Description
An allAuthenticatedUsers entry in BigQuery dataset access grants its role to all authenticated BigQuery users, beyond a single organization. This differs from anonymous access but can still admit external users who do not need access.
The role determines the available operations. In particular, OWNER is not a read-only role; review dataset administration permissions too.
Potential impact
- Sensitive analytics, customer data or internal metrics can be exposed to external users.
- Excessive roles can also permit data changes or access management.
Remediation
- Remove public-group grants unless publication is intended, and allow only required users, groups and service accounts.
- Use a minimal read role for identities that only need to query data.
- Preserve necessary existing entries when changing the access list, and verify that required access still works and unwanted access is denied.
Examples
Deployment Manager is a legacy tool whose support has ended. Plan migration to a supported management tool. Replace the dataset ID and group address with actual values.
Before
resources:
- name: bigquery
type: bigquery.v2.dataset
properties:
datasetReference:
datasetId: analytics
access:
- role: OWNER
specialGroup: allAuthenticatedUsers
- role: READER
groupByEmail: analytics-readers@example.com
All authenticated BigQuery users receive the OWNER role.
After
resources:
- name: bigquery
type: bigquery.v2.dataset
properties:
datasetReference:
datasetId: analytics
access:
- role: READER
groupByEmail: analytics-readers@example.com
The public-group entry is removed, leaving READER access for the named Google group. Preserve separate permissions for required administrators.