Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy

A security engineer needs to implement a policy that prevents any user from directly assigning the `roles/owner` role to any new user or service account at the project level within the entire organization. This policy should apply to all existing and future projects. How can this be achieved most effectively?

  1. AConfigure a Cloud Audit Logs sink to alert on `roles/owner` assignments and manually revoke them.
  2. BImplement an Organization Policy constraint that disallows the `roles/owner` role from being granted.
  3. CCreate a custom IAM role that excludes the `resourcemanager.projects.setIamPolicy` permission and assign it to all project administrators.
  4. DUse IAM Conditions to restrict who can assign the `roles/owner` role based on time of day.
Show answer & explanation

Correct answer: B. Implement an Organization Policy constraint that disallows the `roles/owner` role from being granted.

Organization Policies are designed to enforce restrictions across an entire organization or specific folders/projects, making them the most effective way to prevent the assignment of specific roles like `roles/owner` at scale.

Why the other options are wrong

  • A. Auditing and manual revocation is reactive and not preventative, failing to meet the requirement of 'preventing' the assignment.
  • C. Custom roles limit what a user with that role can do, but don't prevent other users (e.g., existing project owners) from assigning the owner role if they have the necessary permissions.
  • D. IAM Conditions can restrict role assignments based on attributes like time, but an Organization Policy is specifically designed for broad, preventative restrictions on role grants themselves, independent of who is making the grant or when.

Organization Policy Constraints

Organization Policy Constraints allow administrators to define guardrails for their Google Cloud resources, enforcing specific behaviors or preventing certain actions across the entire organization or specific parts of it.

  • Applied at the Organization, Folder, or Project level.
  • Preventative controls, not just reactive auditing.
  • Can restrict resource configurations, API usage, and IAM policies.
  • Often used to enforce compliance and security best practices.

Memory trick: Organization's Royal Guard: No one gets the Crown without explicit permission!

More Configuring access within a cloud solution environment questions