GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit

Get admin/cloud-identity query on MFA set on specific accounts - break/glass and root/super-admin - for GR 1 CaC

Open
#270 0 comments 0 reactions 1 assignee Claimed by @fmichaelobrien View on GitHub
Dominant language
Shell
Stars
36
Forks
26
PR merge metrics
No merged PRs in 30d

Description

see also #252

Query MFA field on/off only for workspace/cloud-identity BG/super admin account (federated IdP MFA can be ignored)

Get admin/cloud-identity query on MFA set on specific accounts - break/glass and root/super-admin - for GR 1 CaC
https://github.com/canada-ca/cloud-guardrails/blob/master/EN/00_Applicable-Scope.md#applicability-of-guardrails-to-cloud-usage-profiles

Need to query root/BG/SA account for MFA (workspace or cloud identity) either directly or via admin
We don't need to check IdP federated MFA - just the BG/SA accounts

From Maninder
https://developers.google.com/admin-sdk/directory/reference/rest/v1/users/list
https://developers.google.com/admin-sdk/directory/v1/guides/search-users

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.