Create tokened mails in gmail/gsuite mailboxes across your org.
Once the Gmail tokening is complete, please remember to remove the "Client ID" and "Client Scopes" entries from your G Suite OAuth client's dashboard found at:
From the Admin Console Home page, go to Menu Security API control. Under App access control, select MANAGE THIRD-PARTY APP ACCESS.
Follow the steps below to Tokenise a Google mailbox.
Step 1: Log in to your Console
Step 2: Add New Canarytoken
Click Add a new Canarytoken.
Step 3: Select Gmail Canarytoken
Create a new Gmail Canarytoken from the drop-down list.
Step 4: Start Process
Click on Let's begin (1 of 4).
Step 5: Modify token options and save the template
Modify the Token's options and paragraph text if you'd like and click on Save Template (2 of 4).
- Mail From: is the email address of who the message is from.
- Mail Subject: this can be changed to whatever you want the subject of the mail to be.
- Mail Content: you can change the content of this mail, we have given you a template to work from.
- Click on Save Template (2 of 4) when done.
Step 6: Login to G Suite
Login to your G Suite admin Console here.
Step 7: Access API Controls in G Suite Admin
In the G Suite admin Console, click on Security > Access and data control > API controls.
Or click the link here.
Step 8: Access Manage Third-party App
Click on MANAGE THIRD-PARTY APP ACCESS.
Step 9: Add the Canarytoken client ID
Click on Add app > Oath App Name Or Client ID
Step 10: Assign OAuth scopes and authorize.
Enter your Client ID and hit SEARCH.
Then Select the Thinkst Gsuite Tokener.
Select the Client ID again and hit SELECT.
Select your preferred organisation scope then select CONTINUE.
Select Trusted then select CONTINUE.
Review your configuration and select FINISH when done.
Head back to API controls, and select MANAGE DOMAIN WIDE DELEGATION.
Add a new API Client, by selecting Add new, then enter your following details:
Client ID: ABC123
First OAuth Scope: https://www.googleapis.com/auth/admin.directory.user.readonly
Second OAuth Scope: https://www.googleapis.com/auth/gmail.insert
Finally click AUTHORIZE when complete.
Step 11: Complete Gmail Tokening Setup in Canary Console
Back on your Canary Console, select All set! (3 of 4).
Select Search Gmail for users, then enter your Google Admin email address; finally select Search.
You'll be presented with a list of users to Token, which can be selected. When ready, select Insert Tokened Email (4 of 4) to start the Tokening process.
Alternatively, larger organisations can provide a comma-separated email list and then click on Insert Tokened Email (4 of 4).
Once the Gmail tokening is complete, the Canary API client can be revoked from the DOMAIN WIDE DELEGATION UI.