> For the complete documentation index, see [llms.txt](https://docs.guardware.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.guardware.com/documentation/insight/settings/cloud-monitoring.md).

# Cloud Monitoring

Cloud Monitoring monitors user activities within your organisation's Microsoft 365 and Google Workspace environments. These data are then analysed within GuardWare INSIGHT to provide dashboards, alerts, and reports on cloud usage and potential security incidents.

It monitors key cloud events such as:

* Files accessed or downloaded from sensitive libraries
* Access and download actions by anonymous, invited, or external users
* Files accessed via shared links
* Creation of anonymous links and external file access activities
* Cloud storage file access, download, and link creation activities
* Outgoing emails

## Set up Integrations

Microsoft 365 and Google Workspace must each be connected to the Management Console before Cloud Monitoring can be set up for that service. Only once a service is connected can its monitoring be enabled or disabled.

### Connect Microsoft 365

{% hint style="info" %}
Requires an Azure Global Administrator account.
{% endhint %}

1. Navigate to **ORGANISATION** > **Integrations** or from within **Cloud Monitoring** by clicking **Configure Integrations**.
2. Click **Connect Microsoft 365**. You'll be redirected to Microsoft's sign-in page.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2Fcgxi8yQfsYfLZGolvPYP%2Fimage.png?alt=media&amp;token=68dfac64-d8e7-4d2f-814b-a35e09b9de9e" alt="" width="563"><figcaption></figcaption></figure></div>
3. Select your Global Administrator account or click **Use another account** if it is not listed.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FIbZOIqhR4RTYns4K5WsL%2Fimage.png?alt=media&amp;token=90426c29-c0b9-4aa9-a7d3-60a895eefd96" alt="" width="480"><figcaption></figcaption></figure></div>
4. Enter your Global Administrator email address and password. Click **Next** and sign in.
5. If your account is protected by multi-factor authentication (MFA), you'll need to approve the sign-in request. This might involve:
   1. Approving a notification in the Microsoft Authenticator app.
   2. Entering the code from your authenticator app.
   3. Responding to a text message or phone call, depending on your MFA settings.<br>

      <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2F8G6i4hL3UJnsIHeWeuti%2Fimage.png?alt=media&amp;token=dc1e1437-260f-46ec-b722-a63c9939f5cc" alt="" width="480"><figcaption></figcaption></figure></div>
6. After authenticating, you'll see a permissions consent screen listing what DISCOVER is requesting access to. Select **Consent on behalf of your organisation** and click **Accept**.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FPk79dI4MWjy6kxhRaEGG%2Fimage.png?alt=media&amp;token=79c27547-a221-48ce-a141-8c4e80f9ebf1" alt="" width="563"><figcaption></figcaption></figure></div>
7. You'll be redirected back to the GuardWare Management Console, saying that the configuration was completed successfully.

### Connect Google Workspace

{% hint style="info" %}
Requires a Google Workspace administrator account, a security group with monitored users, and Google Service Account JSON credentials.
{% endhint %}

1. Navigate to **ORGANISATION** > **Google Workspace** or **INSIGHT >** **Cloud Monitoring** and click  **Add Google Workspace**.\
   ![](https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2Fps1KbSIOlRbZZZnkBcJK%2Fimage.png?alt=media\&token=2f81a166-489a-44e8-bee1-f425eca0a564)
2. In **Admin Email,** enter the Google Workspace admin email address that is used to create the JSON Key.
3. Enter the **Security Group**.
4. Enable **Gmail Monitoring** and **Google Drive Monitoring.**
5. Upload the [Google Service Account JSON](/documentation/management-console/integrations/google-workspace.md) credentials you generated while [setting up the Google Cloud Service Account](/documentation/management-console/integrations/google-workspace.md#set-up-a-google-cloud-service-account).
6. Click **Submit**.

<div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FJj9jT7F4O3xzy9qMuSVN%2Fimage.png?alt=media&amp;token=a27e7c89-81de-4b08-9704-8ca2a524579c" alt="" width="563"><figcaption></figcaption></figure></div>

## Configure Cloud Monitoring

Cloud Monitoring Settings controls monitoring for Microsoft 365 and Google Workspace services. Enable or disable monitoring per service, manage which users' activities are monitored and sync cloud data here.

### Configure Exchange Monitoring

Use this option to enable or disable monitoring of Microsoft Exchange activities.

1. Navigate to **INSIGHT > Cloud Monitoring**.
2. Toggle **Exchange Monitoring** to enable or disable Exchange monitoring.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2F2ustGUleELxQWg26Ubqi%2Fimage.png?alt=media&amp;token=4c56f963-2e7a-40cf-a60b-4920ee07910a" alt=""><figcaption></figcaption></figure></div>
3. Click **Save** to apply the configuration.

#### Add Users to Security Group

The Security Group identifies the Microsoft 365 security group used for Exchange monitoring and is displayed when Exchange Monitoring is enabled.

1. Click **Assign Users**.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FICDCrIk3kY8icMONJ40p%2Fimage.png?alt=media&amp;token=2c746e0c-d1da-4b43-92ea-15424996f02a" alt=""><figcaption></figcaption></figure></div>
2. Select the users to be included in the monitoring group.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2Fvd4ogmCZQcKwtCAq7gId%2Fimage.png?alt=media&amp;token=465785a4-8039-438f-b25b-aa4b124f92ae" alt="" width="563"><figcaption></figcaption></figure></div>
3. Click **Save** to assign the selected users, or click **Assign All Users** to assign all the listed users.

### Configure SharePoint Monitoring

Use this option to enable or disable monitoring of SharePoint activities.

1. Navigate to **INSIGHT > Cloud Monitoring**.
2. Toggle **SharePoint Monitoring** to enable or disable SharePoint monitoring.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FlL5PuMJiiLX1kWWu2oTB%2Fimage.png?alt=media&amp;token=66ffb6a7-cdbb-4f18-b6ee-3cee72d8f1d1" alt=""><figcaption></figcaption></figure></div>
3. Click **Save** to apply the configuration.

### Configure Gmail Monitoring

Use this option to enable or disable monitoring of Gmail activities.

1. Navigate to **INSIGHT > Cloud Monitoring**.
2. Toggle **Gmail Monitoring** to enable or disable Gmail monitoring.<br>

   <figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FxIEYDWDvJUgoM1LlhbNO%2Fimage.png?alt=media&amp;token=231e7d3b-1ea5-4bc8-9e67-39d191a369f1" alt=""><figcaption></figcaption></figure>
3. Click **Save** to apply the configuration.

#### Assign Users to Security Group

Use this option to assign the users whose Gmail activities are monitored.

1. Click **Assign Users**.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2F0PpNv5eVhIswnuSBt9P3%2Fimage.png?alt=media&amp;token=ef9bb496-bffc-4bb1-8a53-5e872bc1db19" alt=""><figcaption></figcaption></figure></div>
2. Select the users to be included in the monitoring group.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2Fvd4ogmCZQcKwtCAq7gId%2Fimage.png?alt=media&amp;token=465785a4-8039-438f-b25b-aa4b124f92ae" alt="" width="563"><figcaption></figcaption></figure></div>
3. Click **Save** to assign the selected users, or click **Assign All Users** to assign all the listed users.

### Configure Google Drive Monitoring

Use this option to enable or disable monitoring of Google Drive activities.

1. Navigate to **INSIGHT > Cloud Monitoring**.
2. Toggle **Google Drive Monitoring** to enable or disable Google Drive monitoring.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FPYpfHa6cX8UWE2cev1LZ%2Fimage.png?alt=media&amp;token=7a7d1689-dfc6-4206-9dc7-8b224a57685d" alt=""><figcaption></figcaption></figure></div>
3. Click **Save** to apply the configuration.

## Sync Cloud Monitoring

Manually refresh configuration and user information rather than waiting for the next scheduled sync.

1. Navigate to **INSIGHT** > **Cloud Monitoring.**
2. Click the **Sync** button to synchronise the latest configuration and user information from Microsoft 365.

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FwT31sdxkGtHXzWbSZLw9%2Fimage.png?alt=media&amp;token=2036403d-5ae0-4c11-a44f-92b736f2b61a" alt=""><figcaption></figcaption></figure></div>

The **Last Synced** field displays the date and time of the most recent successful synchronisation.

## Assign Data Type

Control which sensitive data types Cloud Monitoring monitors.

1. Click **+ Assign Data Type**.
2. Select the data types to monitor.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FIxi1p6ukbWuOOOxGLqMf%2Fimage.png?alt=media&amp;token=70575e09-e01a-48d6-b653-b923f759ed5d" alt="" width="563"><figcaption></figcaption></figure></div>
3. Filter data types by category, including **PCI**, **PII**, **SPI**, and **PHI**, if required.<br>

   <div align="left"><figure><img src="https://3625419753-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FrbF1elaBmiAnq9oEPmNP%2Fuploads%2FcWw8RwA4zcPI5O9m45yO%2Fimage.png?alt=media&amp;token=97a467c0-5dd1-40e2-a219-6a71d015f10b" alt="" width="563"><figcaption></figcaption></figure></div>
4. Click **Save** to apply the changes.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.guardware.com/documentation/insight/settings/cloud-monitoring.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
