<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Error while adding GCP account (permission denied) in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274373#M162</link>
    <description>&lt;P&gt;Not too sure what else it could be.&amp;nbsp; Ran a few tests to try different scenarios (key deleted from Service Account), but I could only get that message to reproduce if the Service Account did not have the necessary permissions on the project you are trying to onboard.&amp;nbsp; The only thing I can think of is that the permissions are added to a different project than the Service Account.&amp;nbsp; Is that the case here?&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 14:54:51 GMT</pubDate>
    <dc:creator>kchen</dc:creator>
    <dc:date>2019-07-02T14:54:51Z</dc:date>
    <item>
      <title>Error while adding GCP account (permission denied)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274187#M159</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV&gt;I am trying out RedLock using the trial and I am having issues trying to configure my GCP project. I followed the instructions carefully at&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/redlock/redlock-admin/connect-your-cloud-platform-to-redlock/onboard-your-gcp-account/set-up-gcp-account-for-redLock-service.html" target="_blank" rel="noopener"&gt;https://docs.paloaltonetworks.com/redlock/redlock-admin/connect-your-cloud-platform-to-redlock/onboard-your-gcp-account/set-up-gcp-account-for-redLock-service.html&lt;/A&gt;&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;I got permissions error. I even tried temporarily to add Project Owner and I still get the following error.&lt;/DIV&gt;&lt;DIV&gt;Any idea?&lt;/DIV&gt;&lt;DIV&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20523i3187A2AC83D7993A/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 02 Sep 2020 17:17:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274187#M159</guid>
      <dc:creator>FAllard</dc:creator>
      <dc:date>2020-09-02T17:17:18Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding GCP account (permission denied)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274194#M160</link>
      <description>&lt;P&gt;Could you post a screenshot of your Service Account's list of permissions?&amp;nbsp; Did you make sure to create a Custom Role that allows storage bucket access?&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jul 2019 14:38:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274194#M160</guid>
      <dc:creator>kchen</dc:creator>
      <dc:date>2019-07-01T14:38:37Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding GCP account (permission denied)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274342#M161</link>
      <description>&lt;P&gt;&lt;FONT face="verdana,geneva" size="3"&gt;See below. As you can see, I added a lot more roles in an attempt to make it work...&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-07-02 at 9.19.52 AM.png" style="width: 519px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20531i3600FAD5BE30161B/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-07-02 at 9.19.52 AM.png" alt="Screen Shot 2019-07-02 at 9.19.52 AM.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-07-02 at 9.21.08 AM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20532iD6F8D021CE4540D0/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-07-02 at 9.21.08 AM.png" alt="Screen Shot 2019-07-02 at 9.21.08 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 13:25:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274342#M161</guid>
      <dc:creator>FAllard</dc:creator>
      <dc:date>2019-07-02T13:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding GCP account (permission denied)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274373#M162</link>
      <description>&lt;P&gt;Not too sure what else it could be.&amp;nbsp; Ran a few tests to try different scenarios (key deleted from Service Account), but I could only get that message to reproduce if the Service Account did not have the necessary permissions on the project you are trying to onboard.&amp;nbsp; The only thing I can think of is that the permissions are added to a different project than the Service Account.&amp;nbsp; Is that the case here?&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 14:54:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274373#M162</guid>
      <dc:creator>kchen</dc:creator>
      <dc:date>2019-07-02T14:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding GCP account (permission denied)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274384#M163</link>
      <description>&lt;P&gt;I am not sure what you mean by that "&lt;SPAN&gt;the permissions are added to a different project than the Service Account". The permissions are added to a Service Account that is part of a project. I import the Service Account Key (JSON) which contains the project information. Nowhere in RedLock I specify a project or do I assign permissions in the project outside of the service account.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 15:22:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274384#M163</guid>
      <dc:creator>FAllard</dc:creator>
      <dc:date>2019-07-02T15:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding GCP account (permission denied)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274409#M164</link>
      <description>&lt;P&gt;Just as a check, if you remove the extra permissions you added, does it throw the 'Permission denied" error again? Keeping only the 3 required permissions:&lt;/P&gt;
&lt;OL class="ol substeps"&gt;
&lt;LI class="li substep"&gt;&lt;SPAN class="ph cmd"&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Project&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Viewer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="li substep"&gt;&lt;SPAN class="ph cmd"&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Custom&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;RedLock Viewer&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI class="li substep"&gt;&lt;SPAN class="ph cmd"&gt;&lt;SPAN class="ph menucascade"&gt;&lt;SPAN class="ph uicontrol"&gt;Compute Engine&lt;/SPAN&gt;&lt;SPAN class="ph uicontrol"&gt;Compute Security Admin&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Tue, 02 Jul 2019 16:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274409#M164</guid>
      <dc:creator>lpingali</dc:creator>
      <dc:date>2019-07-02T16:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: Error while adding GCP account (permission denied)</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274428#M165</link>
      <description>&lt;P&gt;That's the first thing I tried since I followed the instructions. I tried again and I get the same error. See my service account roles below:&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screen Shot 2019-07-02 at 1.33.36 PM.png" style="width: 999px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/20538i0A5B2A76ECD634AC/image-size/large/is-moderation-mode/true?v=v2&amp;amp;px=999" role="button" title="Screen Shot 2019-07-02 at 1.33.36 PM.png" alt="Screen Shot 2019-07-02 at 1.33.36 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 17:35:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/error-while-adding-gcp-account-permission-denied/m-p/274428#M165</guid>
      <dc:creator>FAllard</dc:creator>
      <dc:date>2019-07-02T17:35:45Z</dc:date>
    </item>
  </channel>
</rss>

