how to provide permission(create/view) to group in gcp and enable logging for the same

Viewed 882

How to provide permissions ->

  • How organization admin delegate create/view permission(identity access management) or access to group in google cloud platform ?? and enable logging for the same??
  • Can we create alias and grant permission to it as well??

Not able to find relevant documents to explain the steps to follow. Can anyone please enlighten? I am new to Google platform.

Went through following links which does not speak about groups permissions precisely.

To understand audit logging , went through following links

Can anybody share some link or pointer for my understanding.

Regards,

2 Answers

Google Cloud offers Identity and Access Management (IAM), which lets you give more granular access to specific Google Cloud resources and prevents unwanted access to other resources. IAM lets you adopt the security principle of least privilege, so you grant only the necessary access to your resources.

IAM lets you control who (users) has what access (roles) to which resources by setting IAM policies. IAM policies grant specific role(s) to a user giving the user certain permissions.

If you want more information about IAM follow this link

More information about Loggin in Google IAM

I agree with @Ismael Clemente Aguirre but in addition to it you can also check Manage access to project,folders and organisation.

Also Google groups can help you manage users at scale. Each member of a Google group inherits the Identity and Access Management (IAM) roles granted to that group. This inheritance means that you can use a group's membership to manage users' roles instead of granting IAM roles to individual users.

To use the Cloud Console to manage groups, you need a role that includes the resourcemanager.organizations.get permission.

To gain this permission while following the principle of least privilege, ask your administrator to grant you the Organization Viewer role (roles/resourcemanager.organizationViewer).

For more information regarding groups in IAM please refer Managing groups in Cloud Console.

Related