Offboarding GCP
Overview
Offboarding involves stopping the monitoring of a cloud account in Prisma Cloud Data Security Posture Management (DSPM) and then deleting it from the DSPM console. This process removes all data associated with the specified project.
Important: If you want to temporarily disable DSPM without offboarding, please refer to Monitoring an Account.
Prerequisites
Before proceeding with the offboarding process, make sure that you have the necessary permissions to manage your GCP project and deployment manager resources.
Offboarding Procedure
WARNING: Perform the offboarding procedure according to the order described below to avoid causing issues such as resources not being deleted from the project.
Step 1: Offboarding a Project from the Prisma Cloud Console
WARNING: The offboarding process is irreversible; once initiated, it cannot be canceled, and all data is permanently deleted.
Before initiating the offboarding process, review the project information in the Prisma Cloud DSPM console.
Deleted Data
When you initiate offboarding, the following data is deleted:
Assets
Classification findings
Risk findings
Activity log entries
Dynamic resources used for scans
The following resources are not deleted; however, they are deleted in the next steps:
Static resources created by Prisma Cloud DSPM for scanning purposes
Third-party integrations
Prisma Cloud DSPM deployment resources, including:
Roles
Service accounts
Bindings
Sign in to Prisma Cloud Console.
From the DSPM Preferences tab, navigate to the GCP projects page.

Navigate to the DSPM project you want to offboard.
Click the gear icon in the column on the far right side of the project table, and select Offboard Project.

Read the information provided and click Offboard Project to confirm.
Read content on the entire Offboard Project? screen. If you agree with the warnings and want to proceed with offboarding the project, click Offboard Project.

During the offboarding process, the following occurs:
Project monitoring is disabled.
An Offboarding tag is applied to the project.
All data associated with the cloud account is deleted within 72 hours.
NOTE: Data may still appear in the console during this period.
WARNING: The cloud infrastructure deployed by DSPM is not deleted during the offboarding process. For more details, refer to the specific offboarding documentation. This process is irreversible, so proceed with caution.
Step 2: Wait for Resource Deletion
After disabling monitoring, wait for 48 hours. During this time, all resources created in GCP as part of the scanning procedures are scheduled for deletion.
WARNING: If you proceed with the offboarding process before this period concludes, some resources may remain in your environment and will not be deleted.
Step 3: Access the CloudShell
Sign in to your GCP account.
Navigate to the CloudShell page.
Step 4: Delete the Org Resources (Single Account)
Locate and delete the Dig Security deployment manager according to your location.
Europe
dig-security-logging
dig-security-roles
dig-security-service-accounts (edited)
United States
dig-security-logginguse1
Dig-security-rolesuse1
dig-security-service-accountsuse1
Step 5: Delete Binding of the Deleted Service Accounts
Navigate to the IAM (account level or Folder/Org level) page and delete the binding of the deleted service accounts.
Delete each binding with the prefix “dig-”.
Navigate to the Org roles page and delete all roles with “Dig_”.
Disclaimer: The permanent deletion process takes 30 days. During the 30-day window, the role and all associated bindings are permanently removed, and you cannot create a new role with the same role ID.
Step 6: DDR Offboarding
Note: Perform the following steps only when offboarding an Orchestrator project.
Go to the GCP console in the orchestrator project you are offboarding.
In the search box, type log router and select the Log Router page.
Search for the sink mentioned under Log Sink with the prefix “dig-”.
Click on the three dots and select Delete sink.
Last updated
Was this helpful?

