Limitations of Cloud IAM
So far, we've discussed the various features of Cloud, IAM as well as how it works, but before we wrap up Cloud IAM, let's take a look at what you cannot do with Cloud IAM.
Like any other cloud service, policies have limitations. For starters, each Google Cloud resource can only have one policy attached to it. It does not matter at what level in the hierarchy it is; the organization can have the number of policies as a Cloud Storage bucket, which is 1. You can, however, have different versions of a policy, but only one will be active at a time.
A single policy can only have up to 1,500 members (out of which 250 can be Google groups). This might seem like a major limitation at first but from a practical standpoint, 1,500 members per resource is more than most projects require. Furthermore, if you want more than 1,500 individual users, you can simply add them to a Google group because users in a Google group are counted as one member (the Google...