Description
In BigQuery, allAuthenticatedUsers is not limited to your organization. It includes service accounts and internet users authenticated with Google Accounts, including personal Gmail accounts. It does not include unauthenticated, anonymous users.
Granting a dataset role to this group lets users outside the organization perform the operations allowed by that role. For internal data, restrict access to the required users, groups or service accounts. Review both dataset permissions and permissions inherited from higher-level resources to understand the actual access scope.
Potential impact
- If a valid grant takes effect, authenticated users outside the organization can perform the operations permitted by that role. Read permissions can allow unintended data access or copying.
- Granting write or administrative permissions to such a broad group can increase the impact. The group name alone does not establish the permissions granted or the extent of exposure.
- Replacing an existing access list incorrectly can also interrupt access for required users and services. Check both the removal of public grants and the retention of necessary permissions.
Remediation
- Inspect the dataset's actual access entries, IAM policy and inherited permissions. Determine whether publication is intentional; remove unnecessary
allAuthenticatedUsersgrants from internal datasets. - Specify the required users, groups or service accounts and the minimum roles they need.
- Revoke existing grants explicitly through a supported BigQuery access-control operation. Retain the necessary entries when updating the access list. Omitting or emptying
accessin thegoogle.cloud1.14.0 module does not explicitly revoke existing grants. - Read the resulting policy and test access for both intended and unintended users. Check for permissions granted through other paths.
Examples
Authenticated-users group entry
---
- name: create a dataset
google.cloud.gcp_bigquery_dataset:
name: my_example_dataset
access:
- special_group: allAuthenticatedUsers
dataset_reference:
dataset_id: my_example_dataset
project: test_project
auth_kind: serviceaccount
service_account_file: "/tmp/auth.pem"
state: present
Default access for a new dataset
- name: create a dataset
google.cloud.gcp_bigquery_dataset:
name: my_example_dataset
dataset_reference:
dataset_id: my_example_dataset
project: test_project
auth_kind: serviceaccount
service_account_file: /tmp/auth.pem
state: present
Explanation:
- Authenticated-users group entry: The example specifies
allAuthenticatedUsersbut has norole. It is an incomplete permission configuration and should not be deployed as written. - Default access for a new dataset: When
accessis omitted on creation, BigQuery adds default access for theprojectOwners,projectWritersandprojectReadersgroups and for the dataset creator. This does not automatically establish least privilege or revoke a public grant on an existing dataset. Configure the project and credential-file settings for the actual environment.