How to Block Project Access for a Given User or Group in GCP
How to Block Project Access for a Given User or Group in GCP
Learn how to block user or group access to a GCP project during a security event using the GCP Console and CLI in our step-by-step guide.
Published September 24, 2024 • 5 min read
In Google Cloud Platform (GCP), you can control access to your projects with a combination of roles and policies. If you need to block project access to a GCP user or group, you need to update policies on the fly.
How to Get All IAM Policies for a GCP Project
First, it can be helpful to get information on all the policies and roles associated with a certain project.
Using the Console:
- Visit GCP console: https://console.cloud.google.com
- Click on the Select a project button, and find the project or folder you want to view the IAM policies for.
- Click on the navigation menu and select IAM and Admin.
- You will see a list of every member/principal along with their respective project roles. Principals who inherited roles from parent resources are also shown on this list.
- The details of a specific policy can be viewed by clicking on the member's name.
- If you have a large number of policies, use the search feature to locate the one you are looking for.
Using the CLI:
Run the following get-iam-policy command to see all IAM policies:
gcloud RESOURCE_TYPE get-iam-policy <RESOURCE_ID> --<FORMAT>=format > PATH
- RESOURCE_TYPE: This is the type of resource you want to see, such as projects, folders, or organizations.
- RESOURCE_ID: It is the ID of the GCP project, folder, or organization you want to retrieve the IAM policies for. Project IDs are always alphanumeric, like this-project1. Meanwhile, organization and folder IDs are numeric, like 1231998.
- FORMAT: You can use yaml or json as your desired format.
- PATH: It specifies the path to a new policy output file. In the following example, the policy for the project is obtained and saved in JSON format to your home directory
The final command would look like this:
gcloud projects get-iam-policy this-project1 --format=json > ~/policy.json
The output will be the IAM policy for the project you specified.
Checking if a Specific Principal Has a Certain Role
Next, you can check if a specific user or principal has access to this project and what roles they have.
Using the Console:
To check if a specific principal (e.g. a user, a group, a service account, etc.) has a particular role in a GCP, follow these steps:
- Visit Google Cloud Console and select the project that you want to check.
- Visit IAM & Admin from the hamburger menu.
- Select the PERMISSIONS tab, and then click VIEW BY PRINCIPALS. You will see a list of all the principals that have been granted roles in this project.
- You will see Filter under the VIEW BY PRINCIPALS tab. Click on it and select Role from the menu. Next, choose Type and select the kind you are looking for, such as Service Account. Click enter and now the IAM console will show you principals with the Service Account role.
Using the gCloud CLI:
Follow these steps to check if a specific principal has a particular role in a GCP:
- Run the projects list command using custom query filters to list the IDs of the projects in your GCP account. The command is:
gcloud projects list --format="table(projectId)"
- Now, use the get-iam-policy command with the GCP project ID you want to check to describe IAM policy in JSON format. The command:
gcloud projects get-iam-policy <PROJECT_ID> --format=json
How To Remove the Principal from the IAM Policy Role Binding to Block Their Access
Using the Console:
Follow these steps to block GCP project access to a User or Group:
- Go to the Google Cloud Console and select the project from which you want to remove the principal.
- Go to the IAM & admin menu and select IAM.
- Click on the PERMISSIONS tab, and select View by Principals to see every member's account made for the GCP project you have selected.
- Find the role you want to delete from the selected member account, like Service Account User, or Service Account Token Creator on the Edit permissions panel. Once you have identified it, click on the delete icon (it is next to each role) to remove the role.
- To save the changes, click SAVE. It will remove the principal from the IAM Policy Role Binding, and they will no longer have access to the project.
Using the gCloud CLI:
Follow these steps to block GCP project access:
- Run projects get-iam-policy command using the GCP project ID you wish to reconfigure to find the IAM policy made for this project:
gcloud projects get-iam-policy <PROJECT_ID> --format=json
- Edit the policy that was returned at the previous step and delete the role binding with the name roles/iam.serviceAccountUser and roles/iam.serviceAccountTokenCreator for members made for the selected project.
- Save the policy document as new-gcp-iam-policy.json in a JSON file:
"bindings": [
{
"members": [
"user:cloud.realisation@gmail.com"
],
"role": "roles/editor"
},
{
"members": [
"user:cloud.conformity@gmail.com"
],
"role": "roles/owner"
}
],
"etag": "abcdabcdabcd",
"version": 1
- Now, update the IAM policy by running set-iam-policy command with policy reconfigured at the previous step:
gcloud projects set-iam-policy <PROJECT_ID> new-gcp-iam-policy.json
Now, you’ve blocked certain users from the roles they previously had.
Blocking Project Access with a Blink Automation
Taking the steps to remove someone’s access to a project is time-consuming, but there are circumstances where urgency is important. If someone’s account is compromised or if they may be exfiltrating data, you would want to quickly be able to block them until you have more information or have resolved an incident.