IAM release notes

This page documents production updates to Identity and Access Management. Check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

August 14, 2026

Feature

You can use custom constraints with Organization Policy to provide more granular control over specific fields for Agent Identity resources, such as agentidentity.googleapis.com/AuthProvider. For more information, see Use custom organization policies for Agent Identity. This feature is in GA.

Feature

Agent Identity VPC Service Controls (VPC Service Controls) integration is generally available. You can add the Agent Identity API (agentidentity.googleapis.com) and Agent Identity Credentials API (agentidentitycredentials.googleapis.com) to a service perimeter and specify agent identities in ingress and egress rules.

For more information, see Agent Identity overview.

August 12, 2026

Change

The workflow for creating workforce identity pool providers in the Google Cloud console changed. After submitting the initial provider configuration, the console directs you to a centralized page to configure provider attributes, including attribute mappings, attribute conditions, and extra attributes.

For more information, see Manage workforce identity pools and providers.

August 03, 2026

Feature

Organization Policy Service custom constraints are available for Privileged Access Manager (PAM). You can use custom constraints to restrict how users create and modify entitlements and grants. This feature is in Preview.

For more information, see Use custom organization policies for Privileged Access Manager.

July 27, 2026

Feature

Managed workload identities for Compute Engine are generally available.

For more information, see Configure managed workload identity authentication for Compute Engine.

June 18, 2026

Feature

The Agent Identity API (agentidentity.googleapis.com) is available in Preview. This new API replaces the legacy IAM Connectors API (iamconnectors.googleapis.com) for managing auth providers and agent identities.

During the preview migration period, both APIs operate side-by-side. Existing auth providers are automatically mirrored to the new V2 resource hierarchy (authProviders/), allowing you to migrate your IAM policies, agent code, and client applications without downtime.

June 15, 2026

Feature

You can use the error ID provided in permission error messages to help troubleshoot access. Error IDs provide context for the error, including the principal, resource, permission, and supported IAM conditions. This feature is available in Preview.

For more information, see Permission error messages.

May 08, 2026

Feature

You can use the IAM recommender to remediate excessive permissions for Google groups by transitioning from permanent role bindings to temporary, on-demand entitlements in Privileged Access Manager (PAM). This feature is in Preview.

To learn how to remediate excessive permissions, see Remediate excessive permissions with Privileged Access Manager.

April 22, 2026

Feature

Privileged Access Manager supports agent identities as grant requesters and approvers.

This feature is available in preview.

For more information, see Privileged Access Manager overview.

Feature

Agent Identity auth manager is available in preview. You can use Agent Identity auth manager to help securely authenticate your agents to third-party services using 3-legged OAuth, 2-legged OAuth, or API keys.

For more information, see Agent Identity auth manager.

Feature

Agent Identity is generally available (GA). Agent Identity provides a strongly attested, cryptographic identity for each agent that is tied to the lifecycle of the resource hosting the agent.

For more information, see Agent Identity overview.

April 13, 2026

Feature

Requesters can schedule grant requests in Privileged Access Manager up to seven days in advance. This lets requesters align access with scheduled maintenance or on-call shifts.

This feature is in preview.

For more information, see Privileged Access Manager overview.

April 07, 2026

Feature

Organization Policy Service custom constraints are available for managed workload identity and Workload Identity Federation. You can use custom constraints to control how managed workload identity and Workload Identity Federation are used in your organization. For more information, see Custom organization policy constraints for managed workload identity and Custom organization policy constraints for Workload Identity Federation.

March 31, 2026

Feature

Gemini assistance in the IAM role picker is generally available.

For more information, see Get predefined role suggestions with Gemini assistance.

March 18, 2026

Feature

Managed workload identities are generally available.

For more information, see Managed workload identities overview.

March 03, 2026

Feature

Service account principal sets are generally available. You can use service account principal sets to reference all service accounts or service agents in a project, folder, or organization when writing allow policies, deny policies, and access policies.

February 27, 2026

Feature

The ability to self-grant missing permissions from permission error messages is generally available.

To learn how to request missing permissions, see Request missing permissions.

Feature

You can disable the option to send auto-generated access requests from permission error messages. This feature is in preview.

To learn how to disable these requests, see Disable auto-generated access request emails.

December 15, 2025

Change

You can ask Gemini for predefined role suggestions (preview) without enabling any APIs.

In addition, you can get custom role suggestions from Gemini using the Cloud Assist panel in the Google Cloud console.

For more information, see Get predefined role suggestions with Gemini assistance.

Feature

A new infinite-scrolling UI for audit logs is available on the Privileged Access Manager > Audit logs page in the Google Cloud console. This interface update replaces pagination with clear data loading indicators and time boundaries to help facilitate event investigations.

This feature is in preview.

September 26, 2025

Change

For Privileged Access Manager, notification emails for grant activation, activation failure, or denial no longer include approver details.

To learn how to view the approver details, see Check grant status.

September 12, 2025

Feature

IAM offers predefined roles that are tailored to specific job functions. These roles cover all of the permissions that a user might need to perform their job. This feature is generally available.

For more information, see Predefined roles for job functions.

Feature

Permission errors in the Google Cloud console contain actionable steps for remediation. For more information, see Troubleshoot permission error messages.

July 21, 2025

Feature

You can ask Gemini for predefined role suggestions using the IAM role picker in the Google Cloud console. This feature is in preview.

For more information, see Get predefined role suggestions with Gemini assistance.

June 13, 2025

Change

Conditions that check the tags for a resource can also check other attributes, such as the resource name of the timestamp of the request. This feature is available in Preview. For more information, see Resource tags.

May 28, 2025

Feature

Workforce Identity Federation supports detailed audit logging, which you can use to troubleshoot attribute mapping issues. This feature is generally available.

May 15, 2025

Change

The predefined role reference and the permissions reference have been reorganized to improve performance and searchability. To see the new experience, visit the IAM roles and permissions index.

May 07, 2025

May 05, 2025

Change

A new enforcement version, enforcement version 3, is available for principal access boundary policies. To learn more about enforcement versions and see the permissions that enforcement version 3 can block, see Permissions that principal access boundary policies can block.

February 24, 2025

Feature

Workforce Identity Federation can map up to 400 groups from Microsoft Entra ID. The feature is generally available. To learn more, see Configure Workforce Identity Federation with Microsoft Entra ID and a large number of groups.

Change

Workforce Identity Federation supports an attribute mapping of up to 400 groups and a maximum size of 16 KB.

December 16, 2024

Change

Principal access boundary policies are generally available. You can use principal access boundary policies to limit the resources that a principal is eligible to access.

December 09, 2024

Change

Using IAM attributes in custom organization policies is generally available. For more information, see Use custom organization policies.

Feature

You can use the iam.managed.preventPrivilegedBasicRolesForDefaultServiceAccounts managed organization policy constraint to prevent default service accounts from being granted the Editor (roles/editor) or Owner (roles/owner) roles. For more information, see Prevent the Owner and Editor role from being granted to default service accounts.

September 16, 2024

Feature

Privileged Access Manager (PAM) is now released to General Availability. The following features have been added:

September 12, 2024

Change

You can manage IAM deny policies using the Google Cloud console. For more information, see Deny access to resources.

August 12, 2024

Feature

You can attach tags to Identity and Access Management (IAM) service accounts to conditionally grant or deny access to specific service accounts. This feature is in Preview. For more information, see Creating and managing tags for service accounts.

July 30, 2024

Feature

You can use IAM attributes in custom organization policies to control how your allow policies can be modified. For more information, see Use custom organization policies.

June 10, 2024

Feature

You can use principal access boundary policies to limit the resources that a principal is eligible to access. This feature is available in Preview.

May 08, 2024

Feature

Privileged Access Manager (PAM) lets you manage just-in-time temporary privilege elevation for select principals, and to view audit logs afterwards to find out who had access to what and when. This feature is in Preview.

May 03, 2024

Change

As of May 3, 2024, when you create a new organization, it enforces the following organization policy constraints by default:

  • iam.disableServiceAccountKeyCreation
  • iam.disableServiceAccountKeyUpload
  • iam.automaticGrantsForDefaultServiceAccounts
  • iam.allowedPolicyMemberDomains

For more information, see Restricting service account usage and Restricting identities by domain.