabled, the BigQuery connector will start. Then you can hover on the VIEW LOGS button to check the status, either Running or Stopped.
Note
Text Only | |
---|---|
1 |
|
Restart The BigQuery Connector:
-
Go to Settings > Applications > select the BigQuery connector application .
-
Edit the application > Disable it > and Save it.
-
Open the same application again and then: Enable it and Save it.
- Prev topic: Advance Configuration