Description
Granting access to allAuthenticatedUsers on a GCP BigQuery dataset includes Google-authenticated users and service accounts outside your organization. On a sensitive dataset, this broad grant can permit data reads, changes or access management, depending on the role.
allAuthenticatedUsers does not mean anonymous users, but it is not limited to members of your organization. The granted role and other applicable authorization controls determine which operations are possible.
Potential impact
- Read permissions can allow information to leave the organization.
- Write or administrative permissions can compromise data integrity or access controls.
Remediation
Confirm whether the data is intended for public use and remove unnecessary allAuthenticatedUsers grants. Give approved users, groups and service accounts only the roles they need, and review inherited IAM permissions. Verify that required access succeeds and unapproved access is denied.
Examples
These examples change access to the same dataset. The definition of the referenced bqowner service account is omitted.
Before
resource "google_bigquery_dataset" "analytics_dataset" {
dataset_id = "example_dataset"
location = "EU"
access {
role = "OWNER"
special_group = "allAuthenticatedUsers"
}
}
This gives OWNER access to all Google-authenticated users and service accounts, making both the audience and permissions broad.
After
resource "google_bigquery_dataset" "analytics_dataset" {
dataset_id = "example_dataset"
location = "EU"
access {
role = "OWNER"
user_by_email = google_service_account.bqowner.email
}
}
This limits the principal to one service account but retains OWNER access. Check whether it needs dataset administration and use a narrower role if it does not.