Identity-Aware Proxy roles and permissions Stay organized with collections Save and categorize content based on your preferences.
This page lists the IAM roles and permissions for Identity-Aware Proxy. Tosearch through all roles and permissions, see therole andpermission index.
Identity-Aware Proxy roles
| Role | Permissions |
|---|---|
IAP Policy Admin( Provides full access to Identity-Aware Proxy resources. |
|
IAP-secured Web App User( Provides permission to access HTTPS resources which use Identity-Aware Proxy. |
|
IAP-secured Resource Remediator UserBeta( Remediate IAP resource |
|
IAP Settings Admin( Administrator of IAP Settings. |
|
IAP-secured Tunnel Destination Group Editor( Edit Tunnel Destination Group resources which use Identity-Aware Proxy |
|
IAP-secured Tunnel Destination Group Viewer( View Tunnel Destination Group resources which use Identity-Aware Proxy |
|
IAP-secured Tunnel User( Access Tunnel resources which use Identity-Aware Proxy |
|
Identity-Aware Proxy permissions
| Permission | Included in roles |
|---|---|
| Owner ( Editor ( Viewer ( Support User ( IAP Settings Admin ( |
| Owner ( Editor ( IAP Settings Admin ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( IAP-secured Tunnel User ( |
| Owner ( Editor ( IAP-secured Tunnel Destination Group Editor ( |
| Owner ( Editor ( IAP-secured Tunnel Destination Group Editor ( |
| Owner ( Editor ( Viewer ( Support User ( IAP-secured Tunnel Destination Group Editor ( IAP-secured Tunnel Destination Group Viewer ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Editor ( Viewer ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( IAP-secured Tunnel Destination Group Editor ( IAP-secured Tunnel Destination Group Viewer ( |
| Owner ( IAP-secured Resource Remediator User ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( Editor ( IAP-secured Tunnel Destination Group Editor ( |
| Owner ( IAP-secured Tunnel User ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( IAP-secured Resource Remediator User ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Editor ( Viewer ( Support User ( IAP Settings Admin ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( Editor ( IAP Settings Admin ( |
| IAP-secured Web App User ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Editor ( Viewer ( Support User ( IAP Settings Admin ( |
| Owner ( IAP-secured Resource Remediator User ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( Editor ( IAP Settings Admin ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Editor ( Viewer ( Support User ( IAP Settings Admin ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( Editor ( IAP Settings Admin ( |
| Owner ( Security Admin ( Security Auditor ( Security Reviewer ( IAP Policy Admin ( |
| Owner ( Editor ( Viewer ( Support User ( IAP Settings Admin ( |
| Owner ( Security Admin ( IAP Policy Admin ( |
| Owner ( Editor ( IAP Settings Admin ( |
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-12-15 UTC.