Kirim masukan
  
   
 
  
    
      Kontrol akses dengan IAM 
  
      
     
  
  
  
   
  
    
  
  
    
    
    
    
  
Peran Identity and Access Management (IAM) menentukan cara Anda dapat menggunakan
API Layanan Terkelola untuk Microsoft Active Directory (Microsoft AD Terkelola). Berikut adalah daftar setiap peran IAM yang tersedia untuk Managed Microsoft AD dan metode yang tersedia untuknya.
Selain itu, akun layanan harus memiliki izin servicemanagement.services.bind
untuk melihat dan mengaktifkan Managed Microsoft AD. Pelajari lebih lanjut peran dan izin pengelolaan layanan .
   
  
Role 
Permissions 
 
 
Google Cloud Managed Identities Admin
 
(roles/managedidentities.admin )
Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level.
 
 
  
    
      managedidentities.* 
    
    
      managedidentities.backups.create   
      managedidentities.backups.delete   
      managedidentities.backups.get 
      managedidentities.backups.getIamPolicy   
      managedidentities.backups.list 
      managedidentities.backups.setIamPolicy   
      managedidentities.backups.update   
      managedidentities.domains.attachTrust   
      managedidentities.domains.checkMigrationPermission   
      managedidentities.domains.create   
      managedidentities.domains.createTagBinding   
      managedidentities.domains.delete   
      managedidentities.domains.deleteTagBinding   
      managedidentities.domains.detachTrust   
      managedidentities.domains.disableMigration   
      managedidentities.domains.domainJoinMachine   
      managedidentities.domains.enableMigration   
      managedidentities.domains.extendSchema   
      managedidentities.domains.get 
      managedidentities.domains.getIamPolicy   
      managedidentities.domains.list 
      managedidentities.domains.listEffectiveTags   
      managedidentities.domains.listTagBindings   
      managedidentities.domains.reconfigureTrust   
      managedidentities.domains.resetpassword   
      managedidentities.domains.restore   
      managedidentities.domains.setIamPolicy   
      managedidentities.domains.update   
      managedidentities.domains.updateLDAPSSettings   
      managedidentities.domains.validateTrust   
      managedidentities.locations.get   
      managedidentities.locations.list   
      managedidentities.operations.cancel   
      managedidentities.operations.delete   
      managedidentities.operations.get   
      managedidentities.operations.list   
      managedidentities.peerings.create   
      managedidentities.peerings.delete   
      managedidentities.peerings.get 
      managedidentities.peerings.getIamPolicy   
      managedidentities.peerings.list   
      managedidentities.peerings.setIamPolicy   
      managedidentities.peerings.update   
      managedidentities.sqlintegrations.get   
      managedidentities.sqlintegrations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Backup Admin
 
(roles/managedidentities.backupAdmin )
Full access to Google Cloud Managed Identities Backup and related resources. Intended to be granted on a project-level
 
 
  
    
      managedidentities.backups.* 
    
    
      managedidentities.backups.create   
      managedidentities.backups.delete   
      managedidentities.backups.get 
      managedidentities.backups.getIamPolicy   
      managedidentities.backups.list 
      managedidentities.backups.setIamPolicy   
      managedidentities.backups.update   
     
   
  managedidentities.domains.get
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  
    
      managedidentities.operations.* 
    
    
      managedidentities.operations.cancel   
      managedidentities.operations.delete   
      managedidentities.operations.get   
      managedidentities.operations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Backup Viewer
 
(roles/managedidentities.backupViewer )
Read-only access to Google Cloud Managed Identities Backup and related resources.
 
 
  managedidentities.backups.get
  managedidentities.backups.getIamPolicy  
  managedidentities.backups.list
  managedidentities.domains.get
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Domain Admin
 
(roles/managedidentities.domainAdmin )
Read-Update-Delete to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a resource (domain) level.
 
 
  
    
      managedidentities.backups.* 
    
    
      managedidentities.backups.create   
      managedidentities.backups.delete   
      managedidentities.backups.get 
      managedidentities.backups.getIamPolicy   
      managedidentities.backups.list 
      managedidentities.backups.setIamPolicy   
      managedidentities.backups.update   
     
   
  managedidentities.domains.attachTrust  
  managedidentities.domains.checkMigrationPermission  
  managedidentities.domains.createTagBinding  
  managedidentities.domains.delete  
  managedidentities.domains.deleteTagBinding  
  managedidentities.domains.detachTrust  
  managedidentities.domains.disableMigration  
  managedidentities.domains.domainJoinMachine  
  managedidentities.domains.enableMigration  
  managedidentities.domains.extendSchema  
  managedidentities.domains.get
  managedidentities.domains.getIamPolicy  
  managedidentities.domains.listEffectiveTags  
  managedidentities.domains.listTagBindings  
  managedidentities.domains.reconfigureTrust  
  managedidentities.domains.resetpassword  
  managedidentities.domains.restore  
  managedidentities.domains.update  
  managedidentities.domains.updateLDAPSSettings  
  managedidentities.domains.validateTrust  
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  
    
      managedidentities.sqlintegrations.*  
    
    
      managedidentities.sqlintegrations.get   
      managedidentities.sqlintegrations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Domain Join
Beta 
 
(roles/managedidentities.domainJoin )
Access to domain join VMs with Cloud AD
 
 
  managedidentities.domains.domainJoinMachine  
  managedidentities.domains.get
 
 
Google Cloud Managed Identities Peering Admin
 
(roles/managedidentities.peeringAdmin )
Full access to Google Cloud Managed Identities Domains and related resources. Intended to be granted on a project-level
 
 
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  
    
      managedidentities.operations.* 
    
    
      managedidentities.operations.cancel   
      managedidentities.operations.delete   
      managedidentities.operations.get   
      managedidentities.operations.list   
     
   
  
    
      managedidentities.peerings.* 
    
    
      managedidentities.peerings.create   
      managedidentities.peerings.delete   
      managedidentities.peerings.get 
      managedidentities.peerings.getIamPolicy   
      managedidentities.peerings.list   
      managedidentities.peerings.setIamPolicy   
      managedidentities.peerings.update   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Google Cloud Managed Identities Peering Viewer
 
(roles/managedidentities.peeringViewer )
Read-only access to Google Cloud Managed Identities Peering and related resources.
 
 
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  managedidentities.peerings.get
  managedidentities.peerings.getIamPolicy  
  managedidentities.peerings.list  
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
Cloud Managed Identities Service Agent
 
(roles/managedidentities.serviceAgent )
Gives Managed Identities service account access to managed resources.
 
  Warning:  Do not grant service agent roles to any principals except
  service agents .
 
 
  compute.globalOperations.get
  compute.networks.addPeering
  compute.networks.get
  compute.networks.removePeering
  compute.networks.update
  compute.routes.list
  
    
      dns.changes.* 
    
    
      dns.changes.create 
      dns.changes.get 
      dns.changes.list 
     
   
  
    
      dns.dnsKeys.* 
    
    
      dns.dnsKeys.get 
      dns.dnsKeys.list 
     
   
  
    
      dns.managedZoneOperations.* 
    
    
      dns.managedZoneOperations.get 
      dns.managedZoneOperations.list 
     
   
  dns.managedZones.create
  dns.managedZones.delete
  dns.managedZones.get
  dns.managedZones.list
  dns.managedZones.update
  dns.networks.bindPrivateDNSPolicy  
  dns.networks.bindPrivateDNSZone  
  dns.policies.create
  dns.policies.delete
  dns.policies.get
  dns.policies.list
  dns.policies.update
  dns.projects.get
  
    
      dns.resourceRecordSets.* 
    
    
      dns.resourceRecordSets.create 
      dns.resourceRecordSets.delete 
      dns.resourceRecordSets.get 
      dns.resourceRecordSets.list 
      dns.resourceRecordSets.update 
     
   
  
    
      dns.responsePolicies.* 
    
    
      dns.responsePolicies.create 
      dns.responsePolicies.delete 
      dns.responsePolicies.get 
      dns.responsePolicies.list 
      dns.responsePolicies.update 
     
   
  
    
      dns.responsePolicyRules.* 
    
    
      dns.responsePolicyRules.create 
      dns.responsePolicyRules.delete 
      dns.responsePolicyRules.get 
      dns.responsePolicyRules.list 
      dns.responsePolicyRules.update 
     
   
  monitoring.metricDescriptors.create  
  monitoring.metricDescriptors.get  
  monitoring.metricDescriptors.list  
  
    
      monitoring.monitoredResourceDescriptors.*  
    
    
      monitoring.monitoredResourceDescriptors.get   
      monitoring.monitoredResourceDescriptors.list   
     
   
  monitoring.timeSeries.create
  resourcemanager.projects.get
  resourcemanager.projects.list
  telemetry.metrics.write
 
 
Google Cloud Managed Identities Viewer
 
(roles/managedidentities.viewer )
Read-only access to Google Cloud Managed Identities Domains and related resources.
 
 
  managedidentities.backups.get
  managedidentities.backups.getIamPolicy  
  managedidentities.backups.list
  managedidentities.domains.get
  managedidentities.domains.getIamPolicy  
  managedidentities.domains.list
  managedidentities.domains.listEffectiveTags  
  managedidentities.domains.listTagBindings  
  
    
      managedidentities.locations.* 
    
    
      managedidentities.locations.get   
      managedidentities.locations.list   
     
   
  managedidentities.operations.get  
  managedidentities.operations.list  
  managedidentities.peerings.get
  managedidentities.peerings.getIamPolicy  
  managedidentities.peerings.list  
  
    
      managedidentities.sqlintegrations.*  
    
    
      managedidentities.sqlintegrations.get   
      managedidentities.sqlintegrations.list   
     
   
  resourcemanager.projects.get
  resourcemanager.projects.list
 
 
 
 
Untuk mengetahui informasi selengkapnya tentang peran IAM, lihat
memahami peran .
  
  
  
  
     
  
  
 
  
    
    
      
       
         
  
  
    
    Kirim masukan
  
   
 
       
    
    
  
  
 
  Kecuali dinyatakan lain, konten di halaman ini dilisensikan berdasarkan Lisensi Creative Commons Attribution 4.0 , sedangkan contoh kode dilisensikan berdasarkan Lisensi Apache 2.0 . Untuk mengetahui informasi selengkapnya, lihat Kebijakan Situs Google Developers . Java adalah merek dagang terdaftar dari Oracle dan/atau afiliasinya.
  Terakhir diperbarui pada 2025-10-31 UTC.
 
 
  
  
    
    
    
      
  
  
    Ada masukan untuk kami?
  
   
 
     
  
  
    
      [[["Mudah dipahami","easyToUnderstand","thumb-up"],["Memecahkan masalah saya","solvedMyProblem","thumb-up"],["Lainnya","otherUp","thumb-up"]],[["Sulit dipahami","hardToUnderstand","thumb-down"],["Informasi atau kode contoh salah","incorrectInformationOrSampleCode","thumb-down"],["Informasi/contoh yang saya butuhkan tidak ada","missingTheInformationSamplesINeed","thumb-down"],["Masalah terjemahan","translationIssue","thumb-down"],["Lainnya","otherDown","thumb-down"]],["Terakhir diperbarui pada 2025-10-31 UTC."],[],[]]