Modify Google Cloud Policy
Modify Google Cloud Policy
Before you can create a Google service account key, you might need to allow key creation. Follow the steps below to enable this setting.
Go to the Google Cloud Platform Console and log in with your Super Admin account.
In the top-left corner, next to the Google Cloud logo, select your organization from the dropdown list.
Go to shield_person IAM and admin.
Click person_add Grant access.
Add your Super Admin account in the New principal field.
Under Assign roles, select the Organisation Administrator and Organisation Policy Administrator roles.
Click Save and wait a few minutes (± 3 minutes) to ensure that IAM changes have propagated.
Go to article Organization Policies.
Filter on
iam.disableServiceAccountKeyCreation.Select the policy
iam.disableServiceAccountKeyCreation.Click edit Manage policy.
Scroll down to Rules, and expand the Enforced rule.
Change Enforcement to Off.
Click Done.
Click Set policy.
Updated on 2025-06-05