Description:
It is recommended to configure your instance to not use the default Compute Engine service account because it has the Editor role on the project.
Rationale:
The default Compute Engine service account has the Editor role on the project, which allows read and write access to most Google Cloud Services. To defend against privilege escalations if your VM is compromised and prevent an attacker from gaining access to all of your project, it is recommended to not use the default Compute Engine service account. Instead, you should create a new service account and assigning only the permissions needed by your instance.
The default Compute Engine service account is named '[PROJECT_NUMBER][email protected]'.
From Google Cloud Console
From Google Cloud CLI
gcloud compute instances stop
gcloud compute instances set-service-account --service-account=
gcloud compute instances start