Change theme
Help
Press space for more information.
Show links for this issue (Shortcut: i, l)
Copy issue ID
Previous Issue (Shortcut: k)
Next Issue (Shortcut: j)
Sign in to use full features.
Vote: I am impacted
Notification menu
Refresh (Shortcut: Shift+r)
Go home (Shortcut: u)
Pending code changes (auto-populated)
View issue level access limits(Press Alt + Right arrow for more information)
Issue affecting a 3rd party
View staffing
Description
The customers (users) are not able to export data from the Google Search Console (GSC) and are seeking help from the Google Search Console team.
They are unable to execute any queries against BigQuery tables when DRS org policy is in place.
#### What you expected to happen:
They should be able to export data to the BigQuery table from GSC and be able to execute any queries against the BigQuery tables when DRS org policy is in place.
Other information (workarounds you have tried, documentation consulted, etc):
1. Using the service account impersonation
2. Running the query in a different project
They strongly feel that the changes required to resolve the issue (listed below) are not adhering to the "Least Privileged" principle:
1) Assign the “setIAMPolicy” permission to this service account on the Project,
2) Add the Service Account in the "Domain Restricted Sharing" Organization policy on the project.
Customer's note: "policies we need to enable for this setup is not our organization standard policy and is not a recommended approach. We are evaluating options that best fit our and Google's needs."