- NAME
-
- gcloud alpha pam grants withdraw - withdraw a Privileged Access Manager grant
- SYNOPSIS
-
-
gcloud alpha pam grants withdraw(GRANT:--entitlement=ENTITLEMENT--folder=FOLDER--location=LOCATION--organization=ORGANIZATION) [GCLOUD_WIDE_FLAG …]
-
- DESCRIPTION
-
(ALPHA)Withdraw a Privileged Access Manager (PAM) grant. - EXAMPLES
-
The following command withdraws a grant with the full name
:GRANT_NAMEgcloud alpha pam grants withdraw GRANT_NAME - POSITIONAL ARGUMENTS
-
-
Grant resource - Name of the grant to withdraw. The arguments in this group can
be used to specify the attributes of this resource. (NOTE) Some attributes are
not given arguments in this group but can be set in other ways.
To set the
projectattribute:-
provide the argument
granton the command line with a fully specified name; -
provide the argument
--projecton the command line; -
set the property
core/project. This resource can be one of the following types: [privilegedaccessmanager.projects.locations.entitlements.grants, privilegedaccessmanager.folders.locations.entitlements.grants, privilegedaccessmanager.organizations.locations.entitlements.grants].
This must be specified.
GRANT-
ID of the grant or fully qualified identifier for the grant.
To set the
grantattribute:-
provide the argument
granton the command line.
This positional argument must be specified if any of the other arguments in this group are specified.
-
provide the argument
--entitlement=ENTITLEMENT-
The entitlement id
To set the
entitlementattribute:-
provide the argument
granton the command line with a fully specified name; -
provide the argument
--entitlementon the command line.
-
provide the argument
--folder=FOLDER-
The name of the folder
To set the
folderattribute:-
provide the argument
granton the command line with a fully specified name; -
provide the argument
--folderon the command line. Must be specified for resource of type [privilegedaccessmanager.folders.locations.entitlements.grants].
-
provide the argument
--location=LOCATION-
The resource location
To set the
locationattribute:-
provide the argument
granton the command line with a fully specified name; -
provide the argument
--locationon the command line.
-
provide the argument
--organization=ORGANIZATION-
The name of the organization
To set the
organizationattribute:-
provide the argument
granton the command line with a fully specified name; -
provide the argument
--organizationon the command line. Must be specified for resource of type [privilegedaccessmanager.organizations.locations.entitlements.grants].
-
provide the argument
-
provide the argument
-
Grant resource - Name of the grant to withdraw. The arguments in this group can
be used to specify the attributes of this resource. (NOTE) Some attributes are
not given arguments in this group but can be set in other ways.
- GCLOUD WIDE FLAGS
-
These flags are available to all commands:
--access-token-file,--account,--billing-project,--configuration,--flags-file,--flatten,--format,--help,--impersonate-service-account,--log-http,--project,--quiet,--trace-token,--user-output-enabled,--verbosity.Run
$ gcloud helpfor details. - API REFERENCE
-
This command uses the
privilegedaccessmanager/v1alphaAPI. The full documentation for this API can be found at: https://cloud.google.com/iam/docs/pam-overview - NOTES
-
This command is currently in alpha and might change without notice. If this
command fails with API permission errors despite specifying the correct project,
you might be trying to access an API with an invitation-only early access
allowlist. This variant is also available:
gcloud beta pam grants withdraw
gcloud alpha pam grants withdraw
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-09-30 UTC.