IAM release notes

This page documents production updates to Identity and Access Management. Check this page for announcements about new or updated features, bug fixes, known issues, and deprecated functionality.

You can see the latest product updates for all of Google Cloud on the Google Cloud page, browse and filter all release notes in the Google Cloud console, or programmatically access release notes in BigQuery.

To get the latest product updates delivered to you, add the URL of this page to your feed reader, or add the feed URL directly.

September 10, 2026

Feature

The Identity and Access Management (IAM) Model Context Protocol (MCP) server is generally available. You can connect to the IAM remote MCP server from AI applications to inspect and manage custom roles and deny policies across your resources.

For more information, see the following documentation:

September 09, 2026

Feature

You can get IAM role suggestions from Gemini programmatically by using the Policy Assist API (Preview).

For more information, see the following documentation:

August 22, 2026

Feature

The Agent Identity auth manager and the Agent Identity APIs (agentidentity.googleapis.com and agentidentitycredentials.googleapis.com) are generally available.

Agent Identity auth manager provides a centralized credentials vault and authentication broker that simplifies outbound tool authentication for 3-legged OAuth, 2-legged OAuth, and API keys. The Agent Identity APIs replace the legacy IAM Connectors API (iamconnectors.googleapis.com) for managing auth providers and agent identities.

For more information, see the following documentation:

August 14, 2026

Feature

You can use custom constraints with Organization Policy to provide more granular control over specific fields for Agent Identity resources, such as agentidentity.googleapis.com/AuthProvider. For more information, see Use custom organization policies for Agent Identity. This feature is in GA.

Feature

Agent Identity VPC Service Controls (VPC Service Controls) integration is generally available. You can add the Agent Identity API (agentidentity.googleapis.com) and Agent Identity Credentials API (agentidentitycredentials.googleapis.com) to a service perimeter and specify agent identities in ingress and egress rules.

For more information, see Agent Identity overview.

August 12, 2026

Change

The workflow for creating workforce identity pool providers in the Google Cloud console changed. After submitting the initial provider configuration, the console directs you to a centralized page to configure provider attributes, including attribute mappings, attribute conditions, and extra attributes.

For more information, see Manage workforce identity pools and providers.

August 03, 2026

Feature

Organization Policy Service custom constraints are available for Privileged Access Manager (PAM). You can use custom constraints to restrict how users create and modify entitlements and grants. This feature is in Preview.

For more information, see Use custom organization policies for Privileged Access Manager.

July 27, 2026

Feature

Managed workload identities for Compute Engine are generally available.

For more information, see Configure managed workload identity authentication for Compute Engine.

June 18, 2026

Feature

The Agent Identity API (agentidentity.googleapis.com) is available in Preview. This new API replaces the legacy IAM Connectors API (iamconnectors.googleapis.com) for managing auth providers and agent identities.

During the preview migration period, both APIs operate side-by-side. Existing auth providers are automatically mirrored to the new V2 resource hierarchy (authProviders/), allowing you to migrate your IAM policies, agent code, and client applications without downtime.

June 15, 2026

Feature

You can use the error ID provided in permission error messages to help troubleshoot access. Error IDs provide context for the error, including the principal, resource, permission, and supported IAM conditions. This feature is available in Preview.

For more information, see Permission error messages.

May 08, 2026

Feature

You can use the IAM recommender to remediate excessive permissions for Google groups by transitioning from permanent role bindings to temporary, on-demand entitlements in Privileged Access Manager (PAM). This feature is in Preview.

To learn how to remediate excessive permissions, see Remediate excessive permissions with Privileged Access Manager.

April 22, 2026

Feature

Privileged Access Manager supports agent identities as grant requesters and approvers.

This feature is available in preview.

For more information, see Privileged Access Manager overview.

Feature

Agent Identity auth manager is available in preview. You can use Agent Identity auth manager to help securely authenticate your agents to third-party services using 3-legged OAuth, 2-legged OAuth, or API keys.

For more information, see Agent Identity auth manager.

Feature

Agent Identity is generally available (GA). Agent Identity provides a strongly attested, cryptographic identity for each agent that is tied to the lifecycle of the resource hosting the agent.

For more information, see Agent Identity overview.

April 13, 2026

Feature