Resolve Domain Restricted Sharing policy
In brief
The guide now explicitly directs administrators to review prerequisites, clarifies the connected GCP project requirement, and specifies permission to modify organization-level GCP policies.
What Defender admins need to know
Administrators can verify project connectivity and required organization-level permissions before following the resolution steps.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Microsoft Defender for Cloud generates a deployment script that includes all of the resources necessary to onboard your Google Cloud Platform (GCP) account to Defender for Cloud. However, as of May 2024, GCP enforces a policy called Domain Restricted Sharing by default for all organizations created after May 2024. The policy prevents the assignment of Identity and Access Management (IAM) permissions to service accounts external to your GCP organization. This policy might cause the deployment script generated by Defender for Cloud to fail.
This page guides you through the steps to resolve the Domain Restricted Sharing policy and ensure your GCP account is connected to Defender for Cloud correctly. Before you begin, make sure you meet the prerequisites, including having a connected GCP project and the required permissions.
Prerequisites
Microsoft Defender for Cloud set up on your Azure subscription.
Contributor level permission for the relevant Azure subscription.
Modify the policy at the organization level.Permission to modify organization-level policies in GCP.
Configure Domain Restricted Sharing for Defender for Cloud
@@ -1,8 +1,9 @@ --- title: Resolve Domain Restricted Sharing policy description: Resolve GCP Domain Restricted Sharing policy settings that block Defender for Cloud onboarding and connector deployment.-ms.date: 06/03/2025+ms.date: 07/03/2026 ms.topic: how-to+ms.custom: msecd-doc-authoring-1013 #customer intent: As a security professional, I want to resolve the Domain Restricted Sharing policy in Google Cloud Platform (GCP) to ensure my resources are connected and protected. ai-usage: ai-assisted ---@@ -11,7 +12,7 @@ ai-usage: ai-assisted Microsoft Defender for Cloud generates a deployment script that includes all of the resources necessary to onboard your Google Cloud Platform (GCP) account to Defender for Cloud. However, as of May 2024, GCP enforces a policy called [Domain Restricted Sharing](https://cloud.google.com/resource-manager/docs/organization-policy/restricting-domains) by default for all organizations created after May 2024. The policy prevents the assignment of Identity and Access Management (IAM) permissions to service accounts external to your GCP organization. This policy might cause the deployment script generated by Defender for Cloud to fail. -This page guides you through the steps to resolve the Domain Restricted Sharing policy and ensure your GCP account is connected to Defender for Cloud correctly.+This page guides you through the steps to resolve the Domain Restricted Sharing policy and ensure your GCP account is connected to Defender for Cloud correctly. Before you begin, make sure you meet the [prerequisites](#prerequisites), including having a connected GCP project and the required permissions. ## Prerequisites @@ -21,11 +22,11 @@ Before you update the policy, make sure you have the following prerequisites: - [Microsoft Defender for Cloud](get-started.md#enable-defender-for-cloud-on-your-azure-subscription) set up on your Azure subscription. -- [A connected GCP project](quickstart-onboard-gcp.md).+- [A connected Google Cloud Platform (GCP) project](quickstart-onboard-gcp.md). - Contributor level permission for the relevant Azure subscription. -- Modify the policy at the organization level.+- Permission to modify organization-level policies in GCP. ## Configure Domain Restricted Sharing for Defender for Cloud 