Broad authenticated-user access to a GCP BigQuery dataset

Limit dataset access to the users and service accounts that need it.

Description

Granting access to allAuthenticatedUsers on a GCP BigQuery dataset includes Google-authenticated users and service accounts outside your organization. On a sensitive dataset, this broad grant can permit data reads, changes or access management, depending on the role.

allAuthenticatedUsers does not mean anonymous users, but it is not limited to members of your organization. The granted role and other applicable authorization controls determine which operations are possible.

Potential impact

  • Read permissions can allow information to leave the organization.
  • Write or administrative permissions can compromise data integrity or access controls.

Remediation

Confirm whether the data is intended for public use and remove unnecessary allAuthenticatedUsers grants. Give approved users, groups and service accounts only the roles they need, and review inherited IAM permissions. Verify that required access succeeds and unapproved access is denied.

Examples

These examples change access to the same dataset. The definition of the referenced bqowner service account is omitted.

Before

hcl
resource "google_bigquery_dataset" "analytics_dataset" {
  dataset_id = "example_dataset"
  location   = "EU"

  access {
    role          = "OWNER"
    special_group = "allAuthenticatedUsers"
  }
}

This gives OWNER access to all Google-authenticated users and service accounts, making both the audience and permissions broad.

After

hcl
resource "google_bigquery_dataset" "analytics_dataset" {
  dataset_id = "example_dataset"
  location   = "EU"

  access {
    role          = "OWNER"
    user_by_email = google_service_account.bqowner.email
  }
}

This limits the principal to one service account but retains OWNER access. Check whether it needs dataset administration and use a narrower role if it does not.

References