services / Google Cloud / Compute Engine managed instance groups
Create and alter managed instance groups.
Allows creation, modification, and destruction of auto-scaling instance groups. Except for resizing, can not critically impact organizational functions.
compute.instanceGroupManagers.delete
Does not delete instances themselves, but can effectively remove network access to instances.
Risks
Scope: HIGH
This privilege may grant access to sensitive data from a single organizational function, or allow interruption of a service supporting a single organizational function.
Links
Contributed by P0 Security
© 2023–present P0 Security and contributors to the IAM Privilege Catalog