Action: GCP > Network > Firewall > Set Target Tags
Set the firewall rule's target tags to the subset matching the GCP > Network > Firewall > Target Tags > Approved > Tags patterns (wildcards * and ? are supported) — that is, remove only the unapproved target tags. Only the target tags are changed; allowed, sourceRanges and every other field on the rule are left untouched, and the rule is never deleted. The quick action mirrors the Target Tags > Approved control's safety guards: while the approved list is unconfigured nothing is removed, and the rule's last remaining target tag is never removed, because an empty target-tag set would apply the rule to every instance in the network. A rule that targets no network tags (for example one targeting service accounts) is left unchanged.
Resource Types
This quick action targets the following resource types:
Controls
This quick action enforces the following controls: