[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-04 (世界標準時間)。"],[[["\u003cp\u003eThis guide is intended for users familiar with IAM and focuses on security best practices, rather than teaching how to use IAM, with new users directed to the IAM Quickstart.\u003c/p\u003e\n"],["\u003cp\u003eAdopt the principle of least privilege by granting the most limited predefined or custom roles instead of basic roles, and create separate service accounts for different application components.\u003c/p\u003e\n"],["\u003cp\u003eAvoid using service account keys whenever possible due to the inherent security risks, and if keys are necessary, adhere to best practices for their secure management, including regular rotation.\u003c/p\u003e\n"],["\u003cp\u003eRegularly audit changes to allow policies and access to service account keys using Cloud Audit Logs, and consider exporting logs for long-term storage.\u003c/p\u003e\n"],["\u003cp\u003eManage access policies efficiently by granting roles to groups rather than individual users, and consider granting roles at the organization level if a principal requires access to all projects.\u003c/p\u003e\n"]]],[],null,["# Use IAM securely\n\nThis page recommends security best practices that you should keep in mind when\nusing IAM.\n\nThis page is designed for users who are proficient with IAM.\nIf you are just starting out with IAM, these instructions\nwill not teach you how to use it; instead, new users should start with the\n[IAM Quickstart](/iam/docs/grant-role-console).\n\nLeast privilege\n---------------\n\nService accounts\n----------------\n\nService account keys\n--------------------\n\nAuditing\n--------\n\nPolicy management\n-----------------"]]