ST-2026-002 · Authentication & identity
Google SecOps SOAR sets 30 September deadline for Stage 2 API, IAM and agent migration
Google Security Operations requires Stage 2 migration of SOAR permissions, APIs, webhooks, audit logging and Remote Agents to Google Cloud services, with legacy APIs, API keys and several legacy components scheduled to stop functioning after 30 September 2026.
Previous state
SOAR permission groups, legacy SOAR APIs/API keys, siemplify-soar.com webhooks and API-key-authenticated Remote Agents.
Current state
Google Cloud IAM, Chronicle API endpoints, googleapis.com webhook URLs, Cloud audit logging and service-account-authenticated Remote Agents.
Affected users
Who needs to care
SOAR administrators, integration owners and developers using legacy API calls, permission groups, webhooks or Remote Agents.
Required response
What to do
Complete Stage 1 first, migrate permissions to IAM, map legacy API calls to Chronicle API, update webhook domains and formats, and upgrade Remote Agents to service-account authentication before the final deadline.
Evidence boundary
What the source does not prove
The documentation states the migration obligations and final deadline. It does not prove that any individual customer has completed Stage 1 or Stage 2, and some customer-specific migration timing remains controlled through in-product notices.
Lifecycle history
Dated event sequence
- Stage 2 generally available
Google made Stage 2 migration available to all customers.
- Final transition deadline
Legacy SOAR APIs and API keys, legacy webhook domain, permission compatibility surfaces and existing Remote Agents reach the documented cutoff.
- Official-source recheck
Current Google migration and API guidance continued to state 30 September 2026 as the final cutoff for legacy SOAR APIs, webhooks and Remote Agents.
Evidence ledger
First-party sources
- 01Google Cloud Documentation — SOAR migration overview
Official migration documentation · 2026-07-22
Open official source ↗ - 02Google Cloud Documentation — Migrate to Chronicle API
Official API migration guide · 2026-07-22
Open official source ↗