Assigned
Status Update
Comments
ha...@google.com <ha...@google.com> #2
Thanks for the report. I will route this to the appropriate internal team and update this when I hear back from them.
No update yet.
Thanks for the report. I will route this to the appropriate internal team and update this when I hear back from them.
Description
Business Impact: Protecting Google IAM changes to prevent any single person from making an IAM change without the approval of at least one other person.
Relevant Details:
they are looking for available options protections Google IAM can add to prevent any single person from making an IAM change without the approval of at least one other person.
customer can create a separate org admin (and remove the org admin role from the existing super admin) as described in the best practices[1], but the super admin will still retain the permission to re-assign the org admin role to themselves.
Research done:
[1]-https://cloud.google.com/resource-manager/docs/super-admin-best-practices
[2]-https://cloud.google.com/iam/docs/setting-limits-on-granting-roles
Reproduction Steps: N/A
What you would like to accomplish:
How this might work: