Service Account Scopes and Built-in Roles for Impersonate User
The following table lists the minimum requirements of Service Account Scopes and Built-in Roles applied to an Impersonate User for the respective connector operations:
Connector Operation |
Service Account Scopes |
Impersonate User |
---|---|---|
Test Connection |
|
No Role |
Role related operations(Aggregate Role, Add and Remove Role) |
|
Super Admin |
Create Account with Role |
|
Super Admin |
Refresh Account |
G-Suite
GCP
|
G-Suite User Management Admin, Groups Admin Cloud Asset Viewer, Service account user, Project IAM Admin, Folder IAM Admin, Organization Administrator (only required if organization level access managed), Service Account Admin, User Management, and Group Admin
|
Account Aggregation |
||
Create Account with Entitlement(s) |
||
Update Account attribute(s) (For accounts with entitlement) |
||
Add and Remove Entitlement(s) |
||
Partitioning Aggregation |
||
Group Aggregation |
G-Suite
GCP
|
G-Suite Group Admin Cloud Asset Viewer, Organization Administrator (only required if organization level access is managed), Service Account Admin, Folder IAM Admin, and Project IAM Admin
|
Create and Update Group |
G-Suite
GCP
|
|
Create Account without Entitlement(s) |
G-Suite
GCP
|
G-Suite User Management Admin, Super Admin (only required if managing domain as a user) GCP Service Account Admin
|
Enable, Disable, and Delete Account |
||
Update Account attribute(s) (For accounts without entitlement) |
||
Change Password |
||
Delta Aggregation for Account |
G-Suite
GCP
|
G-Suite User Management Admin, Groups Admin, Custom Role (Reports), Super Admin (only required if managing domain as a user)
GCP Cloud Asset Viewer |
Delta Aggregation for Group |
G-Suite
GCP
|
G-Suite Groups Admin and Custom Role (Reports)
GCP Cloud Asset Viewer |
Delete Data Transfer |
|
User Management, Group Admin, and Data Transfer |
DelegatedAdmins |
|
User Management, Group Admin, and Gmail (Settings) |
Aggregation for Folder and Project |
GCP
|
GCP Cloud Asset Viewer |
Aggregation for IAM Role |
GCP
|
GCP Cloud Asset Viewer and Organization Role Viewer |
Create, Update, and Delete IAM Roles |
GCP
|
GCP Organization Role Administrator |
IAM Resource Permission |
GCP
|
GCP Cloud Asset Viewer, Organization Role Viewer, Organization Administrator (only required if managing Organization level access), Service Account Admin, Folder IAM Admin, and Project IAM Admin |
To manage all operations on domain as Account type in GCP |
|
Super Admin |