Invia feedback
  
   
 
  
    
      Controllo dell'accesso con IAM 
  
      
     
  
  
  
   
  
    
  
  
    
    
    
    
  
I ruoli IAM (Identity and Access Management) stabiliscono in che modo puoi utilizzare l'API Managed Service for Microsoft Active Directory (Managed Microsoft AD). Di seguito è riportato un elenco di ciascun ruolo IAM disponibile per Managed Microsoft AD e dei metodi a sua disposizione.
Inoltre, gli account di servizio devono disporre dell'autorizzazione servicemanagement.services.bind
per visualizzare e attivare Managed Microsoft AD. Scopri di più su autorizzazioni e ruoli per la gestione dei servizi .
   
  
Role 
Permissions 
 
 
Google Cloud Managed Identities Admin
 
(roles/managedidentities.admin )
Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level.
 
 
  
    
      managedidentities.* 
    
    
      managedidentities.backups.create   
      managedidentities.backups.delete   
      managedidentities.backups.get 
      managedidentities.backups.getIamPolicy   
      managedidentities.backups.list 
      managedidentities.backups.setIamPolicy   
      managedidentities.backups.update   
      managedidentities.domains.attachTrust   
      managedidentities.domains.checkMigrationPermission   
      managedidentities.domains.create   
      managedidentities.domains.createTagBinding   
      managedidentities.domains.delete   
      managedidentities.domains.deleteTagBinding   
      managedidentities.domains.detachTrust   
      managedidentities.domains.disableMigration   
      managedidentities.domains.domainJoinMachine   
      managedidentities.domains.enableMigration   
      managedidentities.domains.extendSchema   
      managedidentities.domains.get 
      managedidentities.domains.getIamPolicy   
      managedidentities.domains.list 
      managedidentities.domains.listEffectiveTags   
      managedidentities.domains.listTagBindings   
      managedidentities.domains.reconfigureTrust   
      managedidentities.domains.resetpassword   
      managedidentities.domains.restore   
      managedidentities.domains.setIamPolicy   
      managedidentities.domains.update   
      managedidentities.domains.updateLDAPSSettings   
      managedidentities.domains.validateTrust   
      managedidentities.locations.get   
      managedidentities.locations.list   
      managedidentities.operations.cancel   
      managedidentities.operations.delete   
      managedidentities.operations.get   
      managedidentities.operations.list   
      managedidentities.peerings.create   
      managedidentities.peerings.delete   
      managedidentities.peerings.get 
      managedidentities.peerings.getIamPolicy   
      managedidentities.peerings.list   
      managedidentities.peerings.setIamPolicy   
      managedidentities.peerings.update   
      managedidentities.sqlintegrations.get   
      managedidentities.sqlintegrations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Backup Admin
 
(roles/managedidentities.backupAdmin )
Full access to Google Cloud Managed Identities Backup and related resources. Intended to be granted on a project-level
 
 
  
    
      managedidentities.backups.* 
    
    
      managedidentities.backups.create   
      managedidentities.backups.delete   
      managedidentities.backups.get 
      managedidentities.backups.getIamPolicy   
      managedidentities.backups.list 
      managedidentities.backups.setIamPolicy   
      managedidentities.backups.update   
     
   
  managedidentities.domains.get
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  
    
      managedidentities.operations.* 
    
    
      managedidentities.operations.cancel   
      managedidentities.operations.delete   
      managedidentities.operations.get   
      managedidentities.operations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Backup Viewer
 
(roles/managedidentities.backupViewer )
Read-only access to Google Cloud Managed Identities Backup and related resources.
 
 
  managedidentities.backups.get
  managedidentities.backups.getIamPolicy  
  managedidentities.backups.list
  managedidentities.domains.get
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Domain Admin
 
(roles/managedidentities.domainAdmin )
Read-Update-Delete to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a resource (domain) level.
 
 
  
    
      managedidentities.backups.* 
    
    
      managedidentities.backups.create   
      managedidentities.backups.delete   
      managedidentities.backups.get 
      managedidentities.backups.getIamPolicy   
      managedidentities.backups.list 
      managedidentities.backups.setIamPolicy   
      managedidentities.backups.update   
     
   
  managedidentities.domains.attachTrust  
  managedidentities.domains.checkMigrationPermission  
  managedidentities.domains.createTagBinding  
  managedidentities.domains.delete  
  managedidentities.domains.deleteTagBinding  
  managedidentities.domains.detachTrust  
  managedidentities.domains.disableMigration  
  managedidentities.domains.domainJoinMachine  
  managedidentities.domains.enableMigration  
  managedidentities.domains.extendSchema  
  managedidentities.domains.get
  managedidentities.domains.getIamPolicy  
  managedidentities.domains.listEffectiveTags  
  managedidentities.domains.listTagBindings  
  managedidentities.domains.reconfigureTrust  
  managedidentities.domains.resetpassword  
  managedidentities.domains.restore  
  managedidentities.domains.update  
  managedidentities.domains.updateLDAPSSettings  
  managedidentities.domains.validateTrust  
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  
    
      managedidentities.sqlintegrations.*  
    
    
      managedidentities.sqlintegrations.get   
      managedidentities.sqlintegrations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Domain Join
Beta 
 
(roles/managedidentities.domainJoin )
Access to domain join VMs with Cloud AD
 
 
  managedidentities.domains.domainJoinMachine  
  managedidentities.domains.get
 
 
Google Cloud Managed Identities Peering Admin
 
(roles/managedidentities.peeringAdmin )
Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level
 
 
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  
    
      managedidentities.operations.* 
    
    
      managedidentities.operations.cancel   
      managedidentities.operations.delete   
      managedidentities.operations.get   
      managedidentities.operations.list   
     
   
  
    
      managedidentities.peerings.* 
    
    
      managedidentities.peerings.create   
      managedidentities.peerings.delete   
      managedidentities.peerings.get 
      managedidentities.peerings.getIamPolicy   
      managedidentities.peerings.list   
      managedidentities.peerings.setIamPolicy   
      managedidentities.peerings.update   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Peering Viewer
 
(roles/managedidentities.peeringViewer )
Read-only access to Google Cloud Managed Identities Peering and related resources.
 
 
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  managedidentities.peerings.get
  managedidentities.peerings.getIamPolicy  
  managedidentities.peerings.list  
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Cloud Managed Identities Service Agent
 
(roles/managedidentities.serviceAgent )
Gives Managed Identities service account access to managed resources.
 
  Warning:  Do not grant service agent roles to any principals except
  service agents .
 
 
  compute.globalOperations.get
  compute.networks.addPeering
  compute.networks.get
  compute.networks.removePeering
  compute.networks.update
  compute.routes.list
  
    
      dns.changes.* 
    
    
      dns.changes.create 
      dns.changes.get 
      dns.changes.list 
     
   
  
    
      dns.dnsKeys.* 
    
    
      dns.dnsKeys.get 
      dns.dnsKeys.list 
     
   
  
    
      dns.managedZoneOperations.* 
    
    
      dns.managedZoneOperations.get 
      dns.managedZoneOperations.list 
     
   
  dns.managedZones.create
  dns.managedZones.delete
  dns.managedZones.get
  dns.managedZones.list
  dns.managedZones.update
  dns.networks.bindPrivateDNSPolicy  
  dns.networks.bindPrivateDNSZone  
  dns.policies.create
  dns.policies.delete
  dns.policies.get
  dns.policies.list
  dns.policies.update
  dns.projects.get
  
    
      dns.resourceRecordSets.* 
    
    
      dns.resourceRecordSets.create 
      dns.resourceRecordSets.delete 
      dns.resourceRecordSets.get 
      dns.resourceRecordSets.list 
      dns.resourceRecordSets.update 
     
   
  
    
      dns.responsePolicies.* 
    
    
      dns.responsePolicies.create 
      dns.responsePolicies.delete 
      dns.responsePolicies.get 
      dns.responsePolicies.list 
      dns.responsePolicies.update 
     
   
  
    
      dns.responsePolicyRules.* 
    
    
      dns.responsePolicyRules.create 
      dns.responsePolicyRules.delete 
      dns.responsePolicyRules.get 
      dns.responsePolicyRules.list 
      dns.responsePolicyRules.update 
     
   
  monitoring.metricDescriptors.create  
  monitoring.metricDescriptors.get  
  monitoring.metricDescriptors.list  
  
    
      monitoring.monitoredResourceDescriptors.*  
    
    
      monitoring.monitoredResourceDescriptors.get   
      monitoring.monitoredResourceDescriptors.list   
     
   
  monitoring.timeSeries.create
  resourcemanager.projects.get
  resourcemanager.projects.list
  telemetry.metrics.write
 
 
Google Cloud Managed Identities Viewer
 
(roles/managedidentities.viewer )
Read-only access to Google Cloud Managed Identities Domains and related resources.
 
 
  managedidentities.backups.get
  managedidentities.backups.getIamPolicy  
  managedidentities.backups.list
  managedidentities.domains.get
  managedidentities.domains.getIamPolicy  
  managedidentities.domains.list
  managedidentities.domains.listEffectiveTags  
  managedidentities.domains.listTagBindings  
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  managedidentities.peerings.get
  managedidentities.peerings.getIamPolicy  
  managedidentities.peerings.list  
  
    
      managedidentities.sqlintegrations.*  
    
    
      managedidentities.sqlintegrations.get   
      managedidentities.sqlintegrations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
 
 
Per ulteriori informazioni sui ruoli IAM, consulta la sezione Informazioni sui ruoli .
  
  
  
  
     
  
  
 
  
    
    
      
       
         
  
  
    
    Invia feedback
  
   
 
       
    
    
  
  
 
  Salvo quando diversamente specificato, i contenuti di questa pagina sono concessi in base alla licenza Creative Commons Attribution 4.0 , mentre gli esempi di codice sono concessi in base alla licenza Apache 2.0 . Per ulteriori dettagli, consulta le norme del sito di Google Developers . Java è un marchio registrato di Oracle e/o delle sue consociate.
  Ultimo aggiornamento 2025-10-31 UTC.
 
 
  
  
    
    
    
      
  
  
    Vuoi dirci altro?
  
   
 
     
  
  
    
      [[["Facile da capire","easyToUnderstand","thumb-up"],["Il problema è stato risolto","solvedMyProblem","thumb-up"],["Altra","otherUp","thumb-up"]],[["Difficile da capire","hardToUnderstand","thumb-down"],["Informazioni o codice di esempio errati","incorrectInformationOrSampleCode","thumb-down"],["Mancano le informazioni o gli esempi di cui ho bisogno","missingTheInformationSamplesINeed","thumb-down"],["Problema di traduzione","translationIssue","thumb-down"],["Altra","otherDown","thumb-down"]],["Ultimo aggiornamento 2025-10-31 UTC."],[],[]]