OFICIAL Google Cloud Blog

Introducing new session management tools with native, granular controls

What happened
Based on Google Cloud Blog · Sep 15, 2026

Google Cloud has upgraded session management with granular controls, replacing broad defaults with precise, automation-friendly policies to reduce credential theft risks.

Introducing new session management tools with native, granular controls
Google Cloud Blog — Google
Key points
·
Default session length set to 16 hours for all Google Cloud customers to standardize security against credential theft risks.
·
Session policies now use Google Groups for granular targeting, allowing distinct session lengths for specific user roles like billing administrators.
·
Session Controls policy supports application-specific enforcement, preventing disruptions to OAuth-based integrations like dashboards.
Key numbers
·
Google Cloud has extended a 16-hour default session length to all customers, replacing self-configured settings to standardize security against credential theft and account takeover risks.

Google Cloud has extended a 16-hour default session length to all customers, replacing self-configured settings to standardize security against credential theft and account takeover risks. This global rollout concludes the initial phase, but the update introduces deeper integration with Context-Aware Access (CAA) for more flexible and automated session policy management. Administrators can now enforce session controls programmatically using Terraform, gcloud CLI, or REST APIs, aligning with DevSecOps workflows for infrastructure-as-code environments.

A key improvement allows session policies to target specific user groups via Google Groups, replacing organizational unit-based restrictions. This enables tailored session lengths, such as shorter sessions for billing administrators and project owners, while maintaining standard durations for general developers. The shift provides granular control over access durations without being constrained by organizational hierarchies, addressing long-standing user requests for precision.

Session Controls now support application-specific policies, allowing administrators to apply session rules to individual applications rather than enforcing blanket restrictions across all Google Cloud API scopes. This prevents disruptions to legitimate integrations like business intelligence tools or dashboards that rely on OAuth, avoiding all-or-nothing scenarios that could impact productivity.

Google Cloud customers can now manage session policies directly in the Google Cloud Console, alongside other access levels and security bindings in Access Context Manager (ACM). Previously limited to the Google Workspace administrator console, this update provides a unified experience for policy administration, available in preview for Google Cloud administrators.

Original source → Deals on Clipraptor.com →