configuring-identity-aware-proxy-with-google-iap - Configure Google IAP identity-aware access
Configure Google Cloud IAP to enforce identity, context, session, and programmatic access controls for cloud applications and TCP services.
Tags
Updated: 2026-09-29Google IAPidentity-aware proxyGoogle Cloudzero trustaccess controlcontext-aware accessCloud RunApp EngineGKE
Capabilities
What this skill does
- Enable IAP on services
- Grant conditional IAM access
- Create device access levels
- Configure session reauthentication
- Enable service account access
- Configure IAP audit logging
- Monitor denied access
Inputs
- Google Cloud project
- Application platform
- OAuth client credentials
- IAM users and groups
- Access policy identifiers
- Device and network conditions
- Session settings
- Service account credentials
- IAP-protected URL
Outputs
- Enabled IAP configuration
- IAM access bindings
- Context-aware access levels
- Session reauthentication settings
- Authenticated service requests
- IAP audit logs
- Denied-access log metric
Requirements
- Google Cloud project with billing
- IAP API enabled
- Access Context Manager API enabled
- Application behind HTTPS Load Balancer, App Engine, or Cloud Run
- Cloud Identity or Google Workspace
- Configured OAuth consent screen
