Principal Access Boundary policies can block all permissions that are included in the policy's enforcement version. If a Principal Access Boundary policy can block a permission, then it can prevent principals from using that permission to access resources.
You specify a policy's enforcement version when you create the policy. Updating the enforcement version updates the permissions that the policy can block.
If Principal Access Boundary policies can't block a permission, then they have no effect on whether principals can use the permission. In other words, IAM can't enforce the policy for access attempts involving that permission.
Periodically, IAM adds new Principal Access Boundary enforcement versions that can block additional permissions. Each new version can also block all of the permissions in the previous version.
This page lists the permissions that each enforcement version can block.
For more information about how to set and manage enforcement versions, see Manage enforcement versions.
Default enforcement version
The default enforcement version is used for the following Principal Access Boundary policies:
- New policies that don't specify a version number
- Policies that use the value
latestfor the version
The current default enforcement version is
4.
Enforcement version 4
Policies with enforcement version 4 can block all of the permissions listed in
the following enforcement versions:
Additionally, policies with the enforcement
version 4 can also block all of the permissions listed in the following table.
Each row contains the following information:
- The name of a service with permissions that Principal Access Boundary policies can block.
The permissions for that service that Principal Access Boundary policies can block.
In some cases, a section of a permission name is replaced with a wildcard character (
*). This format indicates that Principal Access Boundary policies can block all permissions that match that pattern.
| Service | Permissions | Exceptions |
|---|---|---|
| BigQuery sharing |
|
None |
| BigQuery |
|
None |
| Cloud Deploy |
|
None |
| Filestore |
|
None |
| Network Connectivity Center |
|
None |
| Certificate Authority Service |
|
None |
| Identity and Access Management |
|
|
| Live Stream |
|
None |
| Document AI |
|
None |
| Security Center Management API |
|
None |
| Web Security Scanner |
|
None |
| Security Command Center |
|
None |
| Cloud Quotas |
|
None |
| Recommender |
|
None |
| AlloyDB for PostgreSQL |
|
|
| App Hub |
|
None |
| Cloud Integrations |
|
|
| Backup for GKE |
|
None |
| Managed Service for Apache Airflow |
|
None |
| Cloud Data Fusion |
|
None |
| Cloud Key Management Service |
|
|
| Firebase Storage |
|
None |
| Translation |
|
|
| Cloud Workstations |
|
None |
| Confidential Computing |
|
None |
| Google Cloud Contact Center as a Service |
|
None |
| Database Migration Service |
|
|
| Dataform |
|
|
| Datastream |
|
None |
| Infrastructure Manager |
|
None |
| Parallelstore |
|
None |
| Policy Simulator |
|
None |
| Secret Manager |
|
None |
| Serverless VPC Access |
|
None |
| Service Usage |
|
None |
| Cloud Asset Inventory |
|
None |
| Kubernetes Metadata API |
|
None |
| Service Management |
|
None |
| Backup and Disaster Recovery |
|
|
| Sensitive Data Protection |
|
None |
| Secure Source Manager |
|
None |
| Connectors |
|
|
| Dataproc Metastore |
|
|
Enforcement version 3
Policies with enforcement version 3 can block all of the permissions listed in
the following enforcement versions:
Additionally, policies with the enforcement
version 3 can also block all of the permissions listed in the following table.
Each row contains the following information:
- The name of a service with permissions that Principal Access Boundary policies can block.
The permissions for that service that Principal Access Boundary policies can block.
In some cases, a section of a permission name is replaced with a wildcard character (
*). This format indicates that Principal Access Boundary policies can block all permissions that match that pattern.
| Service | Permissions | Exceptions |
|---|---|---|
| Essential Contacts |
|
None |
| Identity and Access Management |
|
|
| Managed Service for Apache Spark |
|
None |
| Service Management |
|
None |
| Bigtable |
|
None |
| Cloud Bigtable Admin API |
|
None |
| Cloud SQL |
|
None |
| Network Services |
|
None |
| Cloud Service Mesh |
|
None |
| Network Management API |
|
None |
| Compute Engine |
|
None |
| Artifact Registry |
|
None |
| Pub/Sub |
|
None |
| Workflows |
|
None |
| Google Distributed Cloud |
|
None |
| API Keys |
|
None |
| Cloud DNS |
|
None |
| Firestore |
|
None |
| Cloud Key Management Service |
|
|
| Organization Policy Service |
|
None |
| Knowledge Catalog |
|
None |
| Data Lineage API |
|
None |
| GKE Hub |
|
None |
| Cloud Run functions |
|
None |
| Spanner |
|
None |
| Google Kubernetes Engine |
|
None |
Enforcement version 2
Policies with enforcement version 2 can block all of the permissions listed in
Enforcement version 1. Additionally, policies with the enforcement
version 2 can also block all of the permissions listed in the following table.
Each row contains the following information:
- The name of a service with permissions that Principal Access Boundary policies can block.
The permissions for that service that Principal Access Boundary policies can block.
In some cases, a section of a permission name is replaced with a wildcard character (
*). This format indicates that Principal Access Boundary policies can block all permissions that match that pattern.
| Service | Permissions | Exceptions |
|---|---|---|
| Access Context Manager |
|
None |
| Artifact Analysis |
|
None |
| BigQuery |
|
None |
| BigQuery Data Policy |
|
None |
| BigQuery Data Transfer Service |
|
None |
| Chrome Enterprise Premium |
|
None |
| Cloud Asset Inventory |
|
None |
| Cloud Billing |
|
None |
| Cloud Build |
|
None |
| Cloud Monitoring |
|
|
| Cloud Service Mesh |
|
None |
| Cloud Storage |
|
None |
| Cloud Trace |
|
None |
| Compute Engine |
|
None |
| Firebase Security Rules |
|
None |
| GKE Multi-Cloud |
|
None |
| Identity-Aware Proxy |
|
None |
| Memorystore for Redis |
|
None |
| Network Management API |
|
None |
| Network Services |
|
None |
| Google Cloud Fraud Defense |
|
None |
| Resource Manager |
|
|
| Video Stitcher API |
|
None |
Enforcement version 1
The following table lists the permissions that Principal Access Boundary policies
with enforcement version 1 can block.
Each row contains the following information:
- The name of a service with permissions that Principal Access Boundary policies can block.
The permissions for that service that Principal Access Boundary policies can block.
In some cases, a section of a permission name is replaced with a wildcard character (
*). This format indicates that Principal Access Boundary policies can block all permissions that match that pattern.The permissions for the service that Principal Access Boundary can't block, even if those permissions match one of the supported permission patterns.
| Service | Permissions | Exceptions |
|---|---|---|
| Access Approval |
|
None |
| Access Context Manager |
|
|
| BigQuery |
|
None |
| Binary Authorization |
|
None |
| Cloud Logging |
|
None |
| Cloud Run |
|
None |
| Cloud Storage |
|
None |
| Dataflow |
|
|
| Firestore |
|
None |
| Firebase Security Rules |
|
None |
| GKE Hub |
|
|
| Pub/Sub |
|
|
| Memorystore for Redis |
|
None |
| Gemini Enterprise Agent Platform |
|
|