This page lists the IAM roles and permissions for Managed Service for Microsoft Active Directory. To search through all roles and permissions, see the role and permission index.
Managed Service for Microsoft Active Directory roles
| Role | Permissions |
|---|---|
Google Cloud Managed Identities Admin( Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level. |
|
Managedidentities Editor( Editor role for managedidentities |
|
Google Cloud Managed Identities Viewer( Read-only access to Google Cloud Managed Identities Domains and related resources. |
|
Google Cloud Managed Identities Backup Admin( Full access to Google Cloud Managed Identities Backup and related resources. Intended to be granted on a project-level |
|
Google Cloud Managed Identities Backup Viewer( Read-only access to Google Cloud Managed Identities Backup and related resources. |
|
Google Cloud Managed Identities Domain Admin( Read-Update-Delete to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a resource (domain) level. |
|
Google Cloud Managed Identities Domain Join Beta( Access to domain join VMs with Cloud AD |
|
Google Cloud Managed Identities Peering Admin( Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level |
|
Google Cloud Managed Identities Peering Viewer( Read-only access to Google Cloud Managed Identities Peering and related resources. |
|
Service agent roles
Service agent roles should only be granted to service agents.
| Role | Permissions |
|---|---|
Cloud Managed Identities Service Agent( Gives Managed Identities service account access to managed resources. |
|
Managed Service for Microsoft Active Directory permissions
| Permission | Included in roles |
|---|---|
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Security Admin (
Google Cloud Managed Identities Admin (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Support User (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor ( |
|
Owner (
Google Cloud Managed Identities Admin (
Tag User (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Google Cloud Managed Identities Admin (
Tag User (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin (
Google Cloud Managed Identities Domain Join ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin (
Google Cloud Managed Identities Domain Join ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Tag User (
Tag Viewer (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Security Auditor (
Support User (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Tag User (
Tag Viewer (
DLP Organization Data Profiles Driver (
DLP Project Data Profiles Driver (
Security Auditor (
Support User (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Security Admin (
Google Cloud Managed Identities Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Support User (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin (
Google Cloud Managed Identities Peering Admin (
Google Cloud Managed Identities Peering Viewer ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin (
Google Cloud Managed Identities Peering Admin (
Google Cloud Managed Identities Peering Viewer ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Peering Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Peering Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin (
Google Cloud Managed Identities Peering Admin (
Google Cloud Managed Identities Peering Viewer ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Backup Admin (
Google Cloud Managed Identities Backup Viewer (
Google Cloud Managed Identities Domain Admin (
Google Cloud Managed Identities Peering Admin (
Google Cloud Managed Identities Peering Viewer ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Peering Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Peering Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Support User (
Google Cloud Managed Identities Peering Admin (
Google Cloud Managed Identities Peering Viewer ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Peering Admin (
Google Cloud Managed Identities Peering Viewer ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Peering Admin (
Google Cloud Managed Identities Peering Viewer ( |
|
Owner (
Security Admin (
Google Cloud Managed Identities Admin (
Google Cloud Managed Identities Peering Admin ( |
|
Owner (
Editor (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Peering Admin ( |
|
Owner (
Editor (
Viewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Support User (
Google Cloud Managed Identities Domain Admin ( |
|
Owner (
Editor (
Viewer (
Security Admin (
Security Reviewer (
Google Cloud Managed Identities Admin (
Managedidentities Editor (
Google Cloud Managed Identities Viewer (
Security Auditor (
Support User (
Google Cloud Managed Identities Domain Admin ( |