Remediation
From Google Admin Console and Google Cloud Console
- Create separate regular user accounts for Google Cloud administration.
- Grant those accounts only the Google Cloud IAM roles required for their responsibilities.
- Review IAM bindings at the organization, folder, and project levels.
- Remove Super Admin accounts from Google Cloud IAM bindings.
- Confirm that Super Admin accounts remain reserved for Google Workspace or Cloud Identity administration.