Console access and workload access are different paths
A person logging into a console and a workload calling an API are separate routes with separate controls.
Hardening one does nothing for the other. Strong human authentication with MFA is common; the equivalent discipline for machine access frequently is not, and machine credentials are longer-lived and less watched. Both need answering, and organisations usually have an answer for the first.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Unused cloud permissions are latent attack pathsStill wired
