Skip to main content
Question

IAM Role Mapping in Chronicle SOAR for Google Groups

  • June 3, 2025
  • 5 replies
  • 484 views

ar3diu
Forum|alt.badge.img+9

How can we use group email addresses to assign permission groups and SOC roles in SOAR regardless of what IAM roles they were given in the project IAM? (e.g. Two groups with the same IAM role but who should have different permissions and SOC Roles in SOAR?) 

I tried to use the email address of a google group instead of a IAM Role Name but it doesn't seem to work.

Docs: https://cloud.google.com/security-command-center/docs/map-users-in-secops

 

5 replies

a_aleinikov
Forum|alt.badge.img+6
  • Bronze 1
  • June 4, 2025

Hi @ar3diu ! In Chronicle SOAR, group email addresses can only be used for direct user mapping, not as substitutes for IAM roles in the IAM Role Mapping section.

If two Google Groups have the same IAM role, SOAR cannot differentiate them just by email — IAM role mapping uses IAM roles only, not group identity. try this

  • Use email-based user/group mapping instead of IAM role mapping.
    Go to SOAR Settings → User Management and assign permission groups and SOC roles directly to the group email address there.

  • Or, assign different IAM roles to each Google Group in Cloud IAM, then map those roles in SOAR to different permissions/SOC roles.

Unfortunately, IAM Role Mapping in SOAR doesn’t support differentiating groups with the same IAM role.


ar3diu
Forum|alt.badge.img+9
  • Author
  • Silver 2
  • June 5, 2025

Hi @ar3diu ! In Chronicle SOAR, group email addresses can only be used for direct user mapping, not as substitutes for IAM roles in the IAM Role Mapping section.

If two Google Groups have the same IAM role, SOAR cannot differentiate them just by email — IAM role mapping uses IAM roles only, not group identity. try this

  • Use email-based user/group mapping instead of IAM role mapping.
    Go to SOAR Settings → User Management and assign permission groups and SOC roles directly to the group email address there.

  • Or, assign different IAM roles to each Google Group in Cloud IAM, then map those roles in SOAR to different permissions/SOC roles.

Unfortunately, IAM Role Mapping in SOAR doesn’t support differentiating groups with the same IAM role.


So in SOAR Settings > User Management there is no option to add a new entry. If I go to Group Mapping then here's where I added IAM Role Names as the Group. I tried to add the group email address instead of the IAM Role but it did not work.

 

 


Adrian So
Forum|alt.badge.img+1
  • Bronze 1
  • September 22, 2025

Hi @ar3diu ! In Chronicle SOAR, group email addresses can only be used for direct user mapping, not as substitutes for IAM roles in the IAM Role Mapping section.

If two Google Groups have the same IAM role, SOAR cannot differentiate them just by email — IAM role mapping uses IAM roles only, not group identity. try this

  • Use email-based user/group mapping instead of IAM role mapping.
    Go to SOAR Settings → User Management and assign permission groups and SOC roles directly to the group email address there.

  • Or, assign different IAM roles to each Google Group in Cloud IAM, then map those roles in SOAR to different permissions/SOC roles.

Unfortunately, IAM Role Mapping in SOAR doesn’t support differentiating groups with the same IAM role.

So in SOAR Settings > User Management there is no option to add a new entry. If I go to Group Mapping then here's where I added IAM Role Names as the Group. I tried to add the group email address instead of the IAM Role but it did not work.

148104i5F9D6C1A879C4C49.png

 

148103i0F5A01CA28B3E438.png

 

How do you fix this finally?

I got the similar issue; I would want assign some of my team member out of the admin group.

However, I have no way to set them.


cdc_maneesh
  • New Member
  • May 5, 2026

can we get final solution of this topic? 

i am also stuck at the same .


ar3diu
Forum|alt.badge.img+9
  • Author
  • Silver 2
  • May 6, 2026

@Adrian So ​@cdc_maneesh 

What worked for me so far:
1. 

  • IAM Role: Predefined Chronicle IAM Role (e.g., Chronicle API Admin) - We encountered some issues here with the Chronicle API Viewer and Chronicle API Editor roles, which lack certain permissions. This caused either the SecOps console to not load or several tabs to be inaccessible to users (such as SOAR Search).
  • Group Members: Leave this blank, or add only the users you want to assign to this specific SOC role.

2. 

  • IAM Role: Custom GCP IAM Role Name
  • Group Members: Leave this blank, or add only the users you want to assign to this specific SOC role.

3. 

  • IAM Role: Google Group Email Address
  • Group Members: Enter the email addresses of the individuals from that group who should be assigned to this specific SOC role.

 

Note: Apart from this, I have also mapped all predefined Chronicle IAM roles (Admin, Editor, and Viewer) in each instance. I am a bit skeptical of approach number three, as I do not think it works as expected. Based solely on my experience, the recommended path right now is approach number one. This is not ideal at all, as permissions evolve and I do not want to maintain a custom IAM role.

References
- https://medium.com/@HavSec/deciphering-google-secops-soar-iam-access-control-the-post-migration-reality-a571236a5b29