Cloud IAM

GCPSecurityFree tier available

Fine-grained identity and access management with predefined and custom roles, service accounts, workload identity federation, and audit logging

Jurisdictional exposure

Provider HQ
USMountain View, USA

Subject to CLOUD Act, FISA-702, DPF

Region locations
APACCNEEAEUUKUSOther44 regions across 7 jurisdictions
Sovereign option
Yes — 2 sovereign-flagged regions available

Attributes

Mfa Support
Yes
Conditional Access
Yes
Audit Logging
Yes

Sub-services (3)

IAM Roles

Predefined and custom roles for access control

Service Accounts

Identities for applications and workloads

Workload Identity Federation

Federated access for external workloads

Compliance & Certifications

This service is attested for the following frameworks. Always verify with the provider before relying on a specific compliance posture.

Where this runs

44 regions
28 countries
2sovereign
Sovereign regions (2)
  • T-Systems Sovereign Cloud · FrankfurtT-Systems Sovereign Cloud powered by Google Cloud
  • S3NS Sovereign Cloud · ParisS3NS — Google Cloud + Thales joint venture
Commercial regions (42)

Europe (13)

  • Belgium
  • Finland
  • Paris
  • Berlin
  • Frankfurt
  • Milan
  • Turin
  • Netherlands
  • Warsaw
  • Madrid
  • Stockholm
  • Zurich
  • London

North America (12)

  • Montréal
  • Toronto
  • Querétaro
  • Northern Virginia
  • Columbus
  • Iowa
  • Dallas
  • Las Vegas
  • Los Angeles
  • South Carolina
  • Salt Lake City
  • Oregon

South America (2)

  • São Paulo
  • Santiago

Asia (9)

  • Hong Kong
  • Delhi
  • Mumbai
  • Jakarta
  • Osaka
  • Tokyo
  • Singapore
  • Seoul
  • Taiwan

Oceania (2)

  • Melbourne
  • Sydney

Middle East (3)

  • Tel Aviv
  • Doha
  • Dammam

Africa (1)

  • Johannesburg

Tags

Equivalent services on other platforms

Alibaba Resource Access ManagementAlibaba

Alibaba Cloud's identity and access management service with users, groups, roles, fine-grained JSON policies, SAML 2.0 federation to enterprise IdPs, and Security Token Service for temporary credentials

AWS IAMAWS

Centralised identity and access management with users, groups, roles, and fine-grained JSON policies, MFA enforcement, identity federation, and IAM Access Analyzer

Amazon CognitoAWS

Customer identity and access management service with User Pools for sign-up and sign-in, Identity Pools for federated AWS credentials, social and SAML/OIDC federation, hosted UI, adaptive authentication, and advanced security risk scoring for consumer-scale apps

Microsoft Entra IDAzure

Cloud identity and access management (formerly Azure AD) with SSO, MFA, conditional access, B2B and B2C guest accounts, and privileged identity management

Azure PolicyAzure

Enforce organisational standards and assess compliance at scale with built-in and custom policy definitions, initiative groupings, remediation tasks, and exemption workflows

Unity CatalogDatabricks

Unified governance layer for data, analytics, and AI assets across all Databricks workspaces with fine-grained access control, data lineage, audit logging, and cross-cloud federation

Huawei Identity and Access ManagementHuawei

Centralised identity management for Huawei Cloud with users, user groups, role-based and fine-grained policies, federated identity via SAML/OIDC, MFA, and temporary credentials through Security Token Service

OpenStack KeystoneOpenStack

Identity, authentication, and service-catalogue service — issues tokens, manages users and projects, federates with external identity providers (LDAP, SAML, OIDC), and exposes the service catalogue every other OpenStack project consumes for endpoint discovery

OCI Identity DomainsOracle

Enterprise identity-as-a-service covering workforce and customer identity with federation (SAML, OIDC), social sign-in, MFA, risk-based adaptive authentication, and delegated administration — the rebranded OCI IAM Identity Cloud Service

OCI Identity and Access ManagementOracle

Authentication and authorisation primitives for OCI — users, groups, policies, dynamic groups (instance principals), and federation. Policy language is Oracle-specific (more declarative than AWS IAM).

Outscale Identity (EIM)Outscale

Experimental Identity Management — IAM with users, groups, policies, federated access via SAML 2.0 / OIDC. AWS IAM-compatible policy syntax. Multi-factor authentication on the management console; access keys for programmatic use.

Tencent Cloud Access ManagementTencent

Tencent Cloud's identity and access management service with sub-accounts, user groups, roles, fine-grained JSON policies, SAML and OIDC federation, MFA, temporary credentials via Security Token Service, and cross-account role assumption

Pricing

Pricing model:free