<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Previously needed permission when onboarding GCP project on Prisma Cloud in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514097#M655</link>
    <description>&lt;P&gt;Hello AmyYoon,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;Minimum&amp;nbsp;permissions required:
&lt;DIV&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Viewer—Primitive role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Prisma&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Cloud&lt;SPAN&gt;&amp;nbsp;Viewer—Custom role. Prisma&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Cloud&lt;SPAN&gt;&amp;nbsp;needs this custom role to grant&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;cloud&lt;SPAN&gt;&amp;nbsp;storage bucket permission to read storage bucket metadata and update bucket IAM policies. This role requires storage.buckets.get to retrieve your list of storage buckets, and storage.buckets.getIampolicy to retrieve the IAM policy for the specified bucket.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Compute Security Admin—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. An optional privilege that is required only if you want to enable auto-remediation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;O&lt;STRONG&gt;rganization Role Viewer—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. This role is required for&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;onboarding&lt;SPAN&gt;&amp;nbsp;a&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP&lt;SPAN&gt;&amp;nbsp;Organization.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Dataflow Admin—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. An optional privilege that is required for dataflow log compression using the Dataflow service. See&amp;nbsp;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html#idd17cd38a-ea89-495d-9c2e-ad67ac646d16" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html%23idd17cd38a-ea89-495d-9c2e-ad67ac646d16&amp;amp;source=gmail&amp;amp;ust=1662572873997000&amp;amp;usg=AOvVaw2LnPXS0h8HkcJ8o4dn-0ma"&gt;Flow Log Compression&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP&amp;nbsp;for details.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;STRONG&gt;Folder Viewer—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. An optional privilege that is required only if you want to onboard&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP&lt;SPAN&gt;&amp;nbsp;Folder metadata, select specific folders—include or exclude folders—, and to automatically create account groups based&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;the folder hierarchy.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud&amp;amp;source=gmail&amp;amp;ust=1662572873997000&amp;amp;usg=AOvVaw0nvhn1Gh-z04pTTd0pUSub"&gt;https://docs.paloaltonetworks.&lt;WBR /&gt;com/prisma/prisma-&lt;SPAN class=""&gt;cloud/&lt;WBR /&gt;prisma-&lt;SPAN class=""&gt;cloud-admin/connect-&lt;WBR /&gt;your-&lt;SPAN class=""&gt;cloud-&lt;SPAN class=""&gt;platform-to-prisma-&lt;WBR /&gt;&lt;SPAN class=""&gt;cloud/onboard-your-&lt;SPAN class=""&gt;gcp-&lt;WBR /&gt;account/set-up-&lt;SPAN class=""&gt;gcp-account-&lt;WBR /&gt;for-prisma-&lt;SPAN class=""&gt;cloud&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 06 Sep 2022 19:06:24 GMT</pubDate>
    <dc:creator>MDavis29</dc:creator>
    <dc:date>2022-09-06T19:06:24Z</dc:date>
    <item>
      <title>Previously needed permission when onboarding GCP project on Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/513806#M649</link>
      <description>&lt;P&gt;Hello everyone.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have some queries about&amp;nbsp;permission previously when onboarding GCP project on Prisma Cloud.&lt;/P&gt;
&lt;P&gt;I have given 5 roles below to the user who is used to onboard the GCP project.&lt;/P&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;1) Role Administrator&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;2) Security Admin&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;3) Service Account Admin&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;4) Service Account Key Admin&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&lt;STRONG&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&amp;nbsp;5) Viewer&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;P&gt;Is there any minimum permission needed to be able to onboard this cloud account?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope you please kindly check this.&lt;/P&gt;
&lt;P&gt;Thank you:)&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Fri, 02 Sep 2022 07:41:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/513806#M649</guid>
      <dc:creator>AmyYoon</dc:creator>
      <dc:date>2022-09-02T07:41:13Z</dc:date>
    </item>
    <item>
      <title>Re: Previously needed permission when onboarding GCP project on Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514068#M651</link>
      <description>&lt;P&gt;AmyYoon,&lt;/P&gt;
&lt;P&gt;Please see below my comments on the minimum permissions needed to on-board a GCP cloud account.&lt;/P&gt;
&lt;DIV&gt;Minimum&amp;nbsp;permissions required:&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Viewer&lt;/STRONG&gt;—Primitive role on GCP.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Prisma Cloud Viewer&lt;/STRONG&gt;—Custom role. Prisma Cloud needs this custom role to grant cloud storage bucket permission to read storage bucket metadata and update bucket IAM policies. This role requires storage.buckets.get to retrieve your list of storage buckets, and storage.buckets.getIampolicy to retrieve the IAM policy for the specified bucket.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Compute Security Admin&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required only if you want to enable auto-remediation.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;O&lt;STRONG&gt;rganization Role Viewer&lt;/STRONG&gt;—Predefined role on GCP. This role is required for onboarding a GCP Organization.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Dataflow Admin&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required for dataflow log compression using the Dataflow service. See&amp;nbsp;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html#idd17cd38a-ea89-495d-9c2e-ad67ac646d16" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html%23idd17cd38a-ea89-495d-9c2e-ad67ac646d16&amp;amp;source=gmail&amp;amp;ust=1662564638069000&amp;amp;usg=AOvVaw0oq1sr-PMLthvAC8WrmTbQ"&gt;Flow Log Compression on GCP&lt;/A&gt;&amp;nbsp;for details.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Folder Viewer&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required only if you want to onboard GCP Folder metadata, select specific folders—include or exclude folders—, and to automatically create account groups based on the folder hierarchy.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud&amp;amp;source=gmail&amp;amp;ust=1662564638069000&amp;amp;usg=AOvVaw09xANtu_mLUt4KpQMghP9i"&gt;https://docs.paloaltonetworks.&lt;WBR /&gt;com/prisma/prisma-cloud/&lt;WBR /&gt;prisma-cloud-admin/connect-&lt;WBR /&gt;your-cloud-platform-to-prisma-&lt;WBR /&gt;cloud/onboard-your-gcp-&lt;WBR /&gt;account/set-up-gcp-account-&lt;WBR /&gt;for-prisma-cloud&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Sep 2022 15:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514068#M651</guid>
      <dc:creator>MDavis29</dc:creator>
      <dc:date>2022-09-06T15:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Previously needed permission when onboarding GCP project on Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514073#M652</link>
      <description>&lt;DIV&gt;Minimum&amp;nbsp;permissions required:&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Viewer&lt;/STRONG&gt;—Primitive role on GCP.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Prisma Cloud Viewer&lt;/STRONG&gt;—Custom role. Prisma Cloud needs this custom role to grant cloud storage bucket permission to read storage bucket metadata and update bucket IAM policies. This role requires storage.buckets.get to retrieve your list of storage buckets, and storage.buckets.getIampolicy to retrieve the IAM policy for the specified bucket.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Compute Security Admin&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required only if you want to enable auto-remediation.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;O&lt;STRONG&gt;rganization Role Viewer&lt;/STRONG&gt;—Predefined role on GCP. This role is required for onboarding a GCP Organization.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Dataflow Admin&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required for dataflow log compression using the Dataflow service. See&amp;nbsp;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html#idd17cd38a-ea89-495d-9c2e-ad67ac646d16" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html%23idd17cd38a-ea89-495d-9c2e-ad67ac646d16&amp;amp;source=gmail&amp;amp;ust=1662564638069000&amp;amp;usg=AOvVaw0oq1sr-PMLthvAC8WrmTbQ"&gt;Flow Log Compression on GCP&lt;/A&gt;&amp;nbsp;for details.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Folder Viewer&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required only if you want to onboard GCP Folder metadata, select specific folders—include or exclude folders—, and to automatically create account groups based on the folder hierarchy.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud&amp;amp;source=gmail&amp;amp;ust=1662564638069000&amp;amp;usg=AOvVaw09xANtu_mLUt4KpQMghP9i"&gt;https://docs.paloaltonetworks.&lt;WBR /&gt;com/prisma/prisma-cloud/&lt;WBR /&gt;prisma-cloud-admin/connect-&lt;WBR /&gt;your-cloud-platform-to-prisma-&lt;WBR /&gt;cloud/onboard-your-gcp-&lt;WBR /&gt;account/set-up-gcp-account-&lt;WBR /&gt;for-prisma-cloud&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Sep 2022 16:32:49 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514073#M652</guid>
      <dc:creator>MDavis29</dc:creator>
      <dc:date>2022-09-06T16:32:49Z</dc:date>
    </item>
    <item>
      <title>Re: Previously needed permission when onboarding GCP project on Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514075#M653</link>
      <description>&lt;P&gt;Hello AmyYoon,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;On-board the account and select&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;monitor&lt;/STRONG&gt;&lt;SPAN&gt;, this will provide the&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;bare minimum&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;permissions&lt;/SPAN&gt;&lt;/P&gt;
&lt;DIV&gt;Minimum&amp;nbsp;permissions required:&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Viewer&lt;/STRONG&gt;—Primitive role on GCP.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Prisma Cloud Viewer&lt;/STRONG&gt;—Custom role. Prisma Cloud needs this custom role to grant cloud storage bucket permission to read storage bucket metadata and update bucket IAM policies. This role requires storage.buckets.get to retrieve your list of storage buckets, and storage.buckets.getIampolicy to retrieve the IAM policy for the specified bucket.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Compute Security Admin&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required only if you want to enable auto-remediation.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;O&lt;STRONG&gt;rganization Role Viewer&lt;/STRONG&gt;—Predefined role on GCP. This role is required for onboarding a GCP Organization.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Dataflow Admin&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required for dataflow log compression using the Dataflow service. See&amp;nbsp;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html#idd17cd38a-ea89-495d-9c2e-ad67ac646d16" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html%23idd17cd38a-ea89-495d-9c2e-ad67ac646d16&amp;amp;source=gmail&amp;amp;ust=1662568600306000&amp;amp;usg=AOvVaw24JLL8Cz2lrkscyVdaOfq1"&gt;Flow Log Compression on GCP&lt;/A&gt;&amp;nbsp;for details.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Folder Viewer&lt;/STRONG&gt;—Predefined role on GCP. An optional privilege that is required only if you want to onboard GCP Folder metadata, select specific folders—include or exclude folders—, and to automatically create account groups based on the folder hierarchy.&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud&amp;amp;source=gmail&amp;amp;ust=1662568600306000&amp;amp;usg=AOvVaw3d9NFaoXcOTBs0EC6B0x8p"&gt;https://docs.paloaltonetworks.&lt;WBR /&gt;com/prisma/prisma-cloud/&lt;WBR /&gt;prisma-cloud-admin/connect-&lt;WBR /&gt;your-cloud-platform-to-prisma-&lt;WBR /&gt;cloud/onboard-your-gcp-&lt;WBR /&gt;account/set-up-gcp-account-&lt;WBR /&gt;for-prisma-cloud&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Sep 2022 16:38:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514075#M653</guid>
      <dc:creator>MDavis29</dc:creator>
      <dc:date>2022-09-06T16:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Previously needed permission when onboarding GCP project on Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514097#M655</link>
      <description>&lt;P&gt;Hello AmyYoon,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV&gt;Minimum&amp;nbsp;permissions required:
&lt;DIV&gt;
&lt;DIV&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Viewer—Primitive role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Prisma&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Cloud&lt;SPAN&gt;&amp;nbsp;Viewer—Custom role. Prisma&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;Cloud&lt;SPAN&gt;&amp;nbsp;needs this custom role to grant&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;cloud&lt;SPAN&gt;&amp;nbsp;storage bucket permission to read storage bucket metadata and update bucket IAM policies. This role requires storage.buckets.get to retrieve your list of storage buckets, and storage.buckets.getIampolicy to retrieve the IAM policy for the specified bucket.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Compute Security Admin—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. An optional privilege that is required only if you want to enable auto-remediation.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;O&lt;STRONG&gt;rganization Role Viewer—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. This role is required for&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;onboarding&lt;SPAN&gt;&amp;nbsp;a&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP&lt;SPAN&gt;&amp;nbsp;Organization.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;Dataflow Admin—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. An optional privilege that is required for dataflow log compression using the Dataflow service. See&amp;nbsp;&lt;A title="" href="https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html#idd17cd38a-ea89-495d-9c2e-ad67ac646d16" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/content/techdocs/en_US/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/dataflow-compression.html%23idd17cd38a-ea89-495d-9c2e-ad67ac646d16&amp;amp;source=gmail&amp;amp;ust=1662572873997000&amp;amp;usg=AOvVaw2LnPXS0h8HkcJ8o4dn-0ma"&gt;Flow Log Compression&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP&amp;nbsp;for details.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&lt;STRONG&gt;&lt;STRONG&gt;Folder Viewer—Predefined role&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP. An optional privilege that is required only if you want to onboard&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;GCP&lt;SPAN&gt;&amp;nbsp;Folder metadata, select specific folders—include or exclude folders—, and to automatically create account groups based&lt;SPAN&gt;&amp;nbsp;&lt;SPAN class=""&gt;on&lt;SPAN&gt;&amp;nbsp;the folder hierarchy.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;
&lt;DIV&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud" target="_blank" rel="noopener" data-saferedirecturl="https://www.google.com/url?q=https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud&amp;amp;source=gmail&amp;amp;ust=1662572873997000&amp;amp;usg=AOvVaw0nvhn1Gh-z04pTTd0pUSub"&gt;https://docs.paloaltonetworks.&lt;WBR /&gt;com/prisma/prisma-&lt;SPAN class=""&gt;cloud/&lt;WBR /&gt;prisma-&lt;SPAN class=""&gt;cloud-admin/connect-&lt;WBR /&gt;your-&lt;SPAN class=""&gt;cloud-&lt;SPAN class=""&gt;platform-to-prisma-&lt;WBR /&gt;&lt;SPAN class=""&gt;cloud/onboard-your-&lt;SPAN class=""&gt;gcp-&lt;WBR /&gt;account/set-up-&lt;SPAN class=""&gt;gcp-account-&lt;WBR /&gt;for-prisma-&lt;SPAN class=""&gt;cloud&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 06 Sep 2022 19:06:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514097#M655</guid>
      <dc:creator>MDavis29</dc:creator>
      <dc:date>2022-09-06T19:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Previously needed permission when onboarding GCP project on Prisma Cloud</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514104#M657</link>
      <description>&lt;P&gt;Hello AmyYoon,&lt;/P&gt;
&lt;P&gt;Please see below the minimum requirements to onboard a GCP cloud account.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Minimum permissions required:&lt;BR /&gt;Viewer—Primitive role on GCP.&lt;BR /&gt;Prisma Cloud Viewer—Custom role. Prisma Cloud needs this custom role to grant cloud storage bucket permission to read storage bucket metadata and update bucket IAM policies. This role requires storage.buckets.get to retrieve your list of storage buckets, and storage.buckets.getIampolicy to retrieve the IAM policy for the specified bucket.&lt;BR /&gt;Compute Security Admin—Predefined role on GCP. An optional privilege that is required only if you want to enable auto-remediation.&lt;BR /&gt;Organization Role Viewer—Predefined role on GCP. This role is required for onboarding a GCP Organization.&lt;BR /&gt;Dataflow Admin—Predefined role on GCP. An optional privilege that is required for dataflow log compression using the Dataflow service. See Flow Log Compression on GCP for details.&lt;BR /&gt;Folder Viewer—Predefined role on GCP. An optional privilege that is required only if you want to onboard GCP Folder metadata, select specific folders—include or exclude folders—, and to automatically create account groups based on the folder hierarchy.&lt;BR /&gt;&lt;A href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud" target="_blank"&gt;https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/onboard-your-gcp-account/set-up-gcp-account-for-prisma-cloud&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Sep 2022 19:52:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/previously-needed-permission-when-onboarding-gcp-project-on/m-p/514104#M657</guid>
      <dc:creator>MDavis29</dc:creator>
      <dc:date>2022-09-06T19:52:04Z</dc:date>
    </item>
  </channel>
</rss>

