More Info:

Administrator access also brings risk with them. Try to have minimum admins in your account.\

Risk Level

High

Address

Security

Compliance Standards

CISGCP,HIPAA,SCO2,NISTCSF,NIST,AWSWAF,ISO27001,HITRUST

Triage and Remediation

Remediation

To remediate the misconfiguration of users with Administrator Access in GCP, follow these steps using the GCP console:

  1. Log in to the GCP console (https://console.cloud.google.com/) using your GCP account with appropriate permissions.

  2. Navigate to the IAM & Admin page by clicking on the “IAM & Admin” option in the left-hand menu.

  3. On the IAM & Admin page, you will see a list of all the users, service accounts, and groups with their associated roles and permissions.

  4. Identify the user(s) with Administrator Access by reviewing the roles assigned to each user. The user(s) with the “Owner” role or any custom role granting full administrative privileges should be identified.

  5. Select the user(s) with Administrator Access by clicking on the checkbox next to their name(s).

  6. Click on the “Remove” button at the top of the page to remove the selected user(s) from the Administrator role.

  7. In the confirmation dialog box, review the changes and click on the “Remove” button to confirm the removal. Note that removing a user from the Administrator role will revoke their administrative privileges.

  8. After removing the user(s) from the Administrator role, it is recommended to assign them appropriate roles based on their responsibilities and least privilege principle. Click on the “Add” button at the top of the page to add roles for the user(s).

  9. In the “Add members” dialog box, enter the email address of the user(s) and select the appropriate role(s) from the list. Roles such as “Project Editor”, “Project Viewer”, or custom roles with restricted permissions can be assigned based on the user’s requirements.

  10. Click on the “Save” button to assign the selected role(s) to the user(s).

  11. Review the changes on the IAM & Admin page to ensure that the user(s) no longer have Administrator Access and have been assigned appropriate roles.

By following these steps, you will be able to remediate the misconfiguration of users with Administrator Access in GCP using the GCP console.