Service Account Scopes and Custom Roles for Impersonate User
For more information on creating custom roles, refer to Creating and Assigning Custom Roles .
The following table lists the minimum requirements of Service Account Scopes and Custom Roles applied to an Impersonate User for the respective connector operations.
|
Connector Operation |
Service Account Scopes |
Impersonate User (Admin Account) |
|---|---|---|
|
Test Connection |
G-Suite
GCP
|
G-Suite
GCP
|
|
Refresh Account |
||
|
Account Aggregation |
||
|
Partitioning Aggregation |
||
|
Role related operations (Aggregate Role, Create Account/Enable/Disable/Change Password/Add and Remove) with Role |
|
Super Admin |
|
Group Aggregation |
G-Suite
GCP
|
G-Suite
GCP
|
|
Delete group |
|
|
|
Create and Update Group |
G-Suite
GCP
|
G-Suite
GCP
|
|
Create Account without Entitlement(s) |
G-Suite
GCP
|
G-Suite
GCP
|
|
Enable, Disable and Delete Account |
||
|
Update Account attribute(s) (For accounts without entitlement) |
||
|
Change Password |
||
|
Create Account with Entitlement(s) |
G-Suite
GCP
|
G-Suite
GCP
|
|
Add/Remove Entitlements |
||
|
Update Account attribute(s) (For accounts with entitlement) |
||
|
Delta Aggregation for Account |
G-Suite
GCP
|
G-Suite
GCP
|
|
Delta Aggregation for Group |
G-Suite
GCP
|
G-Suite
GCP
|
|
Delete Data Transfer |
|
|
|
Delegated Admins |
|
|
|
Agent Aggregation |
GCP
|
GCP
|
|
Aggregation for Folder and Project |
GCP
|
GCP
|
|
Aggregation for IAM Role |
GCP
|
GCP
|
|
Create/Update/Delete IAM Roles |
GCP
|
GCP
|
|
Aggregation for IAM Resource Permission |
GCP
|
GCP
|
|
To manage all operations on domain as Account type in GCP |
G-Suite
|
G-Suite
|