Stay organized with collections
Save and categorize content based on your preferences.
Provide Access to Destination Bucket
Finish the Project Setup and Key Download step for the session. The Session ID can be found in the email titled Action Required: Provide Access for Data Upload - Google Transfer Appliance.
Provide Access to KMS
Prerequisite: Ensure you have the Cloud KMS Admin role (roles/cloudkms.admin) to provide access to the KMS key.
Find the Session ID in the email titled Action Required: Provide Access for Data Upload - Google Transfer Appliance.
Find the KMS key in the 'Key resource nฬฆame' field on the Appliance Detail page for the given session.
Go to the Cryptographic Keys page in Google Cloud console.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-28 UTC."],[],[],null,["Provide Access to Destination Bucket\n------------------------------------\n\nFinish the [Project Setup and Key Download](/transfer-appliance/docs/4.0/procedure-guide#project-setup-and-key-download) step for the session. The Session ID can be found in the email titled *Action Required: Provide Access for Data Upload - Google Transfer Appliance.*\n\nProvide Access to KMS\n---------------------\n\n1. **Prerequisite:** Ensure you have the **Cloud KMS Admin** role (`roles/cloudkms.admin`) to provide access to the KMS key.\n2. Find the Session ID in the email titled *Action Required: Provide Access for Data Upload - Google Transfer Appliance.*\n3. Find the KMS key in the 'Key resource nฬฆame' field on the Appliance Detail page for the given session.\n4. Go to the **Cryptographic Keys** page in Google Cloud console.\n\n [Go to the Cryptographic Keys page](https://console.cloud.google.com/security/kms)\n5. Click the key ring that contains your asymmetric key.\n\n6. Select the checkbox for the asymmetric key.\n\n7. In the **Info panel** , click **Add principal**.\n\n - **Add principals** is displayed.\n8. In the **New principals** field, enter the Transfer Appliance P4SA.\n It looks like the following example:\n\n `service-`\u003cvar translate=\"no\"\u003ePROJECT_NUMBER\u003c/var\u003e`@gcp-sa-transferappliance.iam.gserviceaccount.com`\n\n In this example, \u003cvar translate=\"no\"\u003ePROJECT_NUMBER\u003c/var\u003e is the Google Cloud project number that your appliance is under.\n9. In the **Select a role** field, add the **Cloud KMS CryptoKey Public Key Viewer** role.\n\n10. Click the **Add another role** and add **Cloud KMS CryptoKey Decrypter** role.\n\n11. Click **Save**."]]