Control: GCP > Project > Organization Policy > Domain restricted sharing
Manage the GCP Organization Policy "Domain restricted sharing" for the project.
This list constraint defines the set of members that can be added to Cloud IAM policies. By default, all user identities are allowed to be added to Cloud IAM policies. The allowed/denied list must specify one or more Cloud Identity or G Suite customer IDs. If this constraint is active, only identities in the allowed list will be eligible to be added to Cloud IAM policies.
Resource Types
This control targets the following resource types:
Policies
The following policies can be used to configure this control:
This control type relies on these other policies when running actions:
- GCP > Project > Organization Policy > Domain restricted sharing > Action
- GCP > Project > Organization Policy > Domain restricted sharing > Custom Values
Category
In Your Workspace
Developers
- tmod:@turbot/gcp-orgpolicy#/control/types/iamAllowedPolicyMemberDomains
- tmod:@turbot/turbot#/control/categories/policy
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/gcp-orgpolicy#/control/types/iamAllowedPolicyMemberDomains"
Get Controls
Control Type URI
Category URI
GraphQL
CLI