IAM conditions add context to permissions
Conditions let a permission apply only in defined circumstances: from this network, with MFA present, on resources tagged this way.
It turns a binary grant into a contextual one, which is how least privilege becomes practical at scale. They are underused because they are fiddly to write and are where the difference between a permission that is broadly safe and one that is genuinely scoped usually lives.
More on Cloud IAM
- Cloud roles can replace copied long-lived keysStop posting copies. Hand out passes
- Resource policies create a second authorisation surfaceThe thing has a policy too
- Permission boundaries cap delegated powerGrant what you like. It stops at the rail
- Organisation guardrails prevent dangerous local choicesThe wrong setting is not on the dial
- Cross-account trust expands the identity perimeterYour perimeter now runs round their office
- Console access and workload access are different pathsTwo doors, one room
