Google Associate Cloud EngineerConfiguring access and securityHard
A team member reports that they are unable to delete a specific Cloud Storage bucket, even though they believe they have the necessary 'Storage Admin' role. You check the IAM policy for the bucket and confirm they have 'roles/storage.admin' at the bucket level. What is a common reason for this unexpected permission denial?
- AThe Storage Admin role does not include the 'storage.buckets.delete' permission.
- BThe user's Cloud Identity account is not synchronized correctly.
- CThe bucket is currently in use by an active Compute Engine instance.
- DThere is an Organization Policy denying bucket deletion for that project.
Show answer & explanationAnswer & explanation
Correct answer: D. There is an Organization Policy denying bucket deletion for that project.
Organization Policies can set constraints at the organization, folder, or project level that override IAM permissions. If an Organization Policy constraint like 'Disable Force Delete' or 'Restrict deletion of specific resources' is active, it can prevent even an Owner or Storage Admin from deleting resources.
Why the other options are wrong
- A. The 'Storage Admin' role (roles/storage.admin) explicitly includes the 'storage.buckets.delete' permission, so this statement is incorrect.
- B. Cloud Identity synchronization issues typically affect login or initial access, not specific resource actions once authenticated and authorized by IAM.
- C. A bucket being in use by a Compute Engine instance would not prevent deletion from an IAM perspective, though it might cause errors during deletion if objects are referenced.
Organization Policy Constraints
Rules defined at the organization, folder, or project level that restrict how cloud resources can be configured or used, overriding IAM permissions in some cases.
- Enforce compliance and security across the resource hierarchy.
- Can prevent actions like resource deletion, IP address usage, or specific API calls.
- Applied hierarchically and inherited by child resources.
Memory trick: IAM gives the key, but Org Policy can lock the door, even if you try to open it more.