Skip to content

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.

Glossary term

allUsers and allAuthenticatedUsers

Special IAM principals meaning anyone on the Internet (allUsers) or anyone signed in to a Google account (allAuthenticatedUsers). They make resources public.

allUsers and allAuthenticatedUsers are special IAM members. allUsers means anyone on the Internet, authenticated or not; allAuthenticatedUsers means anyone signed in with any Google account, which in practice is also the whole Internet.

Adding either to a bucket, dataset, Cloud Run service, function or image policy makes the resource public. The grant is recorded in Admin Activity logs as a bindingDeltas entry with action: ADD, but subsequent anonymous reads of public Cloud Storage objects are not tracked by Cloud Audit Logs, so investigators have to reason in exposure windows. Public access prevention on Cloud Storage blocks these grants.

See GCS and BigQuery exfiltration: evidence in audit logs.

Glossary

This tool is not affiliated with, endorsed by or sponsored by Google LLC. Google Cloud and Google Cloud Platform are trademarks of Google LLC. Other names are trademarks of their respective owners.