Home / Platform Considerations / Microsoft 365

Enable Service account key creation

If you are trying to create a Google Service Account, and received the following error message that “Service account key creation is disabled”, follow the steps below to enable Service account key creation.

Alt text

If you receive the above error when creating the JSON and/or P12 Key, please do the following:

  1. Go to the organization (not the project).

    Alt text

  2. Go to IAM (Edit the Principal).

    Alt text

  3. Give the organization the role “Organization Policy Administrator” and click Save.

    Note: You must give the administrator the “Policy” Administrator role. The “Organization” Administrator role is insufficient.

    Alt text

  4. Go to “organization policies”.

  5. Click “Disable service account key creation”.

    Alt text

  6. Click “Manage Policy” for the “Disable Service Account Key Creation” (still as the org).

    Alt text

  7. Drop down the Rules and set “Enforcement” to “Off”. Click “Set Policy” when completed.

    Alt text

You have now enabled Service account key creation, so you may resume with the steps to create your Google Service Account.