ARIA monitors Google Workspace identity events continuously — surfacing MFA gaps, unauthorized admin privilege changes, suspicious sign-in patterns, and OAuth grants that outlive their usefulness.
Credential-based attacks — phishing for passwords, password spraying, session token theft — require no malware and leave no endpoint artifact until an attacker is already inside the environment. The initial access step is an authentication event that looks identical to a legitimate login. The only way to distinguish it is context: does this login match the user's established pattern? Is the device familiar? Has this IP appeared before?
Identity monitoring answers those questions continuously, for every authentication event in the environment. It does not require endpoint agents or network sensors. The Admin SDK and Alert Center give ARIA direct access to authentication events, admin console actions, and OAuth grant records for every user in the Workspace tenant.
ARIA surfaces users who do not have two-factor authentication enabled on their Google Workspace accounts. MFA enrollment status is available through the Workspace Admin SDK directory API. Accounts without MFA are significantly more susceptible to credential theft — a phished password is sufficient for account takeover with no further exploitation required.
ARIA also monitors for MFA bypass events: when a user authenticates without their second factor in a context where one would normally be expected. Alert Center fires on suspicious login events that include bypassed or absent MFA challenges, and ARIA investigates these for context before escalating confirmed anomalies.
Changes to administrative privileges in Google Workspace — assigning super admin access, creating a new admin role, granting delegated admin permissions — are high-risk events that deserve immediate investigation when they occur outside of an expected provisioning workflow. An attacker who has compromised a standard user account will often attempt to escalate to admin access to establish persistence and broaden their reach.
ARIA fires on any event where super admin privileges are assigned to an account. Super admins have unrestricted access to the Workspace environment — every user's data, all settings, billing, and domain management. There is rarely a legitimate reason to grant super admin access without prior planning.
Admin console actions that occur outside of the organization's normal operational hours — late night, weekends, or holidays — are worth investigating regardless of which account performed them. Attackers who compromise an admin account prefer to act when the change is least likely to be noticed immediately.
Delegated admin roles with specific permissions — account management, group management, reporting — can be created to grant limited admin access. ARIA monitors the creation of new delegated admin accounts and correlates them against any recent suspicious activity involving the creating account.
Google Workspace Alert Center fires on login events that its own heuristics flag as suspicious: logins from IPs associated with known threat infrastructure, login attempts from geographic locations far removed from the user's established pattern, or logins from devices not previously seen on the account. ARIA receives these alerts and adds investigation context:
A login from an unfamiliar country followed by immediate admin console access is a confirmed escalation. A login from a new IP with no subsequent anomalous activity and a known VPN provider may close as low-risk — with the investigation logic recorded.
When a Workspace user authorizes a third-party application — a productivity tool, a file converter, a calendar integration — that application receives an OAuth token granting it access to the user's data. The scope of that access is determined at authorization time and, unless the token is explicitly revoked, persists indefinitely. Applications that are no longer in use continue to hold access grants that represent an ongoing exposure.
ARIA monitors OAuth grant events from the Workspace Admin SDK: new grants, grants with broad scopes (particularly those requesting access to Gmail or Drive contents), and grants from applications that have not been reviewed or approved at the organizational level. ARIA also surfaces grants to applications that subsequently appear on threat intelligence feeds — a third-party application compromised after the fact is an access path that looks legitimate until it is not.
Revocation of OAuth tokens for specific applications is a containment action ARIA can propose and a security engineer can approve — removing the application's access across all users in the tenant who granted it.
A read-only ARIA agent connected to your Workspace tenant surfaces MFA gaps, recent admin role changes, and OAuth grants within 48 hours — at no cost.
Book Free AssessmentARIA monitors email, endpoints, and cloud activity alongside identity — the same pipeline handles all four.
View All Use Cases