Policy: GCP > Project > Organization Policy > Disable Automatic IAM Grants for Default Service Accounts
Manage the GCP Organization Policy "Disable Automatic IAM Grants for Default Service Accounts" for the project.
This boolean constraint, when enforced, prevents the default App Engine and Compute Engine service accounts that are created in your projects from being automatically granted any IAM role on the project when the accounts are created.
By default, these service accounts automatically receive the Editor role when they are created.
Resource Types
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
- GCP > Project > Organization Policy > Disable Automatic IAM Grants for Default Service Accounts
- GCP > Project > Organization Policy
Policy Specification
Schema Type |
|
---|---|
Default |
|
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/policy
- tmod:@turbot/gcp-orgpolicy#/policy/types/iamAutomaticIamGrantsForDefaultServiceAccounts
- turbot graphql policy-type --id "tmod:@turbot/gcp-orgpolicy#/policy/types/iamAutomaticIamGrantsForDefaultServiceAccounts"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/gcp-orgpolicy#/policy/types/iamAutomaticIamGrantsForDefaultServiceAccounts"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI