Soru

Zorluk: OrtaConfiguring Organization Policies and Resource Hierarchy Constraints

A cloud administration team needs to ensure that IAM roles within a specific organizational Folder can only be granted to user accounts belonging to their verified corporate Google Workspace domain. They want to prevent project owners within that Folder from adding external Gmail or third-party accounts to IAM policies. Which administrative action correctly enforces this restriction across all current and future projects inside the Folder?

  1. Apply the Domain Restricted Sharing Organization Policy constraint (constraints/iam.allowedPolicyMemberDomains) on the Folder node and specify the corporate Google Workspace Directory Customer ID.Cevap
  2. B
    Grant the Organization Policy Admin (roles/orgpolicy.policyAdmin) role on the Folder to all project owners so that their IAM changes are restricted to internal users.
  3. C
    Assign the Owner primitive role (roles/owner) at the Folder level to automatically filter external principal email addresses out of child project IAM policies.
  4. D
    Revoke IAM policy edit permissions on child projects, relying on inherited IAM policy restrictions from the parent Folder to block external bindings.

Cevap

Apply the Domain Restricted Sharing Organization Policy constraint on the target Folder node with the allowed corporate Directory Customer ID.
The correct approach configures the Domain Restricted Sharing Organization Policy constraint (`constraints/iam.allowedPolicyMemberDomains`) at the Folder level. Organization Policies establish constraints on resource configurations and propagate down the Google Cloud resource hierarchy to all child projects.

Adım Adım Çözüm

1
Identify the requirement
The goal is to restrict identity domains for IAM role assignments across all child resources under a specific Folder.
Organization Policies are designed to restrict configuration options across the resource hierarchy.
2
Select the appropriate constraint mechanism
Use the constraints/iam.allowedPolicyMemberDomains constraint.
This specific Organization Policy constraint evaluates IAM policy additions against allowed Google Workspace Directory Customer IDs.
3
Determine hierarchy placement
Set the policy configuration at the Folder node.
Organization policies applied at a Folder propagate down to all child folders and projects contained within it.

Anahtar Kavram

Organization Policies enforce resource hierarchy constraints (such as Domain Restricted Sharing) to restrict allowed configurations independently of IAM permission grants.
Tahmini Süre:1m 15s
Bu soruyu puanla