configuring-identity-aware-proxy-with-google-iap - Configure Google IAP identity-based access controls
Configure Google Cloud IAP for identity verification, context-aware access, session controls, service accounts, and audit logging.
Tags
Updated: 2026-09-29Capabilities
What this skill does
- Enable IAP on GCP services
- Configure IAM access bindings
- Create context-based access levels
- Set session reauthentication policies
- Configure service account access
- Enable IAP audit logging
Inputs
- Google Cloud project
- OAuth client credentials
- IAM users and groups
- Access policy identifiers
- Device and network conditions
- Service account credentials
- Protected resource URLs
- Session policy settings
Outputs
- IAP-protected services
- IAM access policies
- Access context levels
- Session and reauthentication settings
- Authenticated service requests
- IAP audit logs
- Denied-access metrics
Requirements
- Google Cloud project with billing enabled
- IAP API enabled
- Application behind HTTPS Load Balancer, App Engine, or Cloud Run
- Cloud Identity or Google Workspace
- Access Context Manager API enabled
- OAuth consent screen configured
