# Modify Google Cloud Policy

Before you can create a Google service account key, you might need to allow key creation. Follow the steps below to enable this setting.

01. Go to the [Google Cloud Platform Console](https://console.cloud.google.com/) and log in with your Super Admin account.

02. In the top-left corner, next to the Google Cloud logo, select your organization from the dropdown list.

03. Go to _shield\_person_ **IAM and admin**.

04. Click _person\_add_ Grant access.

05. Add your Super Admin account in the **New principal** field.

06. Under **Assign roles**, select the **Organisation Administrator** and **Organisation Policy Administrator** roles.

07. Click Save and wait a few minutes (± 3 minutes) to ensure that IAM changes have propagated.

08. Go to _article_ **Organization Policies**.

09. Filter on `iam.disableServiceAccountKeyCreation`.

10. Select the policy `iam.disableServiceAccountKeyCreation`.

11. Click _edit_ **Manage policy**.

12. Scroll down to **Rules**, and expand the **Enforced** rule.

13. Change **Enforcement** to **Off**.

14. Click Done.

15. Click Set policy.

Updated on 2025-06-05
