BigQuery dataset grants access to a public group

Grant BigQuery dataset access only to the users and groups that need it.

Description

An allAuthenticatedUsers entry in BigQuery dataset access grants its role to all authenticated BigQuery users, beyond a single organization. This differs from anonymous access but can still admit external users who do not need access.

The role determines the available operations. In particular, OWNER is not a read-only role; review dataset administration permissions too.

Potential impact

  • Sensitive analytics, customer data or internal metrics can be exposed to external users.
  • Excessive roles can also permit data changes or access management.

Remediation

  • Remove public-group grants unless publication is intended, and allow only required users, groups and service accounts.
  • Use a minimal read role for identities that only need to query data.
  • Preserve necessary existing entries when changing the access list, and verify that required access still works and unwanted access is denied.

Examples

Deployment Manager is a legacy tool whose support has ended. Plan migration to a supported management tool. Replace the dataset ID and group address with actual values.

Before

yaml
resources:
  - name: bigquery
    type: bigquery.v2.dataset
    properties:
      datasetReference:
        datasetId: analytics
      access:
        - role: OWNER
          specialGroup: allAuthenticatedUsers
        - role: READER
          groupByEmail: analytics-readers@example.com

All authenticated BigQuery users receive the OWNER role.

After

yaml
resources:
  - name: bigquery
    type: bigquery.v2.dataset
    properties:
      datasetReference:
        datasetId: analytics
      access:
        - role: READER
          groupByEmail: analytics-readers@example.com

The public-group entry is removed, leaving READER access for the named Google group. Preserve separate permissions for required administrators.

References