CanDelegate
Domain-wide/OAuth delegation to act for other principals.
Identity, ApplicationIdentity
── CanDelegate ──▸
Identity
Source types
IdentityApplicationIdentityTarget types
IdentityStates
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | both |
|---|
Per-cloud
| cloud | permissions / triggers | note |
|---|---|---|
| gcp | - | |
| azure | - |
Rules that emit CanDelegate 1
Service account with Domain-Wide Delegation can act as any active Workspace user in the domain for its configured OAuth2 scopes, without the user's knowledge or consent - a tenant-wide identity takeover primitive.
gcpderived