ConditionalPolicy
Condition-bearing binding / Conditional Access / deny assignment.
class: Policy
Realizing resources
gcp gcp
| resource | scope | enumerate | required permissions |
|---|---|---|---|
gcp:accesscontextmanager:access-policy |
global | accesscontextmanager.accessPolicies.list |
accesscontextmanager.accessPolicies.list |
As edge source
As edge target
Exposure sites
None.
Rules that touch ConditionalPolicy 15
A principal who can delete the owning Blueprint/Managed-App or remove a deny-effect policy assignment can lift the guardrail suppressing inherited control edges.
azure
CanModifyPolicyIdentity that can grant policyAdmin at access policy scope gains full perimeter control.
gcp
CanModifyPolicyPrincipal with iam.denypolicies.update or .delete can remove/weaken a deny policy, upgrading the edges it was blocking.
gcp
CanModifyPolicyA principal who can modify or escape a guardrail (SCP / Org Policy / deny assignment) upgrades the edges that guardrail was suppressing from BLOCKED to their underlying state.
?cap