Skip to main content
Cloud / Google Cloud / Products / Access Context Manager - Attribute-Based Access Control

Access Context Manager - Attribute-Based Access Control

Access Context Manager defines access levels and service perimeters for fine-grained, attribute-based access control in Google Cloud.

Security
Pricing Model Free: according to the official pricing page there is no cost for using Access Context Manager
Availability Organization-wide service; access policies are created in the context of an organization
Data Sovereignty As published by the provider / see official documentation
Reliability As published by the provider / see official documentation SLA

Access Context Manager defines fine-grained, attribute-based access rules for Google Cloud resources, serving as the shared foundation for VPC Service Controls, Identity-Aware Proxy, and IAM conditions.

What is Access Context Manager?

Google Cloud organization administrators use Access Context Manager to define fine-grained, attribute-based access control for projects and resources in Google Cloud. As an administrator, you first define an access policy - an organization-wide container for access levels and service perimeters.

Access levels describe the requirements for requests to be honored. Examples include device type and operating system, IP address, and user identity. Service perimeters define sandboxes of resources: resources within the perimeter can freely exchange data but cannot export data outside of the perimeter.

Access Context Manager is not responsible for policy enforcement. Rather, it is designed to define specific rules or context. Policy is configured and enforced across various points, such as VPC Service Controls.

Core Features

  • Access policy: Organization-wide container for all Access Context Manager resources
  • Access levels: Conditions for honoring requests, such as device type, operating system, IP address, or user identity
  • Service perimeters: Bounded sets of resources from which data cannot be exported outside
  • Integration points: Configuration and enforcement through VPC Service Controls, Identity-Aware Proxy, Context-Aware Access for Google Workspace, and IAM conditions

Typical Use Cases

Device-context-based access

Granting access to sensitive projects only from devices of a defined type and operating system, rather than deciding based on network location alone.

Limiting data exfiltration

Placing service perimeters around projects that hold particularly sensitive data so that exporting that data outside the perimeter is blocked.

Mobile work and BYOD

Making access decisions based on request context when the workforce is mobile and uses its own devices - a model Google developed as part of the BeyondCorp effort.

Conditional access at the IAM layer

Combining access levels with IAM conditions so that roles only take effect under specific contextual conditions.

Benefits

  • No cost for the service: According to the official pricing page, there is no cost for using Access Context Manager
  • Context instead of a network boundary: Access is decided based on device, identity, and further attributes, not on network position alone
  • Central definition: One organization-wide access policy as the shared foundation for several enforcement points
  • Smaller privileged network: Endpoints no longer carry ambient authority based on the network alone

Integration with innFactory

As a certified Google Cloud partner, innFactory supports you with Access Context Manager: designing the access policy, defining access levels and service perimeters, and aligning them with VPC Service Controls and IAM.

Contact us for a consultation on Access Context Manager.

Available Tiers & Options

Typical Use Cases

Fine-grained, attribute-based access control for projects and resources
Defining service perimeters to limit data exfiltration
Access decisions based on device type, operating system, IP address, and user identity
Implementing a BeyondCorp-oriented access model

Technical Specifications

Access policy Organization-wide container for access levels and service perimeters
Attributes Device type and operating system, IP address, and user identity, among others
Context Part of the Chrome Enterprise Premium solution components and of Google's BeyondCorp effort
Enforcement Through VPC Service Controls, Identity-Aware Proxy, Context-Aware Access for Google Workspace, and IAM conditions

Frequently Asked Questions

What is Access Context Manager?

Google Cloud organization administrators use Access Context Manager to define fine-grained, attribute-based access control for projects and resources in Google Cloud. You first define an access policy, an organization-wide container for access levels and service perimeters.

What is the difference between an access level and a service perimeter?

Access levels describe the requirements for requests to be honored - examples include device type and operating system, IP address, and user identity. Service perimeters define sandboxes of resources: resources within the perimeter can freely exchange data but cannot export data outside of the perimeter.

Does Access Context Manager enforce policy itself?

No. Access Context Manager is not responsible for policy enforcement; it is designed to define specific rules or context. Policy is configured and enforced across various points, such as VPC Service Controls.

What does Access Context Manager cost?

According to the official pricing page, there is no cost for using Access Context Manager. Costs may arise from the connected services in which the policies are configured and enforced.

Which services can Access Context Manager be combined with?

Per the documentation, you can configure and enforce Access Context Manager policies across the following Chrome Enterprise Premium solution components: VPC Service Controls, Identity-Aware Proxy, Context-Aware Access for Google Workspace, and IAM conditions.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Ready to start with Access Context Manager - Attribute-Based Access Control?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation