Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard

A global company uses Google Cloud and has diverse teams across different regions. They want to allow developers to create custom IAM roles for their specific projects, but only within a predefined set of permissions that the central security team has approved. The security team needs to prevent developers from creating custom roles that grant overly broad or unauthorized permissions (e.g., 'iam.serviceAccounts.keyAdmin' or 'resourcemanager.organizations.setIamPolicy'). How can the security engineer enforce this constraint on custom role creation?

  1. ASet an Organization Policy Constraint with a custom constraint that restricts allowed permissions in custom roles.
  2. BImplement Identity Platform and configure it to block creation of sensitive custom roles.
  3. CUse a custom IAM role at the organization level that explicitly denies 'iam.roles.create' for developers.
  4. DManually review every custom role created by developers and delete unauthorized ones.
Show answer & explanation

Correct answer: A. Set an Organization Policy Constraint with a custom constraint that restricts allowed permissions in custom roles.

Organization Policy Constraints are the correct mechanism to enforce restrictions across an entire organization or folder hierarchy. A custom constraint can be defined to specify a denylist or allowlist of permissions that are permitted or denied within custom IAM roles, thereby preventing developers from creating roles with unauthorized permissions.

Why the other options are wrong

  • B. Identity Platform is for customer-facing identity management (CIAM) and has no functionality to control the permissions defined within Google Cloud IAM custom roles.
  • C. Denying 'iam.roles.create' at the organization level would prevent *any* custom role creation, which contradicts the requirement of *allowing* developers to create custom roles within a predefined set of permissions.
  • D. Manual review is reactive, error-prone, and does not scale in a large organization. It does not proactively *prevent* the creation of unauthorized roles.

Organization Policy Constraints (Custom)

Rules defined within Google Cloud Organization Policy Service that enforce restrictions on how resources can be configured, including what permissions can be included in custom IAM roles.

  • Applied at organization, folder, or project level.
  • Can enforce allowlists or denylists for specific resource properties or IAM permissions.
  • Crucial for enforcing security and compliance guardrails across the organization.

Memory trick: Org Policies are the 'guardrails' for 'custom roles'.

More Configuring access within a cloud solution environment questions