Google Associate Cloud EngineerConfiguring access and securityHard

A company is implementing a robust security posture across its Google Cloud projects. They want to ensure that all service accounts created within a specific folder adhere to the principle of least privilege, meaning they should only be granted roles that are absolutely necessary for their function. To enforce this, they need a way to review and approve all new IAM role grants to service accounts. Which Google Cloud feature allows for such controlled and auditable role assignments?

  1. AIAM Conditions
  2. BIAM Policy Troubleshooter
  3. COrganization Policy Constraints
  4. DIAM Recommender
Show answer & explanation

Correct answer: C. Organization Policy Constraints

Organization Policy Constraints can enforce policies at the folder or project level, preventing the granting of overly permissive roles to service accounts. Specifically, the 'Restrict service account usage' constraint can be configured to block service accounts from being granted certain roles, thereby enforcing least privilege and requiring a process (like policy exemption) for any exceptions, which can be part of a review/approval workflow.

Why the other options are wrong

  • A. IAM Conditions add conditional logic to role bindings but do not inherently provide a review/approval workflow for all new grants.
  • B. IAM Policy Troubleshooter helps understand why a user has or doesn't have a permission but doesn't enforce or approve policies.
  • D. IAM Recommender suggests optimal IAM roles based on usage but does not enforce policies or provide an approval workflow.

Organization Policy for Service Accounts

Organization Policies, specifically constraints like 'Restrict service account usage', can enforce rules on how service accounts are created and what roles they can be granted.

  • Prevents granting overly permissive roles to service accounts.
  • Enforces the principle of least privilege at an organizational or folder level.
  • Can be used in conjunction with policy exemptions for controlled exceptions and approval workflows.

Memory trick: Organization Policy is the bouncer for service account roles.

More Configuring access and security questions