You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.
November 11, 2025
The list of Organization Policy Service constraints that are enforced when an organization resource is created has changed. The following Google Cloud security baseline constraints are enforced for all organizations created on or after May 3, 2024:
constraints/iam.managed.disableServiceAccountKeyCreationconstraints/iam.managed.disableServiceAccountKeyUploadconstraints/iam.automaticIamGrantsForDefaultServiceAccountsconstraints/iam.allowedPolicyMemberDomainsconstraints/essentialcontacts.managed.allowedContactDomainsconstraints/compute.managed.restrictProtocolForwardingCreationForTypesconstraints/storage.uniformBucketLevelAccess
For more information, see Google Cloud security baseline constraints.
November 05, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some BigQuery resources. For more information, see Manage BigQuery resources using custom constraints. This feature is generally available (GA).
October 14, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Datastream resources. For more information, see Manage Application Integration resources using custom constraints. This feature is generally available (GA).
October 10, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Application Integration resources. For more information, see Manage Application Integration resources using custom constraints. This feature is available in Preview.
October 06, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Dataform resources. For more information, see Create custom organization policy constraints. This feature is generally available (GA).
October 03, 2025
Select Workload Identity Federation resources let you use custom constraints to define your own restrictions on Google Cloud services. To learn which Workload Identity Federation resources support custom constraints and to view sample use cases, see Use custom organization policies for Workload Identity Federation.
This feature is available in General Availability.
September 18, 2025
Select Cloud Load Balancing resources let you use custom constraints to define your own restrictions on Google Cloud services. To learn which load balancing resources support custom constraints and to view sample use cases, see Manage Cloud Load Balancing resources using custom constraints.
This feature is available in General Availability.
September 11, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Live Stream API resources. For more information, see Use custom custom constraints.
September 09, 2025
Preview: Eight new organization policy constraints are available to help you enforce security best practices for Compute Engine virtual machine (VM) instances.
These managed constraints simplify governance for common security scenarios and integrate with safe rollout tools like dry-run and simulation, letting you test their impact before enforcement.
The new constraints are as follows:
compute.managed.disableNestedVirtualizationcompute.managed.disableSerialPortAccesscompute.managed.disableSerialPortLoggingcompute.managed.disallowGlobalDnscompute.managed.requireOsConfigcompute.managed.requireOsLogincompute.managed.vmCanIpForwardcompute.managed.vmExternalIpAccess
These constraints can evaluate metadata values at the VM instance, project, or zonal level. For more information about these managed constraints, see Managed Constraints in the Resource Manager documentation.
September 08, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Cloud Deploy resources. For more information, see Use custom organization policies.
August 28, 2025
Certain Organization Policy managed constraints that were released on August 21, 2025 were not functioning as intended. The Organization Policy Service evaluated these constraints as if the effectiveInstanceMetadata field of the resources that they were enforced on was empty, causing them to always evaluate to either allow or deny access to the resource.
The following managed constraints were evaluated to always allow creation of resources where they were enforced:
constraints/compute.managed.disableGuestAttributesAccessconstraints/compute.managed.disableSerialPortAccessconstraints/compute.managed.disableSerialPortLogging
The following managed constraints were evaluated to always block creation of resources where they were enforced:
constraints/compute.managed.disallowGlobalDnsconstraints/compute.managed.requireOsConfigconstraints/compute.managed.requireOsLogin
This issue has been corrected, and these constraints now properly evaluate the effectiveInstanceMetadata field to determine whether resource creation should be allowed or blocked.
August 18, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Backup for GKE resources. For more information, see Manage Backup for GKE resources using custom constraints. This feature is generally available.
You can now use organization policy conditions to match a tag key. This lets you enable or disable enforcement against all resources with that tag key, regardless of what tag value is attached. For more information, see Setting an organization policy with tags.
July 25, 2025
Organization policies in dry-run mode are reporting inconsistent results for the following managed constraints:
constraints/compute.managed.restrictProtocolForwardingCreationForTypesconstraints/iam.managed.allowedPolicyMembersconstraints/essentialcontacts.managed.allowedContactDomainsconstraints/compute.managed.blockPreviewFeatures
If a resource inherited an organization policy in dry-run mode that uses any of these managed constraints, that dry-run policy was evaluated without using the parameters specified in the live policy. Normally, an organization policy in dry-run mode that's inherited on a resource is overridden by the live organization policy set directly on that same resource. Not evaluating the live organization policy parameters in the inherited organization policy in dry-run mode led to inconsistent results.
Our engineering team is working to resolve this issue.
February 27, 2025
Custom organization policies are now generally available for the Video Stitcher API. For more information, see Create custom constraints for the Video Stitcher API.
Custom organization policies are now generally available for Service Management. For more information, see Manage Service Management resources with custom constraints.
February 20, 2025
Custom organization policies are now generally available for Cloud Healthcare API. For more information, see Use custom organization policies.
February 19, 2025
Custom organization policies are now generally available for Essential Contacts. For more information, see Creating custom constraints for Essential Contacts.
February 14, 2025
Custom organization policies are now generally available for Cloud Logging. For more information, see Use custom organization policies.
February 13, 2025
Custom organization policies are now generally available for security posture resources. For more information, see Add a custom organization policy.
February 11, 2025
Custom organization policies are now generally available for Cloud DNS. For more information, see Create custom organization policy constraints.
Custom organization policies are now generally available for Identity-Aware Proxy. For more information, see Use custom organization policies.
Custom organization policies are now generally available for Spanner. For more information, see Add a custom organization policy.
Custom organization policies are now generally available for Dataproc Serverless. For more information, see Use custom constraints.
Custom organization policies are now generally available for Developer Connect. For more information, see Create custom organization policies.
February 06, 2025
You can now create custom organization policies for Workflows. For more information, see Create custom organization policy constraints for Workflows.
February 05, 2025
You can now create custom organization policies for Cloud Monitoring alerting policies, notification channels, and snoozes. For more information, see Use custom organization policies.
January 21, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Cloud Data Fusion resources. For more information, see Create custom organization policy constraints.
January 15, 2025
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some reCAPTCHA resources. For more information, see Use custom organization policies for reCAPTCHA keys and firewall policies.
December 19, 2024
The Organization Policy recommender generates insights and organization policy recommendations to restrict the creation and upload of service account keys. This feature is available in Preview.
You can use the iam.managed.allowedPolicyMembers managed organization policy constraint to implement domain restricted sharing. For more information, see Domain restricted sharing.
You can use custom constraints with Organization Policy to provide more granular control over specific fields for some Secure Source Manager resources. For more information, see Manage resources with custom constraints.
December 17, 2024
You can use Organization Policy Service custom constraints to manage specific operations on Bigtable resources. For more information, see Use custom organization policies. This feature is generally available (GA).
December 16, 2024
Cloud Load Balancing resources now let you use custom constraints to define your own restrictions on Google Cloud services. To learn about which load balancing resources support custom constraints, and some sample use cases, see Manage Cloud Load Balancing resources using custom constraints.
This feature is available in General Availability.
December 09, 2024
Using IAM attributes in custom organization policies is generally available. For more information, see Use custom organization policies.
You can use the iam.managed.preventPrivilegedBasicRolesForDefaultServiceAccounts managed organization policy constraint to prevent default service accounts from being granted the Editor (roles/editor) or Owner (roles/owner) roles. For more information, see Prevent the Owner and Editor role from being granted to default service accounts.
December 06, 2024
May 03, 2024
Starting on June 16, 2024, if you don't set a value for the iam.serviceAccountKeyExposure organization policy constraint, Google Cloud will default to the behavior described for DISABLE_KEY.
May 04, 2022
The resource usage restriction Organization Policy constraint has launched into general availability.
August 09, 2021
You can now use the Cloud Console UI to manage your organization policies with tags. For more information, see Setting an organization policy with tags.