Microsoft Defender for Cloud
Cloud and workloads

Resolve Domain Restricted Sharing policy

In brief

The guide now explicitly directs administrators to review prerequisites, clarifies the connected GCP project requirement, and specifies permission to modify organization-level GCP policies.

What Defender admins need to know

Administrators can verify project connectivity and required organization-level permissions before following the resolution steps.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Microsoft Defender for Cloud generates a deployment script that includes all of the resources necessary to onboard your Google Cloud Platform (GCP) account to Defender for Cloud. However, as of May 2024, GCP enforces a policy called Domain Restricted Sharing by default for all organizations created after May 2024. The policy prevents the assignment of Identity and Access Management (IAM) permissions to service accounts external to your GCP organization. This policy might cause the deployment script generated by Defender for Cloud to fail.

This page guides you through the steps to resolve the Domain Restricted Sharing policy and ensure your GCP account is connected to Defender for Cloud correctly. Before you begin, make sure you meet the prerequisites, including having a connected GCP project and the required permissions.

Prerequisites

Configure Domain Restricted Sharing for Defender for Cloud