certslothcertsloth
PCSE/Topic 08

Google Cloud / Professional

Enterprise Identity and Privilege Boundaries

3 min read5 recall promptsReviewed 2026-10-09

Memory hook: Workforce is people; workload is software; neither needs permanent keys.

Must remember

Cloud Identity/Workspace manages organizational users/groups. Directory synchronization brings supported directory identity data into cloud identity; federation connects authentication to a trusted external identity provider. Workforce Identity Federation serves external workforce identities; Workload Identity Federation serves software workloads. The similar names conceal different principals and use cases.

Protect super-administrator and break-glass access with tightly controlled recovery, phishing-resistant authentication where supported, monitoring and rehearsed procedures. Separate normal work from privileged sessions. Account creation, role changes and offboarding must propagate to groups, applications and active credentials. An SSO login proves identity, not entitlement to every project.

Use service-account impersonation or federation for short-lived credentials instead of exporting keys. Limit who can impersonate, attach or administer a powerful service account: those permissions can become a privilege-escalation path. Audit the actual principal and delegated chain. Rotate/revoke unavoidable keys and discover unused credentials.

IAM allow grants are inherited; applicable deny policies can block permissions despite an allow. IAM Conditions refine supported grants with attributes such as time/resource context. Organization policies constrain resource configuration rather than granting access. Custom constraints address supported requirements; a constraint is effective only for the resource/action to which it applies.

Privileged Access Manager supports controlled temporary elevation with configured approvals and auditability. Policy Intelligence tools help investigate and reduce excessive access; recommendations need validation against rare legitimate operations. Access Context Manager defines access levels/service-perimeter policy inputs; context signals complement identity rather than replacing it.

Review details

Principal access boundary policies determine resource eligibility for supported permissions; they do not grant access. Read effective access as the required allow together with applicable deny/boundary enforcement and separate service/org constraints. A condition on one role binding does not constrain a different inherited unconditional grant.

SAML federation exchanges identity assertions for sign-in; OAuth delegates authorized access; two-step verification adds authentication factors. These do not provision accounts or assign every application permission by themselves. Service-account key discovery, disablement and deletion must address dependent workloads and audit evidence; rotating a human password does not revoke an unrelated service-account key.

Choose under exam pressure

Requirement Choice and reason
External contractors use their existing IdP Workforce federation, appropriate authorization and lifecycle controls.
CI job needs Google API credentials Workload federation and scoped short-lived access.
Temporary production elevation Privileged Access Manager with limited duration and approval policy.

Traps

  • Service-account impersonation permission can be as sensitive as the account itself.
  • Organization policy does not grant API permissions.

Active recall

1. Workforce versus workload federation?

Human enterprise identities versus software identities.

2. Why prefer short-lived tokens?

They reduce the persistence and distribution of reusable credentials.

3. What can override an IAM allow?

An applicable deny policy or other relevant enforcement boundary.

4. What does just-in-time elevation reduce?

Standing privileged access.

5. Why review account attachment rights?

A user may gain the attached service account’s effective capabilities through a workload.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.