Skip to main content
Google Cloud Documentation
Technology areas
  • AI and ML
  • Application development
  • Application hosting
  • Compute
  • Data analytics and pipelines
  • Databases
  • Distributed, hybrid, and multicloud
  • Industry solutions
  • Migration
  • Networking
  • Observability and monitoring
  • Security
  • Storage
Cross-product tools
  • Access and resources management
  • Costs and usage management
  • Infrastructure as code
  • SDK, languages, frameworks, and tools
/
Console
  • English
  • Deutsch
  • Español
  • Español – América Latina
  • Français
  • Indonesia
  • Italiano
  • Português
  • Português – Brasil
  • עברית
  • 中文 – 简体
  • 中文 – 繁體
  • 日本語
  • 한국어
Sign in
  • IAM
Start free
Overview Guides Reference Samples Resources
Google Cloud Documentation
  • Technology areas
    • More
    • Overview
    • Guides
    • Reference
    • Samples
    • Resources
  • Cross-product tools
    • More
  • Console
  • Discover
  • Product overview
  • Get started
  • Grant roles in the Google Cloud console
  • Grant roles using client libraries
  • IAM and your security architecture
  • Identity management for Google Cloud
  • Configure identities for users
  • Identities for users
  • Create and manage Google groups in the Google Cloud console
  • Best practices for using Google groups
  • Federate identities for users
    • Workforce identity federation
    • Architecture patterns for identity federation
    • Best practices for using Workforce Identity Federation
    • SCIM provisioning for Workforce Identity Federation
    • Configure Workforce Identity Federation
      • Microsoft Entra ID
      • Microsoft Entra ID with a large number of groups
      • Okta
      • PingFederate
      • PingOne AIC
      • Other OIDC or SAML 2.0
      • Access BigQuery data in Power BI with Microsoft Entra
    • Configure SCIM
      • Microsoft Entra ID
      • Okta
      • OIDC or SAML 2.0
    • Obtain short-lived credentials for Workforce Identity Federation
    • Manage workforce identity pools and providers
    • Delete Workforce Identity Federation users and their data
    • Set up user access to console (federated)
    • Sign in to the gcloud CLI with your federated identity
    • Integrate OAuth applications
      • OAuth application integration overview
      • Manage OAuth applications
  • Configure identities for workloads
  • Identities for workloads
  • Create and manage service accounts
    • About service accounts
      • Service accounts
      • Service account credentials
      • Service account impersonation
      • Service account types
      • Roles for service account authentication
    • Create and grant roles to service agents
    • Create service accounts
    • Manage service accounts
      • List and edit service accounts
      • Disable and enable service accounts
      • Delete and undelete service accounts
      • Manage tags for service accounts
    • Attach service accounts to resources
    • Use custom organization policies for service accounts and keys
    • Service account best practices
      • Best practices for using service accounts
      • Best practices for using service accounts in deployment pipelines
  • Use managed workload identities
    • About managed workload identities
    • Compute Engine
      • Create managed workload identities for GCE
    • GKE
      • Create managed workload identities for GKE
      • Troubleshoot managed workload identities for GKE
    • Cloud load balancing
      • Create managed workload identities for load balancers
    • Use custom organization policies
  • Federate identities for external workloads
    • Workload Identity Federation
    • Configure Workload Identity Federation
      • AWS or Azure
      • Active Directory
      • Deployment pipelines
      • Kubernetes
      • Workloads with X.509 certificates
      • Other identity providers
    • Authenticate workloads using Google auth libraries
    • Manage workload identity pools and providers
    • Best practices for using Workload Identity Federation
    • Let customers access their Google Cloud resources from your product or service
    • Download credential configuration and grant access
    • Integrate Cloud Run and Workload Identity Federation
    • Use custom organization policies
  • Create and manage service account keys
    • Migrate from service account keys
    • Service account key rotation
    • Create and delete service account keys
    • List and get service account keys
    • Upload a public key
    • Disable and enable service account keys
    • Best practices for managing service account keys
  • Built-in identities for resources
  • Configure identities for agents
  • Agent Identity overview
  • Create and deploy an agent with Agent CLI and Agent Identity
  • Authenticate using an agent's own identity
  • Agent Identity auth manager
    • Agent Identity auth manager overview
    • Authenticate using 3-legged OAuth
    • Authenticate using 2-legged OAuth
    • Authenticate using an API key
    • Manage auth providers
    • Migrate to the Agent Identity API
    • Use custom organization policies for auth manager
  • Control access to resources
  • About IAM access controls
    • Roles and permissions
    • Principals
    • Policy types
    • Allow policies
    • Allow policy inheritance
    • Deny policies
    • Principal access boundary policies
    • Access change propagation
    • IAM Conditions
  • Choose roles to grant
    • Choose which type of role to use
    • Find the right predefined roles
    • Get predefined role suggestions with Gemini assistance
    • View grantable roles