tag:google.com,2016:iam-release-notes Identity and Access Management - Release notes Google Cloud Platform 2026-05-08T00:00:00-07:00 May 08, 2026 tag:google.com,2016:iam-release-notes#May_08_2026 2026-05-08T00:00:00-07:00 <![CDATA[

Feature

You can use the IAM recommender to remediate excessive permissions for Google groups by transitioning from permanent role bindings to temporary, on-demand entitlements in Privileged Access Manager (PAM). This feature is in Preview.

To learn how to remediate excessive permissions, see Remediate excessive permissions with Privileged Access Manager.

]]>
April 22, 2026 tag:google.com,2016:iam-release-notes#April_22_2026 2026-04-22T00:00:00-07:00 <![CDATA[

Feature

Privileged Access Manager supports agent identities as grant requesters and approvers.

This feature is available in preview.

For more information, see Privileged Access Manager overview.

Feature

Agent Identity auth manager is available in preview. You can use Agent Identity auth manager to help securely authenticate your agents to third-party services using 3-legged OAuth, 2-legged OAuth, or API keys.

For more information, see Agent Identity auth manager.

Feature

Agent Identity is generally available (GA). Agent Identity provides a strongly attested, cryptographic identity for each agent that is tied to the lifecycle of the resource hosting the agent.

For more information, see Agent Identity overview.

]]>
April 13, 2026 tag:google.com,2016:iam-release-notes#April_13_2026 2026-04-13T00:00:00-07:00 <![CDATA[

Feature

Requesters can schedule grant requests in Privileged Access Manager up to seven days in advance. This lets requesters align access with scheduled maintenance or on-call shifts.

This feature is in preview.

For more information, see Privileged Access Manager overview.

]]>
April 07, 2026 tag:google.com,2016:iam-release-notes#April_07_2026 2026-04-07T00:00:00-07:00 <![CDATA[

Feature

Organization Policy Service custom constraints are available for managed workload identity and Workload Identity Federation. You can use custom constraints to control how managed workload identity and Workload Identity Federation are used in your organization. For more information, see Custom organization policy constraints for managed workload identity and Custom organization policy constraints for Workload Identity Federation.

]]>
March 31, 2026 tag:google.com,2016:iam-release-notes#March_31_2026 2026-03-31T00:00:00-07:00 <![CDATA[

Feature

Gemini assistance in the IAM role picker is generally available.

For more information, see Get predefined role suggestions with Gemini assistance.

]]>
March 18, 2026 tag:google.com,2016:iam-release-notes#March_18_2026 2026-03-18T00:00:00-07:00 <![CDATA[

Feature

Managed workload identities are generally available.

For more information, see Managed workload identities overview.

]]>
March 03, 2026 tag:google.com,2016:iam-release-notes#March_03_2026 2026-03-03T00:00:00-08:00 <![CDATA[

Feature

Service account principal sets are generally available. You can use service account principal sets to reference all service accounts or service agents in a project, folder, or organization when writing allow policies, deny policies, and access policies.

]]>
February 27, 2026 tag:google.com,2016:iam-release-notes#February_27_2026 2026-02-27T00:00:00-08:00 <![CDATA[

Feature

The ability to self-grant missing permissions from permission error messages is generally available.

To learn how to request missing permissions, see Request missing permissions.

Feature

You can disable the option to send auto-generated access requests from permission error messages. This feature is in preview.

To learn how to disable these requests, see Disable auto-generated access request emails.

]]>
December 15, 2025 tag:google.com,2016:iam-release-notes#December_15_2025 2025-12-15T00:00:00-08:00 <![CDATA[

Change

You can ask Gemini for predefined role suggestions (preview) without enabling any APIs.

In addition, you can get custom role suggestions from Gemini using the Cloud Assist panel in the Google Cloud console.

For more information, see Get predefined role suggestions with Gemini assistance.

Feature

A new infinite-scrolling UI for audit logs is available on the Privileged Access Manager > Audit logs page in the Google Cloud console. This interface update replaces pagination with clear data loading indicators and time boundaries to help facilitate event investigations.

This feature is in preview.

]]>
September 26, 2025 tag:google.com,2016:iam-release-notes#September_26_2025 2025-09-26T00:00:00-07:00 <![CDATA[

Feature

Privileged Access Manager (PAM) offers the following features in preview:

Change

For Privileged Access Manager, notification emails for grant activation, activation failure, or denial no longer include approver details.

To learn how to view the approver details, see Check grant status.

]]>
September 12, 2025 tag:google.com,2016:iam-release-notes#September_12_2025 2025-09-12T00:00:00-07:00 <![CDATA[

Feature

IAM offers predefined roles that are tailored to specific job functions. These roles cover all of the permissions that a user might need to perform their job. This feature is generally available.

For more information, see Predefined roles for job functions.

Feature

Permission errors in the Google Cloud console contain actionable steps for remediation. For more information, see Troubleshoot permission error messages.

]]>
July 21, 2025 tag:google.com,2016:iam-release-notes#July_21_2025 2025-07-21T00:00:00-07:00 <![CDATA[

Feature

You can ask Gemini for predefined role suggestions using the IAM role picker in the Google Cloud console. This feature is in preview.

For more information, see Get predefined role suggestions with Gemini assistance.

]]>
June 13, 2025 tag:google.com,2016:iam-release-notes#June_13_2025 2025-06-13T00:00:00-07:00 <![CDATA[

Change

Conditions that check the tags for a resource can also check other attributes, such as the resource name of the timestamp of the request. This feature is available in Preview. For more information, see Resource tags.

]]>
May 28, 2025 tag:google.com,2016:iam-release-notes#May_28_2025 2025-05-28T00:00:00-07:00 <![CDATA[

Feature

Workforce Identity Federation supports detailed audit logging, which you can use to troubleshoot attribute mapping issues. This feature is generally available.

]]>
May 15, 2025 tag:google.com,2016:iam-release-notes#May_15_2025 2025-05-15T00:00:00-07:00 <![CDATA[

Change

The predefined role reference and the permissions reference have been reorganized to improve performance and searchability. To see the new experience, visit the IAM roles and permissions index.

]]>
May 07, 2025 tag:google.com,2016:iam-release-notes#May_07_2025 2025-05-07T00:00:00-07:00 <![CDATA[

Feature

Workload Identity Federation support for X.509 certificates is generally available.

]]>
May 05, 2025 tag:google.com,2016:iam-release-notes#May_05_2025 2025-05-05T00:00:00-07:00 <![CDATA[

Change

A new enforcement version, enforcement version 3, is available for principal access boundary policies. To learn more about enforcement versions and see the permissions that enforcement version 3 can block, see Permissions that principal access boundary policies can block.

]]>
February 24, 2025 tag:google.com,2016:iam-release-notes#February_24_2025 2025-02-24T00:00:00-08:00 <![CDATA[

Feature

Workforce Identity Federation can map up to 400 groups from Microsoft Entra ID. The feature is generally available. To learn more, see Configure Workforce Identity Federation with Microsoft Entra ID and a large number of groups.

Change

Workforce Identity Federation supports an attribute mapping of up to 400 groups and a maximum size of 16 KB.

]]>
December 16, 2024 tag:google.com,2016:iam-release-notes#December_16_2024 2024-12-16T00:00:00-08:00 <![CDATA[

Change

Principal access boundary policies are generally available. You can use principal access boundary policies to limit the resources that a principal is eligible to access.

]]>
December 09, 2024 tag:google.com,2016:iam-release-notes#December_09_2024 2024-12-09T00:00:00-08:00 <![CDATA[

Change

Using IAM attributes in custom organization policies is generally available. For more information, see Use custom organization policies.

Feature

You can use the iam.managed.preventPrivilegedBasicRolesForDefaultServiceAccounts managed organization policy constraint to prevent default service accounts from being granted the Editor (roles/editor) or Owner (roles/owner) roles. For more information, see Prevent the Owner and Editor role from being granted to default service accounts.

]]>
September 16, 2024 tag:google.com,2016:iam-release-notes#September_16_2024 2024-09-16T00:00:00-07:00 <![CDATA[

Feature

Privileged Access Manager (PAM) is now released to General Availability. The following features have been added:

]]>
September 12, 2024 tag:google.com,2016:iam-release-notes#September_12_2024 2024-09-12T00:00:00-07:00 <![CDATA[

Change

You can manage IAM deny policies using the Google Cloud console. For more information, see Deny access to resources.

]]>
August 12, 2024 tag:google.com,2016:iam-release-notes#August_12_2024 2024-08-12T00:00:00-07:00 <![CDATA[

Feature

You can attach tags to Identity and Access Management (IAM) service accounts to conditionally grant or deny access to specific service accounts. This feature is in Preview. For more information, see Creating and managing tags for service accounts.

]]>
July 30, 2024 tag:google.com,2016:iam-release-notes#July_30_2024 2024-07-30T00:00:00-07:00 <![CDATA[

Feature

You can use IAM attributes in custom organization policies to control how your allow policies can be modified. For more information, see Use custom organization policies.

]]>
June 10, 2024 tag:google.com,2016:iam-release-notes#June_10_2024 2024-06-10T00:00:00-07:00 <![CDATA[

Feature

You can use principal access boundary policies to limit the resources that a principal is eligible to access. This feature is available in Preview.

]]>
May 08, 2024 tag:google.com,2016:iam-release-notes#May_08_2024 2024-05-08T00:00:00-07:00 <![CDATA[

Feature

Privileged Access Manager (PAM) lets you manage just-in-time temporary privilege elevation for select principals, and to view audit logs afterwards to find out who had access to what and when. This feature is in Preview.

]]>
May 03, 2024 tag:google.com,2016:iam-release-notes#May_03_2024 2024-05-03T00:00:00-07:00 <![CDATA[

Change

As of May 3, 2024, when you create a new organization, it enforces the following organization policy constraints by default:

  • iam.disableServiceAccountKeyCreation
  • iam.disableServiceAccountKeyUpload
  • iam.automaticGrantsForDefaultServiceAccounts
  • iam.allowedPolicyMemberDomains

For more information, see Restricting service account usage and Restricting identities by domain.

]]>
March 15, 2024 tag:google.com,2016:iam-release-notes#March_15_2024 2024-03-15T00:00:00-07:00 <![CDATA[

Change

You can use the iam.serviceAccountKeyExposureResponse organization policy constraint to help manage leaked service account credentials.

]]>
March 05, 2024 tag:google.com,2016:iam-release-notes#March_05_2024 2024-03-05T00:00:00-08:00 <![CDATA[

Change

To improve performance, we've removed the ability to expand abbreviated permissions in the predefined roles table. You can still filter the predefined roles table based on the full list of permissions included in a role.

]]>
February 15, 2024 tag:google.com,2016:iam-release-notes#February_15_2024 2024-02-15T00:00:00-08:00 <![CDATA[

Feature

Managed workload identities let you bind strongly attested identities to your Compute Engine workloads. The feature is in Preview. Google Cloud provisions X.509 credentials, issued from Certificate Authority Service, that can be used to reliably authenticate your workload with other workloads over mutual TLS (mTLS) authentication. For more information, see Managed workload identities overview.

]]>