Access Context Manager defines fine-grained, attribute-based access rules for Google Cloud resources, serving as the shared foundation for VPC Service Controls, Identity-Aware Proxy, and IAM conditions.
What is Access Context Manager?
Google Cloud organization administrators use Access Context Manager to define fine-grained, attribute-based access control for projects and resources in Google Cloud. As an administrator, you first define an access policy - an organization-wide container for access levels and service perimeters.
Access levels describe the requirements for requests to be honored. Examples include device type and operating system, IP address, and user identity. Service perimeters define sandboxes of resources: resources within the perimeter can freely exchange data but cannot export data outside of the perimeter.
Access Context Manager is not responsible for policy enforcement. Rather, it is designed to define specific rules or context. Policy is configured and enforced across various points, such as VPC Service Controls.
Core Features
- Access policy: Organization-wide container for all Access Context Manager resources
- Access levels: Conditions for honoring requests, such as device type, operating system, IP address, or user identity
- Service perimeters: Bounded sets of resources from which data cannot be exported outside
- Integration points: Configuration and enforcement through VPC Service Controls, Identity-Aware Proxy, Context-Aware Access for Google Workspace, and IAM conditions
Typical Use Cases
Device-context-based access
Granting access to sensitive projects only from devices of a defined type and operating system, rather than deciding based on network location alone.
Limiting data exfiltration
Placing service perimeters around projects that hold particularly sensitive data so that exporting that data outside the perimeter is blocked.
Mobile work and BYOD
Making access decisions based on request context when the workforce is mobile and uses its own devices - a model Google developed as part of the BeyondCorp effort.
Conditional access at the IAM layer
Combining access levels with IAM conditions so that roles only take effect under specific contextual conditions.
Benefits
- No cost for the service: According to the official pricing page, there is no cost for using Access Context Manager
- Context instead of a network boundary: Access is decided based on device, identity, and further attributes, not on network position alone
- Central definition: One organization-wide access policy as the shared foundation for several enforcement points
- Smaller privileged network: Endpoints no longer carry ambient authority based on the network alone
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with Access Context Manager: designing the access policy, defining access levels and service perimeters, and aligning them with VPC Service Controls and IAM.
Contact us for a consultation on Access Context Manager.
Available Tiers & Options
Standard
- Free to use
- Organization-wide container for access levels and service perimeters
- Enforcement through VPC Service Controls, Identity-Aware Proxy, Context-Aware Access, and IAM conditions
- Access Context Manager defines rules but does not enforce them itself
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is Access Context Manager?
Google Cloud organization administrators use Access Context Manager to define fine-grained, attribute-based access control for projects and resources in Google Cloud. You first define an access policy, an organization-wide container for access levels and service perimeters.
What is the difference between an access level and a service perimeter?
Access levels describe the requirements for requests to be honored - examples include device type and operating system, IP address, and user identity. Service perimeters define sandboxes of resources: resources within the perimeter can freely exchange data but cannot export data outside of the perimeter.
Does Access Context Manager enforce policy itself?
No. Access Context Manager is not responsible for policy enforcement; it is designed to define specific rules or context. Policy is configured and enforced across various points, such as VPC Service Controls.
What does Access Context Manager cost?
According to the official pricing page, there is no cost for using Access Context Manager. Costs may arise from the connected services in which the policies are configured and enforced.
Which services can Access Context Manager be combined with?
Per the documentation, you can configure and enforce Access Context Manager policies across the following Chrome Enterprise Premium solution components: VPC Service Controls, Identity-Aware Proxy, Context-Aware Access for Google Workspace, and IAM conditions.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
