This page documents production updates to Identity and Access Management. Check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.
You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
August 14, 2026
You can use custom constraints with Organization Policy to provide more
granular control over specific fields for Agent Identity resources, such as
agentidentity.googleapis.com/AuthProvider. For more information, see
Use custom organization policies for Agent Identity.
This feature is in
GA.
Agent Identity VPC Service Controls (VPC Service Controls) integration is generally available.
You can add the Agent Identity API (agentidentity.googleapis.com) and Agent Identity Credentials API (agentidentitycredentials.googleapis.com) to a service perimeter and specify agent identities in ingress and egress rules.
For more information, see Agent Identity overview.
August 12, 2026
The workflow for creating workforce identity pool providers in the Google Cloud console changed. After submitting the initial provider configuration, the console directs you to a centralized page to configure provider attributes, including attribute mappings, attribute conditions, and extra attributes.
For more information, see Manage workforce identity pools and providers.
August 03, 2026
Organization Policy Service custom constraints are available for Privileged Access Manager (PAM). You can use custom constraints to restrict how users create and modify entitlements and grants. This feature is in Preview.
For more information, see Use custom organization policies for Privileged Access Manager.
July 27, 2026
Managed workload identities for Compute Engine are generally available.
For more information, see Configure managed workload identity authentication for Compute Engine.
June 18, 2026
The Agent Identity API (agentidentity.googleapis.com) is
available in Preview.
This new API replaces the legacy IAM Connectors API
(iamconnectors.googleapis.com) for managing auth providers and agent
identities.
During the preview migration period, both APIs operate side-by-side. Existing
auth providers are automatically mirrored to the new V2 resource hierarchy
(authProviders/), allowing you to migrate your IAM policies,
agent code, and client applications without downtime.
June 15, 2026
You can use the error ID provided in permission error messages to help troubleshoot access. Error IDs provide context for the error, including the principal, resource, permission, and supported IAM conditions. This feature is available in Preview.
For more information, see Permission error messages.
May 08, 2026
You can use the IAM recommender to remediate excessive permissions for Google groups by transitioning from permanent role bindings to temporary, on-demand entitlements in Privileged Access Manager (PAM). This feature is in Preview.
To learn how to remediate excessive permissions, see Remediate excessive permissions with Privileged Access Manager.
April 22, 2026
Privileged Access Manager supports agent identities as grant requesters and approvers.
This feature is available in preview.
For more information, see Privileged Access Manager overview.
Agent Identity auth manager is available in preview. You can use Agent Identity auth manager to help securely authenticate your agents to third-party services using 3-legged OAuth, 2-legged OAuth, or API keys.
For more information, see Agent Identity auth manager.
Agent Identity is generally available (GA). Agent Identity provides a strongly attested, cryptographic identity for each agent that is tied to the lifecycle of the resource hosting the agent.
For more information, see Agent Identity overview.
April 13, 2026
Requesters can schedule grant requests in Privileged Access Manager up to seven days in advance. This lets requesters align access with scheduled maintenance or on-call shifts.
This feature is in preview.
For more information, see Privileged Access Manager overview.
April 07, 2026
Organization Policy Service custom constraints are available for managed workload identity and Workload Identity Federation. You can use custom constraints to control how managed workload identity and Workload Identity Federation are used in your organization. For more information, see Custom organization policy constraints for managed workload identity and Custom organization policy constraints for Workload Identity Federation.
March 31, 2026
Gemini assistance in the IAM role picker is generally available.
For more information, see Get predefined role suggestions with Gemini assistance.
March 18, 2026
Managed workload identities are generally available.
For more information, see Managed workload identities overview.
March 03, 2026
Service account principal sets are generally available. You can use service account principal sets to reference all service accounts or service agents in a project, folder, or organization when writing allow policies, deny policies, and access policies.
February 27, 2026
The ability to self-grant missing permissions from permission error messages is generally available.
To learn how to request missing permissions, see Request missing permissions.
You can disable the option to send auto-generated access requests from permission error messages. This feature is in preview.
To learn how to disable these requests, see Disable auto-generated access request emails.
December 15, 2025
You can ask Gemini for predefined role suggestions (preview) without enabling any APIs.
In addition, you can get custom role suggestions from Gemini using the Cloud Assist panel in the Google Cloud console.
For more information, see Get predefined role suggestions with Gemini assistance.
A new infinite-scrolling UI for audit logs is available on the Privileged Access Manager > Audit logs page in the Google Cloud console. This interface update replaces pagination with clear data loading indicators and time boundaries to help facilitate event investigations.
This feature is in preview.
September 26, 2025
For Privileged Access Manager, notification emails for grant activation, activation failure, or denial no longer include approver details.
To learn how to view the approver details, see Check grant status.
September 12, 2025
IAM offers predefined roles that are tailored to specific job functions. These roles cover all of the permissions that a user might need to perform their job. This feature is generally available.
For more information, see Predefined roles for job functions.
Permission errors in the Google Cloud console contain actionable steps for remediation. For more information, see Troubleshoot permission error messages.
July 21, 2025
You can ask Gemini for predefined role suggestions using the IAM role picker in the Google Cloud console. This feature is in preview.
For more information, see Get predefined role suggestions with Gemini assistance.
June 13, 2025
Conditions that check the tags for a resource can also check other attributes, such as the resource name of the timestamp of the request. This feature is available in Preview. For more information, see Resource tags.
May 28, 2025
Workforce Identity Federation supports detailed audit logging, which you can use to troubleshoot attribute mapping issues. This feature is generally available.
May 15, 2025
The predefined role reference and the permissions reference have been reorganized to improve performance and searchability. To see the new experience, visit the IAM roles and permissions index.
May 07, 2025
May 05, 2025
A new enforcement version, enforcement version 3, is available for principal access boundary policies. To learn more about enforcement versions and see the permissions that enforcement version 3 can block, see Permissions that principal access boundary policies can block.
February 24, 2025
Workforce Identity Federation can map up to 400 groups from Microsoft Entra ID. The feature is generally available. To learn more, see Configure Workforce Identity Federation with Microsoft Entra ID and a large number of groups.
Workforce Identity Federation supports an attribute mapping of up to 400 groups and a maximum size of 16 KB.
December 16, 2024
Principal access boundary policies are generally available. You can use principal access boundary policies to limit the resources that a principal is eligible to access.
December 09, 2024
Using IAM attributes in custom organization policies is generally available. For more information, see Use custom organization policies.
You can use the iam.managed.preventPrivilegedBasicRolesForDefaultServiceAccounts managed organization policy constraint to prevent default service accounts from being granted the Editor (roles/editor) or Owner (roles/owner) roles. For more information, see Prevent the Owner and Editor role from being granted to default service accounts.
September 16, 2024
Privileged Access Manager (PAM) is now released to General Availability. The following features have been added:
- Alerting on any external modifications to access grants outside of PAM.
- VPC Service Controls integration for PAM, which allows customers to enforce authorized network access or require specific access context while using PAM.
- Pub/Sub integration for custom alerting and monitoring.
September 12, 2024
You can manage IAM deny policies using the Google Cloud console. For more information, see Deny access to resources.
August 12, 2024
You can attach tags to Identity and Access Management (IAM) service accounts to conditionally grant or deny access to specific service accounts. This feature is in Preview. For more information, see Creating and managing tags for service accounts.
July 30, 2024
You can use IAM attributes in custom organization policies to control how your allow policies can be modified. For more information, see Use custom organization policies.
June 10, 2024
You can use principal access boundary policies to limit the resources that a principal is eligible to access. This feature is available in Preview.
May 08, 2024
Privileged Access Manager (PAM) lets you manage just-in-time temporary privilege elevation for select principals, and to view audit logs afterwards to find out who had access to what and when. This feature is in Preview.
May 03, 2024
As of May 3, 2024, when you create a new organization, it enforces the following organization policy constraints by default:
iam.disableServiceAccountKeyCreationiam.disableServiceAccountKeyUploadiam.automaticGrantsForDefaultServiceAccountsiam.allowedPolicyMemberDomains
For more information, see Restricting service account usage and Restricting identities by domain.
March 15, 2024
You can use the iam.serviceAccountKeyExposureResponse organization policy
constraint to help manage leaked service account credentials.
March 05, 2024
To improve performance, we've removed the ability to expand abbreviated permissions in the predefined roles table. You can still filter the predefined roles table based on the full list of permissions included in a role.
February 15, 2024
Managed workload identities let you bind strongly attested identities to your Compute Engine workloads. The feature is in Preview. Google Cloud provisions X.509 credentials, issued from Certificate Authority Service, that can be used to reliably authenticate your workload with other workloads over mutual TLS (mTLS) authentication. For more information, see Managed workload identities overview.
January 17, 2024
IAM deny policies let you deny groups of permissions for certain services. For more information, see Permission groups.
December 11, 2023
You can use identities from workforce and workload identity pools in IAM deny policies. For more information, see Principal identifiers.
September 27, 2023
You can now configure IAM workforce identity federation using the Google Cloud console. To learn more, see the configuration guides for Azure AD, Okta, or other OIDC and SAML 2.0 providers. The feature is in General Availability (GA).
September 13, 2023
You can now configure IAM workforce identity federation using the Google Cloud console. To learn more, see the configuration guides for Azure AD, Okta, or other OIDC and SAML 2.0 providers. The feature is in Preview.
August 14, 2023
For Credential Access Boundaries, removed the requirement to enable uniform bucket-level access for your Cloud Storage bucket.
July 11, 2023
Workforce identity federation now supports browser-based sign-in with the Google Cloud CLI. The feature is generally available (GA). To use it, see Browser-based sign-in in Obtain short-lived tokens for workforce identity federation, or locate the Browser-based sign-in section in the configuration guide for your identity provider.
June 22, 2023
You can trigger service agent creation instead of waiting for service agents to be created automatically. This feature is in Preview.
April 05, 2023
Workforce identity federation and workload identity federation can now accept encrypted SAML assertions. The feature is generally available (GA). To use the feature, locate the Create the workload identity pool and provider section in the configuration guide for your identity provider and follow the gcloud CLI instructions for the SAML workflow.
March 13, 2023
Workforce identity federation now supports browser-based sign-in with the Google Cloud CLI. The feature is in Preview. To use it, see Browser-based sign-in in Obtain short-lived tokens for workforce identity federation, or locate the Browser-based sign-in section in the configuration guide for your identity provider.
March 07, 2023
You can now set an expiry time for all newly created service account keys in your project, folder, or organization. This feature is generally available (GA).
March 03, 2023
The IAM documentation has been reorganized. We made the following changes:
- Reorganized the left-hand navigation for the Guides tab.
- Removed the Support tab and relocated its documents to the Resources and Guides tabs.
February 10, 2023
Workforce identity federation is generally available (GA). The feature lets you use an external identity provider to authenticate and authorize users to access supported Google Cloud products.
December 14, 2022
For information about issues with workforce identity federation, see Troubleshoot workforce identity federation
December 01, 2022
For some users, the IAM basic and predefined roles reference is crashing or is very slow to load. We are working to mitigate this issue.
November 09, 2022
You can use the Google Cloud console to view authentication activities, which indicate when your service accounts and keys were last used to call a Google API.
October 25, 2022
Deny policies are generally available (GA). Use deny policies to prevent principals from using certain permissions, regardless of the roles they're granted.