Google Cloud API 要求可能涉及多個資源的作業。機構限制標頭服務會檢查要求中的所有資源是否都在授權機構清單中。如果任何資源不屬於授權機構清單,系統就會拒絕要求。
允許保管箱使用者下載資料
Google 保管箱是 Google Workspace 的資訊管理與電子蒐證工具,保管箱管理員可存取儲存在 Google 擁有的 Cloud Storage bucket 中的 Google Workspace 使用者資料。
根據預設,機構限制功能會禁止保管箱管理員從 Google 自有的 Cloud Storage bucket 下載匯出的 Google Workspace 使用者資料。如要允許保管箱管理員發出的要求,請務必將儲存保管箱資料的機構 ID organizations/433637338589 新增至機構限制標頭。
建議您只在保管箱管理員的要求標頭中,新增儲存保管箱資料的機構 ID。
啟用 Google 擁有的資源存取權
為方便開發人員使用 BigQuery 或 Compute Engine 等 Google Cloud 服務, Google Cloud 提供 Google 擁有的公開資源。舉例來說,Compute Engine 提供公開 OS 映像檔,協助開發人員快速開始建構自己的映像檔,或利用其中一個映像檔代管工作負載。其他 Google Cloud 服務也採用類似的公開資源模式。這些公開資源會託管在 Google 擁有的 Google Cloud 機構中。
為確保貴機構使用者在強制執行機構限制後,仍可存取這些公開資源,請在機構限制標頭的授權機構清單中,加入下列 Google 擁有的機構 ID: Google Cloud Google Cloud
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[],[],null,["# Additional considerations\n\nThis page lists additional considerations you must be aware of when using organization restrictions.\n\n### Multi-resource access\n\nGoogle Cloud API requests might involve operations on multiple resources. Organization restrictions\nheader service checks whether all resources that are part of the request\nare in the list of authorized organizations. If any resource is not part of the list of authorized\norganizations, the request is denied.\n\n### Allow download for Vault users\n\n[Google Vault](https://support.google.com/vault/answer/2462365) is an information governance\nand eDiscovery tool for Google Workspace. Vault administrators access Google Workspace user data stored\nin Google-owned Cloud Storage buckets.\n\nBy default, the organization restrictions feature restricts Vault administrators from downloading\nan exported Google Workspace user data from a Google-owned Cloud Storage bucket.\nTo allow requests that originate from the Vault administrators, ensure that organization ID\n`organizations/433637338589`, which stores Vault data, is added to the organization restrictions header.\n\nWe recommend to add this ID of the organization, which stores Vault data, only in headers\nfor requests from Vault administrators.\n\n### Enable access to Google-owned resources\n\nTo enable developers to use Google Cloud services, such as BigQuery\nor Compute Engine, Google Cloud provides Google-owned public resources. For example,\nCompute Engine provides [public OS images](/compute/docs/images#os-compute-support)\nthat help developers quickly get started with building their own or leveraging one\nof these images to host their workloads. Other Google Cloud services employ similar\npublic resource patterns. These public resources are hosted in a Google-owned Google Cloud organization.\n\nTo ensure that users of your Google Cloud organization continue to have access\nto these public resources after you enforce organization restrictions, add the\nfollowing Google-owned Google Cloud organization ID to the list of authorized organizations\nin the organization restrictions header: \n\n organizations/433637338589\n\nWhat's next\n-----------\n\n- Learn about [using organization restrictions](/resource-manager/docs/organization-restrictions/examples-org-restrictions).\n- Learn about the [services supported by organization restrictions](/resource-manager/docs/organization-restrictions/supported-services)."]]