Remediation
From Google Cloud Consoleβ
- Go to
IAM & Admin/IAM
using https://console.cloud.google.com/iam-admin/iam - For any member having
Cloud KMS Admin
and any of theCloud KMS CryptoKey Encrypter/Decrypter
,Cloud KMS CryptoKey Encrypter
,Cloud KMS CryptoKey Decrypter
roles granted/assigned, click theDelete Bin
icon to remove the role from the member.
Note: Removing a role should be done based on the business requirement.