本頁說明設定 Gemini Notebook Enterprise 時,必須完成的啟動工作。
完成本頁面上的工作後,使用者就能開始在 Gemini Notebook Enterprise 中建立及使用筆記本。
關於身分設定
如要完成設定,您必須在 Google Cloud中設定機構的識別資訊提供者 (IdP)。正確設定身分有兩個重要原因:
使用者可透過現有的公司憑證存取 Gemini Notebook Enterprise 使用者介面。
確保使用者只會看到自己擁有的筆記本,或是與自己共用的筆記本。
支援的架構
系統支援下列驗證架構:
Cloud Identity:
情況 1:如果您使用 Cloud Identity 或 Google Workspace,所有使用者身分和使用者群組都會透過Google Cloud顯示及管理。如要進一步瞭解 Cloud Identity,請參閱 Cloud Identity 說明文件。
案例 2:您使用第三方 IdP,且已將身分與 Cloud Identity 同步。使用者必須先透過 Cloud Identity 驗證身分,才能存取 Google 資源或 Google Workspace。
案例 3:您使用第三方 IdP,且已將身分與 Cloud Identity 同步。不過,您仍使用現有的第三方 IdP 執行驗證。您已透過 Cloud Identity 設定單一登入,使用者會先透過 Cloud Identity 登入,然後系統會將他們導向第三方 IdP。(設定其他 Google Cloud 資源或 Google Workspace 時,您可能已完成這項同步作業)。
員工身分聯盟:如果您使用外部識別資訊提供者 (Microsoft Entra ID、Okta、Ping、PingFederate 或其他 OIDC 或 SAML 2.0 IdP),但不想將身分同步到 Cloud Identity,則必須先在 Google Cloud中設定員工身分聯盟,才能為 Gemini Notebook Enterprise 啟用資料來源存取控管。
google.subject屬性必須對應至外部 IdP 中的電子郵件地址欄位。以下是常用 IdP 的google.subject和google.groups屬性對應範例:Microsoft Entra ID
使用 OIDC 通訊協定的 Microsoft Entra ID
google.subject=assertion.email google.groups=assertion.groupsMicrosoft Entra ID (使用 SAML 協定)
google.subject=assertion.attributes['http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name'][0] google.groups=assertion.attributes['http://schemas.microsoft.com/ws/2008/06/identity/claims/groups']-
如果您使用 Microsoft Entra ID,且群組數量超過約 150 個,請按照大量群組的設定程序操作。
google.subject=user.emails[0].value.lowerAscii() google.groups=group.externalId
Okta
google.subject=assertion.email google.groups=assertion.groupsgoogle.subject=assertion.subject google.groups=assertion.attributes['groups']
每個 Google Cloud 專案只能選取一個 IdP。
事前準備
開始執行本頁的程序前,請確認符合下列任一條件:
您使用 Cloud Identity 做為 IdP,或
您使用第三方 IdP,並已透過 Cloud Identity 設定 SSO,或
您使用非 Okta 的第三方 IdP,且符合下列條件:
請按照「使用 Microsoft Entra ID 設定員工身分聯盟,並讓使用者登入」一文中的操作說明,設定員工身分聯盟。如果群組數量超過約 150 個,請參閱「使用 Microsoft Entra ID 和大量群組,設定員工身分聯盟」一文。
如果按照「使用 Microsoft Entra ID 設定員工身分聯盟,並讓使用者登入」操作說明進行設定,請務必按照建議的安全最佳做法步驟新增群組聲明,並選取「所有群組」。這是 Gemini Notebook Enterprise 的必要步驟。
設定 SCIM。請參閱「在 Microsoft Entra ID 中設定 SCIM」。自動完成使用者電子郵件和群組名稱 以及使用大量群組的 Microsoft Entra ID 時,必須設定 SCIM。
您使用 Okta 做為第三方 IdP,並已按照「使用 Okta 設定員工身分聯盟」一文的說明操作。
建立專案並啟用 API
如果您已有要使用的 Google Cloud 專案,請從步驟 2 開始。
- 登入 Google Cloud 帳戶。如果您是 Google Cloud新手,歡迎 建立帳戶,親自評估產品在實際工作環境中的成效。新客戶還能獲得價值 $300 美元的免費抵免額,可用於執行、測試及部署工作負載。
-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Discovery Engine API.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.-
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
-
Verify that billing is enabled for your Google Cloud project.
Enable the Discovery Engine API.
Roles required to enable APIs
To enable APIs, you need the
serviceusage.services.enablepermission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.
授予 Cloud NotebookLM 管理員角色
專案擁有者必須將 Cloud NotebookLM 管理員角色指派給使用者,才能讓他們在這個專案中管理 Gemini Notebook Enterprise:
-
前往 Google Cloud 控制台的「IAM」頁面。
前往「IAM」頁面 - 選取專案。
- 按一下 「授予存取權」。
-
在「New principals」(新增主體) 欄位中,輸入使用者 ID。這通常是指 Google 帳戶或使用者群組的電子郵件地址。
- 在「Select a role」(選取角色) 清單中,選取「Cloud NotebookLM Admin」(Cloud NotebookLM 管理員)。 詳情請參閱「使用者角色」。
- 按一下「Save」(儲存)。
設定 Gemini Notebook Enterprise 的 IdP
專案擁有者或具備 Cloud NotebookLM 管理員角色的使用者可以設定 IdP。
前往 Google Cloud 控制台的「Gemini Notebook Enterprise」頁面。
將「身分設定」設為「Google 識別資訊提供者」或「第三方識別資訊提供者」。
詳情請參閱上方的「關於身分設定」。
如果您使用第三方 IdP 和員工身分聯盟,請指定工作團隊集區的名稱和工作團隊集區提供者。
複製「連結」。
您會將這個連結傳送給 Gemini Notebook Enterprise 的所有使用者。這是使用者介面的連結,使用者可透過這個介面建立、編輯及共用筆記本。
選用:註冊客戶自行管理的加密金鑰
如要使用客戶自行管理的加密金鑰 (CMEK) 而非 Google 預設加密,請按照客戶自行管理的加密金鑰中的操作說明,為 Gemini Notebook Enterprise 註冊金鑰。
一般來說,只有在貴機構有嚴格的法規要求或內部政策,規定必須控管加密金鑰時,才需要使用 CMEK。在大多數情況下,Google 預設加密就已足夠。如需 CMEK 的一般資訊,請參閱 Cloud Key Management Service 說明文件。
將 Gemini Notebook Enterprise 角色授予使用者
本節說明如何授予使用者 IAM 角色,讓他們存取、管理及共用筆記本。
-
前往 Google Cloud 控制台的「IAM」頁面。
前往「IAM」頁面 - 選取專案。
- 按一下 「授予存取權」。
-
在「New principals」(新增主體) 欄位中,輸入使用者 ID。這通常是 Google 帳戶或使用者群組的電子郵件地址,或是員工身分集區中使用者的 ID。詳情請參閱「 在 IAM 政策中代表工作團隊集區使用者」,或聯絡管理員。
-
在「Select a role」(選取角色) 清單中,選取
Cloud NotebookLM User角色。 - 按一下「Save」(儲存)。
除了 Cloud NotebookLM User 角色,使用者還需要 Gemini Notebook Enterprise 授權。請參閱取得 Gemini Notebook Enterprise 授權。