Review per-user IAM access management in Google Cloud

Check the need for direct user grants and consider group-based administration.

Description

Granting IAM roles directly to individual users is valid, but complete revocation can become harder when people change jobs or leave. Organization-managed groups can separate membership changes from role administration.

Potential impact

  • Unnecessary direct grants can leave users with access after their work has ended.
  • Moving to groups can still leave excessive access if membership management or role scope is unsuitable.

Remediation

  • Confirm the need and owner of direct grants, and use managed groups with minimum required roles where appropriate. Review approved individual grants periodically.
  • Control group membership and administration, and remove unnecessary public principals. Verify both required access and revoked access after changes.

Examples

This data source generates a policy document; its application to a resource is omitted. Review the retained Apigee-specific role and sample addresses, using a suitable minimum role and an actual directory group.

Before

hcl
data "google_iam_policy" "example" {
  binding {
    role = "roles/apigee.runtimeAgent"

    members = [
      "user:jane@example.com",
    ]
  }
}

After

hcl
data "google_iam_policy" "example" {
  binding {
    role = "roles/apigee.runtimeAgent"

    members = [
      "group:jane@example.com",
    ]
  }
}

Explanation:

  • Before: The role names an individual user as a member.
  • After: The member is a group. Actual membership and the policy’s application still need to be managed.

References