deniedPrincipals property

List<String>? deniedPrincipals
getter/setter pair

The identities that are prevented from using one or more permissions on Google Cloud resources.

This field can contain the following values: * principal://goog/subject/{email_id}: A specific Google Account. Includes Gmail, Cloud Identity, and Google Workspace user accounts. For example, principal://goog/subject/ * principal://{service_account_id}: A Google Cloud service account. For example, principal://

  • principalSet://goog/group/{group_id}: A Google group. For example, principalSet://goog/group/ * principalSet://goog/public:all: A special identifier that represents any principal that is on the internet, even if they do not have a Google Account or are not logged in. * principalSet://goog/cloudIdentityCustomerId/{customer_id}: All of the principals associated with the specified Google Workspace or Cloud Identity customer ID. For example, principalSet://goog/cloudIdentityCustomerId/C01Abc35. * principal://{pool_id}/subject/{subject_attribute_value}: A single identity in a workforce identity pool. * principalSet://{pool_id}/group/{group_id}: All workforce identities in a group. * principalSet://{pool_id}/attribute.{attribute_name}/{attribute_value}: All workforce identities with a specific attribute value. * principalSet://{pool_id} / * : All identities in a workforce identity pool. * principal://{project_number}/locations/global/workloadIdentityPools/{pool_id}/subject/{subject_attribute_value}: A single identity in a workload identity pool. * principalSet://{project_number}/locations/global/workloadIdentityPools/{pool_id}/group/{group_id}: A workload identity pool group. * principalSet://{project_number}/locations/global/workloadIdentityPools/{pool_id}/attribute.{attribute_name}/{attribute_value}: All identities in a workload identity pool with a certain attribute. * principalSet://{project_number}/locations/global/workloadIdentityPools/{pool_id} / * : All identities in a workload identity pool. * deleted:principal://goog/subject/{email_id}?uid={uid}: A specific Google Account that was deleted recently. For example, deleted:principal://goog/subject/ If the Google Account is recovered, this identifier reverts to the standard identifier for a Google Account. * deleted:principalSet://goog/group/{group_id}?uid={uid}: A Google group that was deleted recently. For example, deleted:principalSet://goog/group/ If the Google group is restored, this identifier reverts to the standard identifier for a Google group. * deleted:principal://{service_account_id}?uid={uid}: A Google Cloud service account that was deleted recently. For example, deleted:principal:// If the service account is undeleted, this identifier reverts to the standard identifier for a service account. * deleted:principal://{pool_id}/subject/{subject_attribute_value}: Deleted single identity in a workforce identity pool. For example, deleted:principal://


core.List<core.String>? deniedPrincipals;