[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[[["\u003cp\u003eThis guide is intended for users familiar with IAM and focuses on security best practices, rather than teaching how to use IAM, with new users directed to the IAM Quickstart.\u003c/p\u003e\n"],["\u003cp\u003eAdopt the principle of least privilege by granting the most limited predefined or custom roles instead of basic roles, and create separate service accounts for different application components.\u003c/p\u003e\n"],["\u003cp\u003eAvoid using service account keys whenever possible due to the inherent security risks, and if keys are necessary, adhere to best practices for their secure management, including regular rotation.\u003c/p\u003e\n"],["\u003cp\u003eRegularly audit changes to allow policies and access to service account keys using Cloud Audit Logs, and consider exporting logs for long-term storage.\u003c/p\u003e\n"],["\u003cp\u003eManage access policies efficiently by granting roles to groups rather than individual users, and consider granting roles at the organization level if a principal requires access to all projects.\u003c/p\u003e\n"]]],[],null,["# Use IAM securely\n\nThis page recommends security best practices that you should keep in mind when\nusing IAM.\n\nThis page is designed for users who are proficient with IAM.\nIf you are just starting out with IAM, these instructions\nwill not teach you how to use it; instead, new users should start with the\n[IAM Quickstart](/iam/docs/grant-role-console).\n\nLeast privilege\n---------------\n\nService accounts\n----------------\n\nService account keys\n--------------------\n\nAuditing\n--------\n\nPolicy management\n-----------------"]]