Identity-Aware Proxy

methodNameDescriptionLog typeSampleRule
anyCatch-all entry for iap.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.activityNN
AuthorizeUserRecords a connection attempt through IAP TCP forwarding (SSH/RDP via an IAP tunnel), gated by the iap.tunnelInstances.accessViaIAP permission. Requires Data Access logging to be enabled for the IAP API.data_accessNY
google.cloud.iap.IdentityAwareProxyAdminService.SetIamPolicySets the IAM policy on an IAP-secured resource, gated by iap.web.setIamPolicy or iap.webServices.setIamPolicy depending on resource scope.activityNY
google.cloud.iap.IdentityAwareProxyAdminService.GetIamPolicyReads the IAM policy on an IAP-secured resource (ADMIN_READ).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.GetIapSettingsReads IAP settings (access levels, reauthentication policy) for a project, folder, or resource (ADMIN_READ).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.UpdateIapSettingsUpdates IAP settings, including access levels and reauthentication policy (DATA_WRITE).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.CreateTunnelDestGroupCreates a TCP tunnel destination group used to scope IAP TCP forwarding (DATA_WRITE).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.UpdateTunnelDestGroupUpdates a TCP tunnel destination group (DATA_WRITE).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.DeleteTunnelDestGroupDeletes a TCP tunnel destination group (DATA_WRITE).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.GetTunnelDestGroupReads a single TCP tunnel destination group (DATA_READ).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.ListTunnelDestGroupsLists TCP tunnel destination groups in a project (DATA_READ).data_accessNN
google.cloud.iap.IdentityAwareProxyAdminService.ValidateIapAttributeExpressionValidates an IAP attribute-based access-control (CEL) expression before it is applied (DATA_WRITE).data_accessNN

any: iap.googleapis.com (any method)

#
ServiceName
iap.googleapis.com

Description

Catch-all entry for iap.googleapis.com. Source-only rules that attribute to the service without a specific method attribute here. Not a distinct audit log operation.

AuthorizeUser: Authorize user

#
ServiceName
iap.googleapis.com

Description

Records a connection attempt through IAP TCP forwarding (SSH/RDP via an IAP tunnel), gated by the iap.tunnelInstances.accessViaIAP permission. Requires Data Access logging to be enabled for the IAP API.

Data Access audit logs are disabled by default.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

google.cloud.iap.IdentityAwareProxyAdminService.SetIamPolicy: Set IAP IAM policy

#
ServiceName
iap.googleapis.com

Description

Sets the IAM policy on an IAP-secured resource, gated by iap.web.setIamPolicy or iap.webServices.setIamPolicy depending on resource scope.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

google.cloud.iap.IdentityAwareProxyAdminService.GetIamPolicy: Get IAP IAM policy

#
ServiceName
iap.googleapis.com

Description

Reads the IAM policy on an IAP-secured resource (ADMIN_READ).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.GetIapSettings: Get IAP settings

#
ServiceName
iap.googleapis.com

Description

Reads IAP settings (access levels, reauthentication policy) for a project, folder, or resource (ADMIN_READ).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.UpdateIapSettings: Update IAP settings

#
ServiceName
iap.googleapis.com

Description

Updates IAP settings, including access levels and reauthentication policy (DATA_WRITE).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.CreateTunnelDestGroup: Create tunnel destination group

#
ServiceName
iap.googleapis.com

Description

Creates a TCP tunnel destination group used to scope IAP TCP forwarding (DATA_WRITE).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.UpdateTunnelDestGroup: Update tunnel destination group

#
ServiceName
iap.googleapis.com

Description

Updates a TCP tunnel destination group (DATA_WRITE).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.DeleteTunnelDestGroup: Delete tunnel destination group

#
ServiceName
iap.googleapis.com

Description

Deletes a TCP tunnel destination group (DATA_WRITE).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.GetTunnelDestGroup: Get tunnel destination group

#
ServiceName
iap.googleapis.com

Description

Reads a single TCP tunnel destination group (DATA_READ).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.ListTunnelDestGroups: List tunnel destination groups

#
ServiceName
iap.googleapis.com

Description

Lists TCP tunnel destination groups in a project (DATA_READ).

Data Access audit logs are disabled by default.

google.cloud.iap.IdentityAwareProxyAdminService.ValidateIapAttributeExpression: Validate IAP attribute expression

#
ServiceName
iap.googleapis.com

Description

Validates an IAP attribute-based access-control (CEL) expression before it is applied (DATA_WRITE).

Data Access audit logs are disabled by default.