Description
Granting IAM roles directly to individual users is valid, but complete revocation can become harder when people change jobs or leave. Organization-managed groups can separate membership changes from role administration.
Potential impact
- Unnecessary direct grants can leave users with access after their work has ended.
- Moving to groups can still leave excessive access if membership management or role scope is unsuitable.
Remediation
- Confirm the need and owner of direct grants, and use managed groups with minimum required roles where appropriate. Review approved individual grants periodically.
- Control group membership and administration, and remove unnecessary public principals. Verify both required access and revoked access after changes.
Examples
This data source generates a policy document; its application to a resource is omitted. Review the retained Apigee-specific role and sample addresses, using a suitable minimum role and an actual directory group.
Before
hcl
data "google_iam_policy" "example" {
binding {
role = "roles/apigee.runtimeAgent"
members = [
"user:jane@example.com",
]
}
}
After
hcl
data "google_iam_policy" "example" {
binding {
role = "roles/apigee.runtimeAgent"
members = [
"group:jane@example.com",
]
}
}
Explanation:
- Before: The role names an individual user as a member.
- After: The member is a group. Actual membership and the policy’s application still need to be managed.