<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: API access ? in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/API-access/m-p/355#M103</link>
    <description>&lt;P&gt;Yup, that's perfectly doable, and it only really needs to be done before deleting an important user account, as ownership needs to be transferred first, else&amp;nbsp;&lt;EM&gt;it should&lt;/EM&gt; disappear along with the owner.&lt;/P&gt;&lt;P&gt;&lt;A title="GCP Resource Manager interface" href="https://console.cloud.google.com/cloud-resource-manager" target="_blank" rel="noopener"&gt;GCP Resource Manager interface&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;There any superadmin can give themselves access to anything else, by assigning &lt;A title="IAM roles" href="https://cloud.google.com/iam/docs/conditions-overview?hl=en_GB" target="_blank" rel="noopener"&gt;IAM roles&lt;/A&gt; to themselves, so called &lt;A title="Principals" href="https://cloud.google.com/iam/docs/overview?hl=en_GB#concepts_related_identity" target="_blank" rel="noopener"&gt;Principals&lt;/A&gt;, for the entire domain.&amp;nbsp;I usually make sure to have these, meaning I can do most things.&lt;/P&gt;&lt;P&gt;Organisation Administrator,&amp;nbsp;Project Creator, Storage Admin,&amp;nbsp;Folder Admin.&lt;/P&gt;&lt;P&gt;You should really read closely what each role can do, as sometimes you need a lesser role to do something even though being "admin" sounds better.&lt;/P&gt;&lt;P&gt;But there's also an &lt;A title="Interactive guide on how to secure your GCP" href="https://console.cloud.google.com/cloud-setup/overview" target="_blank" rel="noopener"&gt;very extensive interactive guide on how to secure your GCP&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I can definitely recommend walking through that, and do most of what is suggested.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Owner&lt;/EM&gt; is of course necessary for things that should not be removed. But it&amp;nbsp;&lt;EM&gt;may&lt;/EM&gt; require that ownership is removed from the user that created it. Else the entire thing needs to re-created with another account.&lt;/P&gt;&lt;P&gt;So, for super-important stuff, I recommend creating and owning them with a "utility" account, an account which isn't really a person, but which is only ever&amp;nbsp;&lt;EM&gt;managed&lt;/EM&gt; by a single person at the time.&lt;/P&gt;&lt;P&gt;Never ever not-ever share credentials to an account.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Jul 2023 22:15:23 GMT</pubDate>
    <dc:creator>Kim_Nilsson</dc:creator>
    <dc:date>2023-07-10T22:15:23Z</dc:date>
    <item>
      <title>API access ?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/API-access/m-p/354#M102</link>
      <description>&lt;P&gt;I have a question about the managment site&amp;nbsp;&lt;A href="https://console.cloud.google.com/" target="_blank" rel="noopener"&gt;https://console.cloud.google.com/&lt;/A&gt;. We get in there from time to time to add SSO etc. Usually I do them but another admin went in and it turns out I can only seee the ones I've created he can only see any hes created etc. Is there any way in here permissions wise we can make it so all admins can see the API settings for each project? If I leave they basically have to leave my account forever.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 20:30:55 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/API-access/m-p/354#M102</guid>
      <dc:creator>jasoncrcsd</dc:creator>
      <dc:date>2023-07-10T20:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: API access ?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/API-access/m-p/355#M103</link>
      <description>&lt;P&gt;Yup, that's perfectly doable, and it only really needs to be done before deleting an important user account, as ownership needs to be transferred first, else&amp;nbsp;&lt;EM&gt;it should&lt;/EM&gt; disappear along with the owner.&lt;/P&gt;&lt;P&gt;&lt;A title="GCP Resource Manager interface" href="https://console.cloud.google.com/cloud-resource-manager" target="_blank" rel="noopener"&gt;GCP Resource Manager interface&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;There any superadmin can give themselves access to anything else, by assigning &lt;A title="IAM roles" href="https://cloud.google.com/iam/docs/conditions-overview?hl=en_GB" target="_blank" rel="noopener"&gt;IAM roles&lt;/A&gt; to themselves, so called &lt;A title="Principals" href="https://cloud.google.com/iam/docs/overview?hl=en_GB#concepts_related_identity" target="_blank" rel="noopener"&gt;Principals&lt;/A&gt;, for the entire domain.&amp;nbsp;I usually make sure to have these, meaning I can do most things.&lt;/P&gt;&lt;P&gt;Organisation Administrator,&amp;nbsp;Project Creator, Storage Admin,&amp;nbsp;Folder Admin.&lt;/P&gt;&lt;P&gt;You should really read closely what each role can do, as sometimes you need a lesser role to do something even though being "admin" sounds better.&lt;/P&gt;&lt;P&gt;But there's also an &lt;A title="Interactive guide on how to secure your GCP" href="https://console.cloud.google.com/cloud-setup/overview" target="_blank" rel="noopener"&gt;very extensive interactive guide on how to secure your GCP&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I can definitely recommend walking through that, and do most of what is suggested.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Owner&lt;/EM&gt; is of course necessary for things that should not be removed. But it&amp;nbsp;&lt;EM&gt;may&lt;/EM&gt; require that ownership is removed from the user that created it. Else the entire thing needs to re-created with another account.&lt;/P&gt;&lt;P&gt;So, for super-important stuff, I recommend creating and owning them with a "utility" account, an account which isn't really a person, but which is only ever&amp;nbsp;&lt;EM&gt;managed&lt;/EM&gt; by a single person at the time.&lt;/P&gt;&lt;P&gt;Never ever not-ever share credentials to an account.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jul 2023 22:15:23 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/API-access/m-p/355#M103</guid>
      <dc:creator>Kim_Nilsson</dc:creator>
      <dc:date>2023-07-10T22:15:23Z</dc:date>
    </item>
  </channel>
</rss>

