Google Cloud Identity & Identity-Aware Proxy (IAP)
by Google Cloud
Cloud Identity manages users and groups; IAP provides an authorization layer in front of HTTPS apps and VM access (Google’s description).
Cloud Identity
Google’s Identity-as-a-Service: centrally manages users and groups, integrates with IAM, and federates with other identity providers such as Active Directory and Microsoft Entra ID. Editions: Free and Premium (feature comparison on the Cloud Identity editions page).
Identity-Aware Proxy
- Protects, per Google’s overview: App Engine, Cloud Run, Compute Engine, GKE, on-premises apps (via connector), Cloud Storage buckets, and Cloud Load Balancing (external and internal HTTP(S)).
- Authenticates with Google Accounts, Workforce Identity Federation or Identity Platform; authorises through IAM (for example the “IAP-secured Web App User” role).
- Context-aware access for console/APIs, VMs (SSH/RDP) and web apps; IAP TCP forwarding lets you reach VMs without public SSH/RDP ports; works with VPC Service Controls.
- Intended as an identity-based alternative to VPN for HTTP apps (zero-trust style; positioning, not verified here).
Signed headers (corrected)
- IAP adds
x-goog-iap-jwt-assertion(signed JWT) plus convenience headersx-goog-authenticated-user-emailandx-goog-authenticated-user-id. - Verify the JWT: issuer
https://cloud.google.com/iap; public keys athttps://www.gstatic.com/iap/verify/public_key(or the-jwkvariant); audience depends on the resource, e.g. Cloud Run/projects/PROJECT_NUMBER/locations/REGION/services/SERVICE_NAME, Compute Engine/GKE/projects/PROJECT_NUMBER/global/backendServices/SERVICE_ID. - Google warns that if an attacker bypasses IAP they can forge the unsigned headers, so never trust the email header alone. (An earlier version of this note pointed to the generic Google OAuth certs URL; that was wrong for IAP.)
Deployment notes
- Enable IAP at one place per ingress path (service or load balancer), and make sure firewall/internal routing cannot bypass it.
- IAP uses an OAuth client managed by Google; deleting it breaks flows.
- Audit via Cloud Audit Logs.
Related products
- BeyondCorp Enterprise is reportedly now called Chrome Enterprise Premium (search coverage; rename date and tier details not verified here).
- Related notes: Cloud Load Balancing, Cloud Run, GKE, Google Workspace.
Billing model
The fetched IAP overview does not discuss pricing; check the IAP and Cloud Identity pricing pages, and note that load balancer resources used with IAP are billed normally.
Sources
- IAP overview: https://docs.cloud.google.com/iap/docs/concepts-overview (fetched 2026-10-05)
- Signed headers: https://docs.cloud.google.com/iap/docs/signed-headers-howto (fetched 2026-10-05)
- Cloud Identity overview: https://docs.cloud.google.com/identity/docs/overview (fetched 2026-10-05)
- Chrome Enterprise Premium: https://docs.cloud.google.com/chrome-enterprise-premium/docs/access-protection (seen in search results 2026-10-05)
Open items
- Whether IAP itself has a charge not confirmed; Chrome Enterprise Premium rename date not confirmed.