Hey guys,
Trying to install GAM for the first time on a new domain + computer. Used it a bunch previously at my former job.
I'm super-admin, yet cannot go thru install with ERROR: 403: Permission iam.serviceAccountKeys.create is required to perform this operation on service account
Any recommendations? See logs:
Creating project "GAM Project"...
Checking project status...
Project: gam-project-jvl-rvq-9cd, Enable 21 APIs
API: admin.googleapis.com, Enabled (1/21)
API: alertcenter.googleapis.com, Enabled (2/21)
API: calendar-json.googleapis.com, Enabled (3/21)
API: chat.googleapis.com, Enabled (4/21)
API: chromemanagement.googleapis.com, Enabled (5/21)
API: chromepolicy.googleapis.com, Enabled (6/21)
API: classroom.googleapis.com, Enabled (7/21)
API: cloudidentity.googleapis.com, Enabled (8/21)
API: contacts.googleapis.com, Enabled (9/21)
API: drive.googleapis.com, Enabled (10/21)
API: driveactivity.googleapis.com, Enabled (11/21)
API: iap.googleapis.com, Enabled (12/21)
API: gmail.googleapis.com, Enabled (13/21)
API: groupssettings.googleapis.com, Enabled (14/21)
API: iam.googleapis.com, Enabled (15/21)
API: licensing.googleapis.com, Enabled (16/21)
API: reseller.googleapis.com, Enabled (17/21)
API: sheets.googleapis.com, Enabled (18/21)
API: siteverification.googleapis.com, Enabled (19/21)
API: storage-api.googleapis.com, Enabled (20/21)
API: vault.googleapis.com, Enabled (21/21)
Setting GAM project consent screen...
Creating Service Account
Generating new private key...
Extracting public certificate...
Done generating private key and public certificate.
Uploading new public certificate to Google...
ERROR: 403: Permission iam.serviceAccountKeys.create is required to perform this operation on service account projects/-/serviceAccounts/117385753880378987998. - 403
This email and all attachments are Two Point property, confidential, and intended only for the recipient. If you are not the intended recipient or believe you have received this message in error, please notify the sender and immediately delete this message. Retaining, disseminating, forwarding, printing, copying, or other unintended use of this mail is prohibited. --
You received this message because you are subscribed to the Google Groups "GAM for Google Workspace" group.
To unsubscribe from this group and stop receiving emails from it, send an email to google-apps-man...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/be95ad28-ed27-467e-a31a-dcaf91319b9an%40googlegroups.com.
Ran into the same issue and got it sorted. This is a permissions issue with the account you're attempting to create the project with. You'll need to ensure that, for your root organization, you have the Service Account Key Admin role. I also have the Org Admin and Owner roles but it didn't work until I added the Service Account Key Admin role.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/f5162ca2-c3c3-4720-9cf9-6d12f4578995n%40googlegroups.com.
Ran into the same issue and got it sorted. This is a permissions issue with the account you're attempting to create the project with. You'll need to ensure that, for your root organization, you have the Service Account Key Admin role. I also have the Org Admin and Owner roles but it didn't work until I added the Service Account Key Admin role.
On Tuesday, May 25, 2021 at 11:24:06 AM UTC-6 l...@iregular.io wrote:
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/f5162ca2-c3c3-4720-9cf9-6d12f4578995n%40googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/google-apps-manager/CAJkvRS_0ofLFrN2oYbXeykyCLtK3-FV-LeXurAWRVLk7FoxJ7w%40mail.gmail.com.