OrganizationPolicy

GCP org policy / governance constraint.

class: Policy

Realizing resources

gcp gcp

resourcescopeenumeraterequired permissions
gcp:orgpolicy:policy global orgpolicy.projects.policies.list orgpolicy.policies.list

Exposure sites

None.

Rules that touch OrganizationPolicy 12

Ability to write Azure Policy assignments/definitions at a management group scope lets a principal weaken or remove a deny-effect guardrail inherited by the subtree.
orgpolicy.policy.set over ANY enforced OrganizationPolicy that blocks a modeled edge = guardrail-removal capability over it.
Delete/alter a custom org-policy constraint that enforces a security invariant, unblocking what it suppressed.
Remove iam.automaticIamGrantsForDefaultServiceAccounts to re-enable over-privileged default SAs on new resources.
Weaken iam.allowedPolicyMemberDomains to allow granting roles to external identities.
Remove storage.publicAccessPrevention to allow making Cloud Storage buckets public.
Remove/weaken iam.disableServiceAccountKeyCreation to re-enable SA key creation.
Remove iam.disableServiceAccountKeyUpload to allow binding an attacker keypair to an SA.
Remove sql.restrictPublicIp to allow Cloud SQL instances to get a public IP.
Weaken compute.vmExternalIpAccess to allow assigning public IPs to VMs (internet exposure).
A principal who can modify or escape a guardrail (SCP / Org Policy / deny assignment) upgrades the edges that guardrail was suppressing from BLOCKED to their underlying state.
?cap
move · open · esc close