Hi @ar3diu ! In Chronicle SOAR, group email addresses can only be used for direct user mapping, not as substitutes for IAM roles in the IAM Role Mapping section.
If two Google Groups have the same IAM role, SOAR cannot differentiate them just by email — IAM role mapping uses IAM roles only, not group identity. try this
Use email-based user/group mapping instead of IAM role mapping.
Go to SOAR Settings → User Management and assign permission groups and SOC roles directly to the group email address there.
Or, assign different IAM roles to each Google Group in Cloud IAM, then map those roles in SOAR to different permissions/SOC roles.
Unfortunately, IAM Role Mapping in SOAR doesn’t support differentiating groups with the same IAM role.
Hi @ar3diu ! In Chronicle SOAR, group email addresses can only be used for direct user mapping, not as substitutes for IAM roles in the IAM Role Mapping section.
If two Google Groups have the same IAM role, SOAR cannot differentiate them just by email — IAM role mapping uses IAM roles only, not group identity. try this
Use email-based user/group mapping instead of IAM role mapping.
Go to SOAR Settings → User Management and assign permission groups and SOC roles directly to the group email address there.
Or, assign different IAM roles to each Google Group in Cloud IAM, then map those roles in SOAR to different permissions/SOC roles.
Unfortunately, IAM Role Mapping in SOAR doesn’t support differentiating groups with the same IAM role.
So in SOAR Settings > User Management there is no option to add a new entry. If I go to Group Mapping then here's where I added IAM Role Names as the Group. I tried to add the group email address instead of the IAM Role but it did not work.

