Your company is using Google Cloud. You have two folders under the Organization: Finance and Shopping. The members of the development team are in a Google Group. The development team group has been assigned the Project Owner role on the Organization. You want to prevent the development team from creating resources in projects in the Finance folder. What should you do?
https://cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy
'Roles are always inherited, and there is no way to explicitly remove a permission for a lower-level resource that is granted at a higher level in the resource hierarchy. Given the above example, even if you were to remove the Project Editor role from Bob on the 'Test GCP Project', he would still inherit that role from the 'Dept Y' folder, so he would still have the permissions for that role on 'Test GCP Project'.'
Currently there are no comments in this discussion, be the first to comment!