Ensure resources are only shared with users whose email addresses match your Google Workspace domain and remove existing mismatched users without auditing every resource. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Set an organization policy constraint to limit identities by domain, and then retroactively remove existing mismatched users..
Why this is the answer
The most effective solution is to set an organization policy constraint to limit identities by domain. This policy, specifically constraints/iam.allowedPolicyMemberDomains, prevents new external identities from being added to IAM policies across your organization. After applying the policy, you must retroactively remove existing mismatched users. This two-step approach ensures both future compliance and addresses current violations. Creating Cloud Scheduler jobs to scan and delete users is inefficient and prone to errors. It requires custom scripting and may miss resources or fail to update all relevant IAM policies. Organization policies are designed for this exact purpose, offering a centralized and automated way to enforce security controls at scale.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed