BigQuery access for all authenticated users

Granting BigQuery access to allAuthenticatedUsers can expose data to authenticated users outside your organization. Limit access to the identities and roles that are needed.

Description

In BigQuery, allAuthenticatedUsers is not limited to your organization. It includes service accounts and internet users authenticated with Google Accounts, including personal Gmail accounts. It does not include unauthenticated, anonymous users.

Granting a dataset role to this group lets users outside the organization perform the operations allowed by that role. For internal data, restrict access to the required users, groups or service accounts. Review both dataset permissions and permissions inherited from higher-level resources to understand the actual access scope.

Potential impact

  • If a valid grant takes effect, authenticated users outside the organization can perform the operations permitted by that role. Read permissions can allow unintended data access or copying.
  • Granting write or administrative permissions to such a broad group can increase the impact. The group name alone does not establish the permissions granted or the extent of exposure.
  • Replacing an existing access list incorrectly can also interrupt access for required users and services. Check both the removal of public grants and the retention of necessary permissions.

Remediation

  1. Inspect the dataset's actual access entries, IAM policy and inherited permissions. Determine whether publication is intentional; remove unnecessary allAuthenticatedUsers grants from internal datasets.
  2. Specify the required users, groups or service accounts and the minimum roles they need.
  3. Revoke existing grants explicitly through a supported BigQuery access-control operation. Retain the necessary entries when updating the access list. Omitting or emptying access in the google.cloud 1.14.0 module does not explicitly revoke existing grants.
  4. Read the resulting policy and test access for both intended and unintended users. Check for permissions granted through other paths.

Examples

Authenticated-users group entry

yaml
---
- name: create a dataset
  google.cloud.gcp_bigquery_dataset:
    name: my_example_dataset
    access:
      - special_group: allAuthenticatedUsers
    dataset_reference:
      dataset_id: my_example_dataset
    project: test_project
    auth_kind: serviceaccount
    service_account_file: "/tmp/auth.pem"
    state: present

Default access for a new dataset

yaml
- name: create a dataset
  google.cloud.gcp_bigquery_dataset:
    name: my_example_dataset
    dataset_reference:
      dataset_id: my_example_dataset
    project: test_project
    auth_kind: serviceaccount
    service_account_file: /tmp/auth.pem
    state: present

Explanation:

  • Authenticated-users group entry: The example specifies allAuthenticatedUsers but has no role. It is an incomplete permission configuration and should not be deployed as written.
  • Default access for a new dataset: When access is omitted on creation, BigQuery adds default access for the projectOwners, projectWriters and projectReaders groups and for the dataset creator. This does not automatically establish least privilege or revoke a public grant on an existing dataset. Configure the project and credential-file settings for the actual environment.

References