Skip to content
SecPod  – Documentation
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
Search this website
Menu Close
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO

Saner Platform

  • Saner Platform Release Notes
    • Saner Platform Integration Release: ServiceNow Integration Introduced, Freshservice Enhanced
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
  • Saner Platform Guide
    • Saner Administration Guide
    • Saner Device Management User Guide
    • Saner Platform and ServiceNow Integration Guide
    • Saner Platform and Freshservice Integration Guide
    • Saner Platform Function Guides
  • FAQs
    • Saner CVEM Technical FAQs
  • How Tos
    • General
      • How to increase the subscription count for an Account in Saner CVEM
      • How to increment license count for an Organization in Saner CVEM
      • How to provision Saner tools for an Organization
      • How to change subscription type in Saner CVEM
      • How to sign-up with Saner CVEM?
      • How to create a new account in Saner CVEM?
      • How to enable SSO authentication policy in Saner CVEM?
      • How to set alerts in Saner?
      • How to view, download and filter the audit logs?
      • How to designate Saner Agent to perform network scan?
      • How to Co-Brand with your logo?
      • How to fetch the details of the mandatory fields from the Okta account?
      • How to create MFA policy for Okta?
      • How to fetch the details of the mandatory fields from the PingID account?
      • How to create MFA policy for PingID?
      • How to fetch the details of the mandatory fields from the PingOne account?
      • How to create MFA policy for PingOne?
      • How to download and install Saner Agent in Mac?
      • How to download and install Saner agent in Linux?
      • How to download and install the Saner agent in Windows?
      • How to update the expiry date of an existing subscription?
      • How to manage users and their preferences using role-based access?
      • How to uninstall Saner Agent using Saner Offline deployer tool.
      • How to onboard a new organization?
      • How to deploy Saner Agent using Saner Offline deployer tool.
      • How to install a Saner agent through the command line?
      • How to uninstall the Saner agent through command line?
    • Saner Reports
      • How to configure mail settings to email Report PDF?
      • How to create a custom report in Saner?
      • How to schedule for the report back up?
    • Saner Device Management
      • How to create custom groups in Saner CVEM
    • Saner Mail Settings
      • How to create new mail settings in Saner?
      • How to use OAuth-enabled authentication in Saner mail settings
      • How to create OAuth Client ID and Client Secret for Gmail
      • How to create OAuth Client ID and Client Secret for Microsoft 365.
  • Supported OSs and Platforms
    • Operating Systems and Platforms Supported
    • Supported Third-party Applications for Patching

Saner Cloud

  • Before You Begin
    • Glossary of Terms
    • Read me First
  • Get Started
    • Prerequisites For Saner SaaS Platform Deployment
    • Saner Cloud Deployment Guides
      • Onboarding a GCP Organization to Saner Cloud(CLI)
      • Onboarding a GCP Project to Saner Cloud (CLI)
      • Onboarding a GCP Organization to Saner Cloud(Manual)
      • Onboarding a GCP Project to Saner Cloud(Manual)
      • Azure Onboarding
      • Troubleshooting
      • Get Started with Saner CNAPP AWS Cloud Deployment V1.0
      • Onboarding with AWS Credentials(Least Recommended Method)
      • Onboarding with AWS Role(Manual)
      • Onboarding with AWS Role CloudFormation (Automatic): Recommended
    • Roles and Permissions
      • Roles and Permissions for AWS Remediation Access
      • Roles and Permissions for Azure Onboarding, Detection, and Remediation
  • Learn About
    • Critical Events to Monitor in GCP
    • Saner CSRP Classification Based on Scoring Decision
    • Cloud Cyber Hygiene Scoring(CCHS) Approach
    • Remediation Rollback
    • Automation and Job-driven Remediation
    • Cost and Usage
    • Excessive Permission Categories Evaluated Across Different Cloud Services
    • Publicly Accessible Resources
    • Patch Aging and Patch Impact
    • SecPod Default Benchmarks
    • Watchlists
    • Cloud Workload Protection Platform(CWPP)
    • Overview of Report Views in Saner Cloud
    • Whitelisting Resources
    • Saner Plasma AI Assistant for Seamless User Interaction
    • Critical Events to Monitor in AWS
    • High-Privilege Actions in Critical Activity Logs for AWS
    • Audit Logs in Saner Cloud
    • Excessive Permissions
    • Alerts in SanerCloud
  • User Guides
    • GCP Cloud Infrastructure Entitlement Management (CIEM) User Guide
    • Azure Cloud Infrastructure Entitlement Management(CIEM) User Guide
    • Cloud Security Risk Prioritization(CSRP) User guide
    • Cloud Cyber Hygiene Score(CCHS) User Guide
    • Cloud Security Remediation Management(CSRM) User Guide
    • AWS Cloud Infrastructure Entitlement Management(CIEM) User Guide
    • Cloud Security Posture Anomaly(CSPA) User Guide
    • Cloud Security Asset Exposure(CSAE) User Guide
    • Cloud Security Posture Management(CSPM) User Guide
  • Tell Me How
    • How to Remediate in Saner Cloud?
    • How to Configure Automation Rule to Remediate Misconfigurations?
    • How to Manage Report Views at Organization-level in Saner Cloud?
    • How to Get a Cohesive View from Saner Cloud Unified Dashboard?
    • How to Use Tags to Quickly Filter Resources?
    • How to Troubleshoot Issues with Audit Logs?
    • How to Manage Groups and Tags in Saner Cloud?
    • How to Manage Report Views for a User Account in Saner Cloud?
    • How to Troubleshoot or Analyze with Critical Activity Logs?
    • How to Setup Alerts Across SanerCloud Tools?
    • How to Take Action on Alert Notifications from SanerCloud?
    • CCHS
      • How to Monitor Resource Risk Trends for CHS?
      • How to Assess Resource Health through Severity Distribution?
      • How to Evaluate Service-Level Risks Using CHS Scores?
      • How to Analyze Cyber Hygiene Scores through Trend Chart?
      • How to Identify High-Risk Resources by Geo Location?
      • How to Get an Overview of Cyber Hygiene for Cloud Resources?
      • How to Review Organization-Level Cyber Hygiene Across Accounts?
      • How to Assess Risk Distribution for Different Cloud Providers?
      • How to Review Major Issues Contributing to the Drop of Cyber Hygiene Score at Account-Level?
      • How to Analyze Module-wise Risk through CHS Distribution?
      • How to View the Cyber Hygiene Score Distributed Across Cloud Environments?
      • How to Track Security Posture with Cyber Hygiene Score?
      • How to Configure Account Weightage?
    • CSRP
      • How to Monitor and Analyze Audit Logs for Risk Prioritization?
      • How to Configure Risk Based Cloud Security Alerts?
      • How to Generate Reports and Visualizations?
      • How to Filter Risks by Tags for Targeted Analysis?
      • How to Manage Prioritized Risks at Account-level?
      • How to View the Detailed Breakdown of a Specific Cloud Cyber Security Standard (CCSS) Risk Finding?
      • How to Review and Prioritize Resources Based on Associated Risks?
      • How to Assess Risk Distribution on Essential Resources?
      • How to Assess and Prioritize Risks Across Resource Categories?
      • How to Identify the Risks Affecting Essential Resources?
      • How to Assess Full Versus Limited Technical Impact of Exploiting an Anomaly?
      • How to Review the Risk Factor Distribution Based on Automatable Reliability?
      • How to Get an Overview of Exploitable Risks?
      • How to Map Risks to MITRE ATT&CK for Threat-Informed Defense?
      • How to Configure Questionnaire and Assess Security Practices Across Core Domains for an Account?
    • CSAE
      • How to Setup Watchlist Configuration for a Resource?
      • How to Identify Outdated Resources for Cleanup?
      • How does Resource Categorization Work in Saner CSAE?
      • How to Identify Resources Exposed to External Network?
      • How to Understand the Resource Footprint Globally Across Various Regions?
      • How to Make Informed Decisions on Your Expenditure based on Resource Usage Graph?
    • CSPM
      • How to Setup Benchmarks in Saner CSPM?
      • How to Use Quick Evaluation Benchmarks?
      • How to Detect Patterns over a Period with Resource Trends?
      • How to Assess System Compliance and Security Posture?
    • CSPA
      • How to Initiate Patch Remediation from CSPA Dashboard?
      • How to Quickly Identify the Detected and Remediated Anomalies for an Account?
      • How to Prioritize Remediation or Fixes based on Confidence Levels?
      • How to Examine the Overall Anomaly Information for Specific Rules or Checks?
      • How to Search and Retrieve Anomaly Data?
      • How to Whitelist Rules or Resources in Cloud Security Scans?
    • CIEM
      • How to See the Active Version for an IAM Policy?
      • How to Address Critical Activities Using Evidence?
      • How to View by Type and Usage for any Identity in CIEM?
      • How to Get Visibility into Cloud Entitlements?
      • How to Use Evidence to Address Policies with Excessive Permission?
      • How to Know the Excessive Permissions on a Specific Service?
      • How to Visually See the Relationship between Identity, Entitlement, Policy, or Permission?
      • How to Determine if a Policy has Excessive Permission?
      • How to Initiate Remediation for Different Identities from CIEM?
    • CSRM
      • Rollback an Applied Remediation
      • How to Configure Automation Rule to Remediate Misconfigurations?
      • How to Create a Patching Task for Items Currently in “Approval Pending” State?
      • How to Evaluate Remediation Effort with Patching Impact Chart?
      • How to Prioritize and Address Older or High-Risk Anomalies with Patch Aging?
      • How to Monitor the Overall Status of the Remediation Job?
      • How do I Get to Know the Regions Impacted by a Specific Rule?
      • How to View the Severity of a Missing Patch Affected by a Rule?
      • How to Address Missing Patches Via Remediation Tasks?
      • How to Quickly Access the Necessary Tool for Remediation and Begin Patching Tasks?
  • Frequently Asked Questions
    • Saner Cloud Technical FAQs
  • Saner Cloud Release Notes
    • Saner Cloud – V.3.0.1.0 Release Notes
    • Saner Cloud – V.3.0.0.0 Release Notes
    • Saner Cloud – V.2.0.0.2 Release Notes
    • Saner Cloud – V.2.0.0.1 Release Notes
    • Saner Cloud – V.2.0.0.0 Release Notes
    • Saner Cloud – V.1.2.0.1 Release Notes
    • Saner Cloud – V.1.2.0.0 Release Notes
    • Saner Cloud – V.1.1.0.0 Release Notes
    • Saner Cloud – V.1.1 Release Notes
    • Saner Cloud – V.1.0 Release Notes

Saner CVEM

  • Saner CVEM Release Notes
    • Release Notes Saner CVEM 6.6
    • Release Notes Saner 6.5
    • Saner Platform Integration Release: ServiceNow Integration Introduced, Freshservice Enhanced
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • SanerNow Risk Prioritization Launch
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
    • Saner CVEM
      • Release Notes Saner CVEM 6.6
  • Saner CVEM Guide
    • Prerequisites For Saner SaaS Platform Deployment
    • What’s New in Saner CVEM?
    • Getting Started with Saner CVEM
    • Pre-requisites for Saner CVEM Deployment
    • How does Saner CVEM’s deployment architecture work?
  • Saner CVEM Products
    • Overview of Saner Continuous Vulnerability and Exposure Management
    • Saner CVEM Unified Dashboard User Guide
    • Saner CVEM Asset Exposure User Guide
    • Saner CVEM Continuous Posture Anomaly Management User Guide
    • Data Points IT teams can Fetch from Saner CPAM
    • Posture Anomaly Computation Rules
    • Saner CVEM Vulnerability Management User Guide
    • Saner CVEM Compliance Management User Guide
    • Saner CVEM Risk Prioritization User Guide
    • Saner CVEM Patch Management User Guide
    • Saner CVEM Endpoint Management User Guide
    • Saner CVEM Remote Scripting User Guide
    • Saner CVEM Remote Access User Guide
    • Saner CVEM Network Scanner User Guide
    • Saner CVEM Cyber Hygiene Score User Guide
  • How Tos
    • Saner AE
      • How to blacklist and whitelist applications in Saner AE?
      • How to manage asset licenses using Saner AE?
      • How to run an asset scan using Saner AE?
    • Saner CPAM
      • How to create new response in PA tool?
      • How to build your own detection and response in PA tool?
      • How to whitelist an entire PA ID?
      • How to configure Posture Anomaly tool for custom detection?
      • How to fix Anomalies from PA dashboard?
      • How to fix anomalies detected in your account from All Anomalies Page?
      • How to fix anomalies from PA Summary page?
      • How to delete PA scan preferences?
      • How to schedule PA Scans on Daily, Weekly, and Monthly basis?
      • How to launch Posture Anomaly scans?
    • Saner VM
      • How to automate and schedule vulnerability scans?
      • How to exclude vulnerabilities in Saner VM tool
      • How to manage excluded vulnerabilities in Saner VM?
      • How to remediate vulnerabilities from vulnerability management dashboard?
    • Saner CM
      • How to run a compliance scan?
      • How to custom create a security policy?
      • How to align with PCI security compliance management?
      • How to align with NIST 800-171 security compliance management?
      • How to align with NIST 800-53 security compliance management?
      • How to align with HIPAA security compliance management using Saner CM?
    • Saner PM
      • How to fix firmware in Saner?
      • How to exclude patches in Saner PM?
      • How to manage excluded patches in Saner PM?
      • How to automate patch management in Saner PM?
      • How to roll back patches in Saner PM?
      • How to apply missing patches in Saner PM?
      • How to apply the most critical patches in Saner PM?
      • How to perform custom remediation for applications that require paid patches using Saner PM
      • How to check the status of patching activity?
    • Saner EM
      • How to collect all security events from Windows Events Log?
      • How to check password policy set in Windows systems?
      • How to check status of DEP in Windows systems?
      • How to check faulty Anti-Virus (AV) status in Windows systems?
      • How to check for Anti-Virus (AV) status in Windows systems?
      • How to check account lockout policy on Windows systems?
      • How to check if Bit-locker protection is OFF in Windows systems?
      • How to list all inactive users on Windows systems?
      • How to list all guest accounts in Windows systems?
      • How to list all Administrator accounts on Windows systems?
      • How to list last-logon details of users on Windows systems?
      • How to identify all users in Windows systems?
      • How to collect all services that are currently running in Windows systems?
      • How to list all Groups in Windows systems?
      • How to collect all keyboard and pointing devices connected to Windows systems?
      • How to collect all storage devices connected to Windows systems?
      • How to investigate total RAM or CPU threshold (greater than or equal to 80%) in Windows systems?
      • How to collect operating systems information in Windows?
      • How to investigate disks running out of space (<100 MB) in Windows systems?
      • How to collect and investigate disk information on Windows systems?
      • How to collect all installed patches in Windows systems?
      • How to collect all software patches that are hidden in the Windows Update server?
      • How to check the status of Windows Update Server (WSUS/SCCM)?
      • How to collect BIOS information such as serial number, version, manufacturer in Windows systems?
      • How to collect all the important missing patches in Windows systems?
      • How to check wireless security in Linux systems?
      • How to collect mounted disk information on Linux systems?
      • How to check wireless signal quality in Linux systems?
      • How to check all firewall policies on Linux systems?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Linux systems?
      • How to collect DNS information on Linux systems?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing in Linux?
      • How to check wireless signal quality in Windows systems?
      • How to check wireless security in Windows systems?
      • How to collect all open ports in Windows systems?
      • How to collect all network interfaces in Windows systems?
      • How to investigate DNS cache on Windows systems?
      • How to check all firewall policies on Windows systems?
      • How to collect DNS information on Windows systems?
      • How to collect all the applications with an unknown publisher in Linux systems?
      • How to perform system tuning?
      • How to collect all software licenses in Windows systems?
      • How to identify potentially unwanted programs such as torrent downloaders or unnecessary toolbars running on Windows systems?
      • How to collect a list of applications that are started when you boot your computer?
      • How to collect all the applications with an unknown publisher in Windows systems?
      • How to collect all software licenses in Mac systems?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing Windows?
      • How to collect all families of operating systems such as Windows, Unix, and macOS?
      • How to collect environment variables set in all operating systems?
      • How to collect all the applications with an unknown publisher in Mac systems?
      • How to delete and quarantine a file?
      • How to start and stop the processes in Saner?
      • How to block blacklisted applications in Saner?
      • How to enable/disable devices in Saner
      • How to manually import devices into Saner?
      • How to deploy software in Saner EM?
      • How to enable and disable firewall settings in Saner AE?
      • How to collect all shared resources on Windows systems?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Windows systems?
      • How to connect to a client machine graphically using Saner Remote Access
  • FAQs
    • Saner CVEM Technical FAQs

Security Intelligence for Saner CVEM

  • Overview of Security Content and Intelligence
  • Security Content Statistics
  • OVAL Definitions Platform Coverage
  • OVAL Definitions Class-wise Distribution
  • OVAL Definitions Family-wise Distribution
  • Application and OS Remediation Coverage
  • Compliance Benchmark Coverage
  • List of Vulnerability to Exploit/Malware Mapping covered in Saner
  • Network Scanner Product Support Matrix
  • Privilege levels for authenticated scans using Saner Network Scanner

Security Intelligence for Saner Cloud

  • Benchmark Compliance Rules in AWS, Azure, and GCP
    • GCP
      • SecPod Rules in GCP
        • SecPod Default Rules in GCP: An Overview
        • Understand SecPod Default Rules in GCP
        • Understand SecPod Global Rules in GCP
        • Understand SecPod Regional Rules in GCP
      • CIS Rules in GCP
        • CIS Benchmark Compliance Rules in GCP: An Overview
        • Understand CIS 4.0.0 Rules in GCP
        • Understand CIS 4.0.0 Global Rules in GCP
        • Understand CIS 4.0.0 Regional Rules in GCP
    • AWS
      • SecPod Rules in AWS
        • SecPod Default Rules in AWS: An Overview
        • Understand SecPod Default Rules in AWS
        • Understand SecPod Global Rules in AWS
        • Understand SecPod Regional Rules in AWS
      • PCI DSS 3.2.1 Rules in AWS
        • PCI DSS 3.2.1 Rules in AWS: An Overview
        • Understand PCI DSS 3.2.1 Rules in AWS
        • Understand PCI DSS 3.2.1 Global Rules in AWS
        • Understand PCI DSS 3.2. 1 Regional in AWS
      • CIS Rules in AWS
        • CIS Rules in AWS: An Overview
        • Understand CIS Rules in AWS
        • Understand CIS 3.0.0 Rules in AWS
        • Understand CIS 4.0.1 Rules in AWS
        • Understand CIS 4.0.0 Rules in AWS
        • Understand CIS 3.0.0 Global Rules in AWS
        • Understand CIS 4.0.0 Global Rules in AWS
        • Understand CIS 3.0.0 Regional Rules in AWS
        • Understand CIS 4.0.0 Regional Rules in AWS
      • SOC 2 Rules in AWS
        • SOC 2 Rules in AWS: An Overview
        • Understand SOC 2 Rules in AWS
        • Understand SOC 2 Global Rules in AWS
        • Understand SOC 2 Regional Rules in AWS
      • HIPAA HITRUST Rules in AWS
        • HIPAA HITRUST Rules in AWS: An Overview
        • Understand HIPAA HITRUST Rules in AWS
        • Understand HIPAA HITRUST Global Rules in AWS
        • Understand HIPAA HITRRUST Regional Rules in AWS
      • NIST 800-53 Revision 5 Rules in AWS
        • NIST 800-53 Revision 5 Rules in AWS: An Overview
        • Understand NIST 800-53 Revision 5 Rules in AWS
        • Understand NIST 800-53 Revision 5 Global Rules in AWS
        • Understand NIST 800-53 Revision 5 Regional Rules in AWS
    • Azure
      • CIS Rules in Azure
        • CIS Rules in Azure: An Overview
        • Understand CIS 1.2.0 Rules in Azure
        • Understand CIS 2.1.0 Rules in Azure
        • Understand CIS 1.1.0 Benchmark Compliance Rules in Azure
        • Understand CIS 3.0.0 Benchmark Compliance Rules in Azure
        • Understand CIS 1.2.0 Global Benchmark Compliance Rules in Azure
        • Understand CIS 2.1.0 Global Benchmark Compliance Rules in Azure
        • Understand CIS 3.0.0 Global Benchmark Compliance Rules in Azure
        • Understand CIS 2.1.0 Regional Benchmark Compliance Rules in Azure
        • Understand CIS 3.0.0 Regional Benchmark Compliance Rules in Azure
      • NIST 800-53 Revision Rules in Azure
        • NIST 800-53 Revision 5 Rules in Azure: An Overview
        • Understand NIST 800-53 Revision 5 Rules in Azure
        • Understand NIST 800-53 Revision 5 Global Rules in Azure
        • Understand NIST 800-53 Revision 5 Regional Rules in Azure
      • SecPod Rules in Azure
        • SecPod Default Rules in Azure: An Overview
        • Understand SecPod Global Rules in Azure
        • Understand SecPod Regional Rules in Azure
        • Understand SecPod Default Rules in Azure
      • HIPAA HITRUST Rules in Azure
        • HIPAA HITRUST Rules in Azure: An Overview
        • Understand HIPAA HITRUST 14.7.0 Rules in Azure
        • Understand HIPAA HITRUST 14.7.0 Global Rules in Azure
        • Understand HIPAA HITRUST 14.7.0 Regional Rules in Azure
      • PCI DSS Rules in Azure
        • PCI DSS 3.2.1 Rules in Azure: An Overview
        • Understand PCI DSS 4.0 Rules in Azure
        • Understand PCI DSS 4.0 Global Rules in Azure
        • Understand PCI DSS 4.0 Regional Rules in Azure
      • SOC 2 Rules in Azure
        • SOC 2 Rules in Azure: An Overview
        • Understand SOC2 Rules in Azure
        • Understand SOC2 Global Rules in Azure
        • Understand SOC2 Regional Rules in Azure
  • Posture Anomaly Checks in AWS and Azure
    • Implementing Posture Anomaly Checks in AWS
    • Implementing Posture Anomaly Checks in Azure
  • Infrastructure Entitlement Checks in AWS, Azure, and GCP
    • Implementing Infrastructure Entitlement Checks in AWS
    • Implementing Infrastructure Entitlement Checks in Azure
    • Implementing Infrastructure Entitlement Checks in GCP
View Categories
  • Home
  • Docs
  • Saner Cloud
  • Get Started
  • Saner Cloud Deployment Guides
  • Onboarding a GCP Project to Saner Cloud(Manual)

Onboarding a GCP Project to Saner Cloud(Manual)

Print Friendly, PDF & Email

Pre-requisites

Users can onboard one or multiple projects from Google Cloud Platform to a single Saner Cloud GCP account, provided all projects are linked to an active billing account. The onboarding process creates a GCP Service Account in one primary project, where the user must have Editor, Project IAM Admin, and Role Administrator privileges. For additional projects, Project IAM Admin and Role Administrator privileges are required. The user must also have Super Admin access to the Google Workspace Admin Console.

Note: Make sure that the project where the Service Account gets created has lesser than 100 existing Service Accounts. Google Cloud Platform enforces a maximum limit of 100 Service Accounts per project, and the onboarding process will fail if this limit is exceeded.

Create a New Account in Saner Cloud

Step1: In the Control Panel, open the All Organizations drop-down menu and select the organization for which you want to create the new account.

Step2: To create a new account, click the New Account button on the top-right of the page.

Step3: Complete all the details required to create the New Account.

  • Provide the name of the cloud account
  • Key in a valid email address
  • Choose the account type “Cloud infrastructure” from the drop-down list
  • Choose the cloud provider as “GCP” from the drop-down list
  • Turn on the slider to provision the relevant tool for the account

Step4: Click the Create button.

The newly created account displays in the Accounts page within a tabular format with the following details:

  • Account Name
  • Email ID
  • Account Type
  • Subscription
  • Expiry Date
  • Action

Note: In the Action column, you have the facility to set up the mail settings for the corresponding account, edit the current account details, delete the account, and redirect to the dashboard view of this account.

Integrate Your GCP Account with Saner Cloud Security

Saner Cloud Security (CNAPP) provides a streamlined process to integrate your Google Cloud Platform account for continuous visibility, monitoring, and security posture assessment. You can connect your GCP account using either an automated or manual approach, depending on your organization’s security and operational requirements.

The following section outlines the platform setup steps and the available integration methods.

Setup

Step1: Login to Saner Cloud Security platform.

Step2: Click on “Control Panel” and select the account that you have created following the steps in prerequisites.

Available Integration Methods

There are two ways to connect your GCP account with Saner Cloud Security listed in order of recommendation.

Method 1: GCP CLI – Recommended

  • Fastest and most secure method
  • Automatically sets up all required permissions
  • Minimal manual configuration needed

Method 2: Manual

  • Requires manual setup of permissions
  • Good for organizations requiring in-depth visibility of the onboarding process

Steps to Use the Manual Method

Step1: Under Saner Cloud Security, click on “Onboard & Scan”.

Step2: Select “Manual” as shown in the following image and select “GCP Project Onboarding”.

Enable Required GCP APIs for Project Integration

To ensure all required GCP Cloud APIs are enabled for your project, you can enable APIs as described in the following steps:

Step3: Log into your GCP account.

Step4: Login to Google Cloud Console, select the project that you want to use for creation of Service Account and onboarding.

Click here to view which APIs are required to be enabled for onboarding.

Navigate to “Enabled APIs and services” under “APIs and Services” to cross check.

Step5: To enable an API, go to “Library” under “APIs and Services,” search for the API, and click “Enable”. 

Create and Configure a Custom IAM Role for Saner Cloud Security

Follow the steps below to create the required custom IAM role in your Google Cloud Platform project.

Step6: Click here to view the list of permissions that must be added to the custom role. Switch to the Project View (to the project under which you want to create the Service Account), navigate to “Roles” under “IAM and Admin” and click on “Create role”.

Step7:

1. Enter the “Title” with “Saner_CNAPP_Remediation_Role” as Prefix (e.g. Saner_CNAPP_Remediation_Role_xxxx_xxxx)

2. Enter the “ID” with “Saner_CNAPP_Remediation_Role” as prefix (e.g. Saner_CNAPP_Remediation_Role_xxxx_xxxx)

3. Click on “Add permissions”, and in the Filter Section, copy and paste each of the permission and click on “Add”.

4. After adding all permissions, click “Create” to complete the custom role creation.

IMPORTANT:

For onboarding multiple projects, create identical custom role in all other projects that you wish to onboard to Saner Cloud Security:

For example:

  • Project 1 (main Project): You just created the custom role by following the Steps 6 and 7.
  • Project 2: Create the identical role by switching to Project 2 and repeating Steps 6 and 7.
  • Project 3: Create the identical role by switching to Project 3 and repeating Steps 6 and 7.
  • Continue this process for all other additional projects that you wish to onboard to Saner Cloud Security.

The role name and permissions must remain consistent across every project being onboarded.

Create Service Account (on Main Project only)

NOTE: Create the Service Account only in the Main Project and not in any additional projects.

Step8: Follow these steps:

  1. Switch to the project that you want to use for creation of Service Account.
  2. Go to “IAM and Admin” and click on “Service Accounts”, then click on a “Create service account”.

Step9: Enter the “Service Account” Name as “sa-cnapp-<date>” (e.g. sa-cnapp-16-03-2026) and a relevant description. Click on Done,  to create the Service Account.

Step10: Verify the service account creation by searching the name of the service account in search bar. Make sure to copy the Service Account Name and keep it handy.

Perform the Roles Binding to the GCP Service Account (on All Projects)

Step11: Ensure you have Editor, Project IAM Admin, and Role Administrator Permissions for Project-Level bindings.

Step12: Using the Service Account created in Step 9, navigate to the Main Project page in the Google Cloud Console. Go to “IAM & Admin” → “IAM,” and click “Grant Access.”

Step13: Add the Name of the Service Account created manually or paste the Name of the Service Account copied in Step 10 in the “New Principals” section.

Step14: Follow these steps:

  1. Assign the roles such as Viewer, BigQuery Data Viewer, BigQuery Job User
  2. Also, assign the Custom Remediator Role Saner_CNAPP_Remediation_Role_xxxx_xxxx created in Step 7.
  3. Once all the roles are assigned, click “Save”.

Step15: If you are onboarding multiple Projects to Saner Cloud Security, repeat Step13 and Step14 for all the additional projects that you are onboarding.

NOTE
To verify if above steps were done successfully, Switch to the Project where the Service Account was created. Navigate to “IAM” under “IAM and admin” and check that the Service Account has Inherited Viewer and Custom Role which were assigned to the Service Account (e.g. “Saner_CNAPP_Remediation_Role_xxxx_xxxx”) at the Org Level.

Service Account Key Generation

Step16: Follow these steps:

  1. Navigate to “IAM & Admin” in the project where the Service Account was created.
  2. Click “Service Accounts”, and search for the Service Account created in Step 9
  3. Select the service account from the list by clicking on it.

Step17:  In order to acquire the Private key required for onboarding, Go to Service account Page and navigate to the “Keys” tab.
Click on “Add Key” and select “Create new key”, choose the “Key type” as JSON and click on Create.

Step18: Once the key is generated, a popup message appears and the key is downloaded to the user’s local system. Click “Close” on the confirmation popup window. Store the JSON file to a secure location for future reference.

Enable Domain Wide Delegation

Enable Domain Wide Delegation

Step19: Key File generated contains the necessary information such as client_email, private_key and client_id necessary for onboarding

Scopes mentioned in Step 21 needs to be added to the Client id of Service account, by Google workspace Admin.

Step20: Login in to admin.google.com, and go to Security > Access and data control > API controls and click on Manage Domain Wide Delegation.

Step21: Follows these steps:

  1. Click on “Add New”
  2. Enter the Client ID from Service Account Key File generated
  3. Add scopes mentioned below to the Client Id.

Note: The Scopes could be added one by one to separate fields or they could also be added in a single field with comma separated values

https://www.googleapis.com/auth/admin.directory.user
https://www.googleapis.com/auth/admin.directory.group
https://www.googleapis.com/auth/cloud-identity
https://www.googleapis.com/auth/cloud-platform
https://www.googleapis.com/auth/admin.reports.audit.readonly
https://www.googleapis.com/auth/cloudplatformprojects

Step22: Once all the Scopes are added, click on AUTHORISE to update the scopes.

IMPORTANT:
If you wish to see the GCP Billing data in Saner Cloud CSAE dashboard, and necessary roles [BigQuery Related] were added to the Service Account to support it as part of Step 16, you can continue from Step 23 onwards.
Else jump to Step 30 to complete the Onboarding Process.

[Optional] Steps to Enable Billing Export to BigQuery

NOTE: Please keep a note of Project ID, Dataset ID, Dataset Location and Billing Account ID which you will use in below steps for future onboarding steps.

Step23: Select the Project where the Service Account was created and navigate to the BigQuery Console.

Step24: In the left panel, click on the arrow to expand options under the Project ID and click on the   “Create dataset” as shown in following image.

Step25: Follow these steps:

1. Enter a Dataset name in format such as, “sanercloud_export_YYYYMMDD”.

2. Choose a location where you want the Dataset to be created (example: US , EU, us-central1, etc)

3. Click on “Create data set”

Step26: Navigate to the Billing Console and select the Billing Account which needs to be linked with the Dataset created in Step 25.

Step27: From the left-hand-side Menu, click “Billing Export”.

Step28: Under “Detailed usage cost”, select the project where the Dataset was created, and select the Dataset that was just created and click on “Save”.

Note:

Cloud Billing data is populated for both the current and previous month starting from the time the dataset begins receiving data. During the initial backfill process, it may take up to five days for the billing data to start exporting. You will begin seeing your usage data only after the backfill process is completed.

Allow up to five days for the initial billing data to appear on your Saner Cloud Dashboard. This is a one-time setup process. Once the data linking is completed, new billing data will be exported automatically on an ongoing basis. For more information, refer to the GCP Guide.

[Required] Make a note of the Project ID, Dataset ID, and Location of the dataset that was created, as well as the Billing Account ID where the billing_export is linked to the dataset.

Note: “Billing Account ID” can be found by navigating to “Billing account management” section.

Step29: Follow these steps:

  1. Onboarding without Billing Information:
    a. Copy the details from the key file which was downloaded as part of Step 18
    b. Go to Saner Onboard & Scan page
    c. Paste the “Client Email” and “Private Key” in the respective fields and provide the email Id of Workspace Super Admin User in the field “Subject”, followed by “Domain Name” and “Organization ID”
    d. Click on “Onboard Project” to complete the Onboarding Process

2. Onboarding with GCP Billing Information

Notes:

  1. Google Cloud billing data is added covering the current and previous month from the time the data is being populated in the dataset. During the first data backfill, it can take up to five days for your Cloud Billing data to begin with exporting. You will start seeing your usage data only after this process is complete.

Wait for 5 days for first billing data to appear on your Saner Cloud Dashboard. Please note that this is a one-time setup. After data linking activity is done, new data will be exported automatically. Go through the GCP Guide for more details.

  • “Billing Account ID” Can be found by navigating to “Billing account management” section.
  1. Copy the details such as “Client Email” and “Private Key” from the key file which was downloaded as part of Step 17
  2. Get the email Id of Workspace Super Admin User for the “Subject” field followed by “Organization ID” and “Domain Name”
  3. Collect the Project ID, Dataset ID, Dataset Location and Billing Account ID which were used for Step23 to Step28
  4. Go to Saner Onboard & Scan page
  5. Paste the “Client Email” and “Private Key” in the respective fields and provide the email Id of Work Space Super Admin User in the field “Subject”. Followed by providing respective “Organization ID” and “Domain Name”
  6. Enable “Collect GCP Billing Data” and Fill the Respective “Billing Project ID”, “Billing Dataset ID”, “Billing Account Id” and “Billing Location”
  7. Click on “Onboard Project” to complete the Onboarding Process

Step30: You have now completed the GCP Manual Onboarding. The Scan Configuration page opens automatically for you to make the necessary settings to initiate the scan. You have an option to:

  • Validate credentials (Test Credentials button) to prevent scan failures due to authentication issues
  • Setup the Scan Schedule run as needed
  • Start the scan or Pause the scan and then resume it from the point where it was paused

Best Practices

  • Regularly review and audit access permissions
  • Keep private keys secure and rotate them regularly
  • Document any custom configurations
  • Regularly verify integration status

Troubleshooting Guide

If you encounter any issues during the onboarding or deployment process, follow these steps to diagnose and resolve them efficiently.

Step1: Verify All Permissions Are Correctly Set

Ensure that the necessary IAM permissions are granted for the user or role performing the deployment. Missing or insufficient permissions may cause failures during onboarding.

  • Check IAM role assignments
  • Ensure the user has administrative privileges or the required set of permissions
  • Confirm that the APIs of the GCP services involved in the deployment have been enabled

Step2: Clean Up Previous Failed Onboarding Attempts

If you are retrying the onboarding process due to a previous failure, make sure all remnants of the prior attempt are removed before trying again.

  • Delete any incomplete Service Accounts created without any keys
  • Remove any IAM roles or permissions that may have been created in the failed attempt
  • Ensure there are no residual configurations that could cause conflicts in a new attempt

Step4: Confirm Required Roles Are Attached to the User

The onboarding process requires the user executing the deployment to have the correct IAM policies assigned. The required privileges include:

  • Project IAM Admin – Ability to bind the Service Account at the Project Level
  • Role Administrator – Permissions to create Custom Roles at the Project Level
  • Editor – Sufficient Permission to create a Service Account at the Project Level
  • Workspace Super Admin – Permission to add the necessary scopes for the client id generated

Step5: Contact Support if Issues Persist

If you have verified the above steps and are still facing issues, reach out to the support team for assistance.

  • Provide detailed logs and error messages
  • Mention the GCP services you are working with
  • Describe the steps already taken for troubleshooting

Share This Article :

  • X
  • LinkedIn
Still stuck? How can we help?

Saner Documentation Feedback

Onboarding a GCP Organization to Saner Cloud(Manual)Azure Onboarding
Table of Contents
  • Pre-requisites
    • Create a New Account in Saner Cloud
    • Integrate Your GCP Account with Saner Cloud Security
      • Setup
      • Available Integration Methods
    • Steps to Use the Manual Method
    • Enable Required GCP APIs for Project Integration
    • Create and Configure a Custom IAM Role for Saner Cloud Security
      • Create Service Account (on Main Project only)
      • Perform the Roles Binding to the GCP Service Account (on All Projects)
    • Service Account Key Generation
  • Enable Domain Wide Delegation
    • [Optional] Steps to Enable Billing Export to BigQuery
    • Best Practices
    • Troubleshooting Guide
Copyright 2026 - SecPod. All Rights Reserved. Privacy Policy.
SanerNow Version 6.5.x