Hey everyone!
I have some OAuth questions which I could not find an answer for.
Setup: We use Looker Standard Platform (Original not Cloud Core).
I am asked to enable OAuth. Before that I need to verify:
1. When I provide the IAM role Looker Instance User (roles/looker.instanceUser) for a group/principal and I give the default role for new users in Looker zero permissions. Do I still need a viewer license for everyone who logs into Looker or only when I assign them viewer permissions or IAM Looker Viewer (roles/looker.viewer)?
2. Can I exclude usergroups via IAM to login to Looker via OAuth?
I would really appreciate an answer or a link. I have studied the documentation but couldn't find the answers.
All the best and thank you!
Solved! Go to Solution.
1. Users without a role or permissions would not count as viewers for licensing purposes.
2. You should be able to create groups on the OAuth side that have differing permissions relating to accessing a specific tool like Looker. So you when a new user needs access, you would move/add them to the group with Looker access.