OrganizationPolicy
GCP org policy / governance constraint.
class: Policy
Realizing resources
gcp gcp
| resource | scope | enumerate | required permissions |
|---|---|---|---|
gcp:orgpolicy:policy |
global | orgpolicy.projects.policies.list |
orgpolicy.policies.list |
As edge source
As edge target
Exposure sites
None.
Rules that touch OrganizationPolicy 12
Ability to write Azure Policy assignments/definitions at a management group scope lets a principal weaken or remove a deny-effect guardrail inherited by the subtree.
azure
CanModifyPolicyorgpolicy.policy.set over ANY enforced OrganizationPolicy that blocks a modeled edge = guardrail-removal capability over it.
gcp
CanModifyPolicyDelete/alter a custom org-policy constraint that enforces a security invariant, unblocking what it suppressed.
gcp
CanModifyPolicyRemove iam.automaticIamGrantsForDefaultServiceAccounts to re-enable over-privileged default SAs on new resources.
gcp
CanModifyPolicyWeaken iam.allowedPolicyMemberDomains to allow granting roles to external identities.
gcp
CanModifyPolicyRemove storage.publicAccessPrevention to allow making Cloud Storage buckets public.
gcp
CanModifyPolicyRemove/weaken iam.disableServiceAccountKeyCreation to re-enable SA key creation.
gcp
CanModifyPolicyRemove iam.disableServiceAccountKeyUpload to allow binding an attacker keypair to an SA.
gcp
CanModifyPolicyRemove sql.restrictPublicIp to allow Cloud SQL instances to get a public IP.
gcp
CanModifyPolicyWeaken compute.vmExternalIpAccess to allow assigning public IPs to VMs (internet exposure).
gcp
CanModifyPolicyA principal who can modify or escape a guardrail (SCP / Org Policy / deny assignment) upgrades the edges that guardrail was suppressing from BLOCKED to their underlying state.
?cap