Skip to main content
Cloud / Google Cloud / Products / Identity-Aware Proxy (IAP) - Access Protection Without a VPN

Identity-Aware Proxy (IAP) - Access Protection Without a VPN

Identity-Aware Proxy provides a central authorization layer for applications, replacing network-level access control with application-level access control.

Security
Pricing Model Pricing as published on the official Identity-Aware Proxy pricing page
Availability Global Google Cloud service
Data Sovereignty Regional deployment depends on the protected resources; see the official documentation for details
Reliability SLA as published by the provider SLA

What Is Identity-Aware Proxy?

Identity-Aware Proxy (IAP) is a global Google Cloud service that places a central authorization layer in front of applications accessed over HTTPS. Instead of controlling access through network-level firewalls, IAP evaluates every request at the application level: identity and authorization are checked before the request reaches the application.

Google positions IAP as a cloud-native alternative to traditional VPNs. Users reach applications directly through the browser; no client software and no network tunnel are required. Access policies are defined and enforced centrally in one place.

Core Capabilities

  • Central authorization layer for applications in Cloud Run, App Engine, Compute Engine, Google Kubernetes Engine, and for on-premises applications
  • Authentication through Google Accounts, Workforce Identity Federation, or Identity Platform
  • IAM-based authorization: IAP evaluates the relevant IAM policy; users need the “IAP-secured Web App User” role
  • Context-aware access policies based on user identity, group membership, device security, and contextual signals such as location or IP address
  • Signed headers and JWT for additional application-side verification; in the App Engine standard environment the Users API is available as an alternative
  • TCP forwarding for SSH and RDP access to VM instances
  • Automatic OAuth configuration: turning on IAP for a resource creates an OAuth 2.0 client ID and secret

Typical Use Cases

Internal applications without a VPN: Employees reach internal web applications through the browser. Access is authorized per application rather than through a blanket network grant.

Administrative access to VMs: TCP forwarding lets administrators reach VM instances over SSH or RDP without those instances needing a public IP address.

Zero-trust architectures: IAP provides continuous authorization and evaluates contextual signals such as device posture, location, or IP address.

Access for external identities: Workforce Identity Federation and Identity Platform let you connect external identity providers without creating separate Google Accounts.

Benefits

  • Access control at the application level instead of broad network access
  • No client software and no network tunnel required
  • Consistent policy management through IAM
  • Applicable to cloud resources and on-premises applications
  • Combines with context-based access conditions

Working with innFactory

As a certified Google Cloud Partner, innFactory supports you with Identity-Aware Proxy:

  • Architecture consulting: assessing which applications can be secured with IAP and how to move away from VPN-based access
  • Policy design: defining IAM and context-aware access policies for your application landscape
  • Integration: connecting existing identity providers through Workforce Identity Federation or Identity Platform
  • Operations: securing administrative access through TCP forwarding and integrating IAP into your monitoring and audit processes

Get in touch for a consultation on Identity-Aware Proxy and zero-trust architectures on Google Cloud.

Typical Use Cases

Access to internal web applications without a VPN
SSH and RDP access to VM instances without a public IP address
Context-aware access control by identity, group, device, and location
Zero-trust architectures for cloud and on-premises applications

Technical Specifications

Application integration Signed headers or JWT; in the App Engine standard environment also the Users API
Authentication Google Accounts, Workforce Identity Federation, or Identity Platform
Authorization IAM policy; access granted through the "IAP-secured Web App User" role
Protected resources Cloud Run, App Engine (standard and flexible), Compute Engine, Google Kubernetes Engine, and on-premises applications
Tcp forwarding SSH and RDP access to VM instances through IAP TCP forwarding

Frequently Asked Questions

What is Identity-Aware Proxy?

Identity-Aware Proxy (IAP) is a global Google Cloud service that lets you establish a central authorization layer for applications accessed over HTTPS. It applies an application-level access control model instead of relying on network-level firewalls. Google positions IAP as a cloud-native alternative to traditional VPNs.

Which resources can IAP protect?

IAP protects applications running in Cloud Run, App Engine (standard and flexible environments), Compute Engine, and Google Kubernetes Engine, as well as on-premises applications.

How does IAP authenticate users?

If a user is not signed in, IAP redirects them to sign in. Authentication methods are Google Accounts, Workforce Identity Federation for external identity providers, and Identity Platform. After sign-in the browser stores a token in a cookie, and IAP uses those credentials to determine the user's identity and email address.

How does authorization work?

IAP applies the relevant IAM policy to check whether the user is authorized to access the requested resource. To reach a protected application, users need the "IAP-secured Web App User" role.

Can IAP be used for SSH and RDP?

Yes. IAP TCP forwarding lets you open SSH and RDP connections to VM instances without exposing them through a public IP address.

What happens when IAP is turned on for a resource?

When you turn on IAP for a resource, the service automatically creates an OAuth 2.0 client ID and secret.

Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.

Google Cloud Partner

innFactory is a certified Google Cloud Partner. We provide expert consulting, implementation, and managed services.

Google Cloud Partner

Ready to start with Identity-Aware Proxy (IAP) - Access Protection Without a VPN?

Our certified Google Cloud experts help you with architecture, integration, and optimization.

Schedule Consultation