How to Securely Delegate Organization Policy Access?

Identity & Access Management
Answer Correct answer: C — Create an org-level tag for target folders and use an IAM condition to restrict org policy admin access to those tagged resources.

You are managing a Google Cloud environment that is organized into folders that represent different teams. These teams need the flexibility to modify organization policies relevant to their work. You want to grant the teams the necessary permissions while upholding Google-recommended security practices and minimizing administrative complexity. What should you do?

  1. Create a custom IAM role with the organization policy administrator permission and grant the permission to each team’s folder. Limit policy modifications based on folder names within the custom role’s definition.
  2. Assign the organization policy administrator role to a central service account and provide teams with the credentials to use the service account when needed.
  3. Create an organization-level tag. Attach the tag to relevant folders. Use an IAM condition to restrict the organization policy administrator role to resources with that tag. Correct Answer
  4. Grant each team the organization policy administrator role at the organization level.

Community Votes

C
50%
A
50%

50% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your ability to apply IAM conditions with organizational tags for granular, dynamic access control instead of static custom roles or overly broad permissions.

Learn how to securely delegate organization policy management to specific teams using IAM conditions and organizational tags. This page confirms that scoped tagging is the optimal approach for flexible, auditable policy administration.

Many candidates choose custom IAM roles assuming they can filter by folder name, but role definitions are static and cannot evaluate resource attributes at runtime.

Community Discussion (3 comments)

p981pa123 👍 1 Selected: A
Tags in Google Cloud are primarily designed for organizing and categorizing resources.While it's possible to create IAM conditions that reference tags (e.g., limiting the use of a role to resources with specific tags), this method is not the most intuitive or straightforward way to manage IAM policies, especially when the main goal is to provide flexible policy management for different teams. In your case, folder-based isolation with custom IAM roles is a cleaner and more intuitive way to achieve team-level control over organization policies
json4u 👍 1 Selected: C
It's C.
abdelrahman89 👍 2
C - Granular Control: Creating an organization-level tag allows you to precisely control which teams have access to modify organization policies by attaching the tag to relevant folders. This ensures that only authorized teams can make changes. IAM Condition: Using an IAM condition to restrict the organization policy administrator role to resources with the tag provides a flexible and efficient way to grant permissions while maintaining control. This ensures that the role is only accessible for the intended teams. Security Best Practices: This approach aligns with Google-recommended security practices by limiting access to organization policies to authorized teams and using IAM conditions to enforce appropriate controls. Administrative Efficiency: This approach simplifies administration by providing a centralized mechanism for managing permissions and ensuring that only authorized teams can modify organization policies.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C correctly applies Google Cloud's recommended pattern for scoped administrative access. By creating an organization-level tag and attaching it to specific folders, you establish a clear boundary for policy management. Applying an IAM condition to the organization policy administrator role ensures that only users interacting with tagged resources can modify policies, enforcing least privilege without manual role proliferation. This dynamic approach scales efficiently as new folders are added to the environment.

Why the Other Options Are Wrong

Option A incorrectly assumes custom IAM roles can evaluate runtime attributes like folder names; role definitions are strictly static and cannot perform conditional filtering. Option B violates fundamental security practices by requiring teams to share centralized service account credentials, which destroys individual accountability and auditability. Option D grants blanket organization-wide permissions, completely ignoring the principle of least privilege and exposing all folders to unauthorized changes.

Community Comment Notes

Several learners debated between options A and C, reflecting a common hesitation about adopting IAM conditions for routine administration. One candidate noted that "this method is not the most intuitive" for policy management, yet Google's architecture explicitly favors dynamic conditions over maintaining dozens of static custom roles. Another user emphasized that granular control through tagging prevents accidental cross-folder policy overrides, aligning perfectly with professional security engineering standards. The consensus ultimately reinforces that conditional access yields better auditability and lower long-term administrative overhead.

Official Reference

Exam Strategy

Always prioritize IAM conditions over custom roles when dynamic resource-based scoping is required, and never share service account credentials for delegated administration.

Frequently Asked Questions

Why can't custom roles filter by folder names?

Custom IAM role definitions are static and cannot evaluate dynamic resource attributes like folder paths at runtime. IAM conditions are required for runtime filtering.

Is sharing a central service account acceptable?

No. Sharing credentials violates least privilege and breaks audit trails. Delegated access should use distinct identities or workload identity federation.

Related Analysis

← Back to PCSE Study Guide