BigQuery tables now support tags for conditional access control using IAM policies

June 28, 2024 at 9:51:29 AM

BigQuery tables now support tags for conditional access control using IAM policies

You can now use tags on BigQuery tables to conditionally grant or deny access with Identity and Access Management (IAM) policies. This feature is generally available. Tags can also be attached to BigQuery datasets during creation to control access.

Tags and IAM Policies

  • Tags: Key-value pairs attached to tables or datasets, or inherited from other Google Cloud resources.
  • Conditional Policies: Policies can be conditionally applied based on the presence of specific tags. For example, the BigQuery Data Viewer role can be conditionally granted on datasets with the environment:dev tag.

Example Use Case

If you are an organization administrator and your data analysts are part of the analysts@example.com group with the BigQuery Data Viewer role on the userData project, you can use tags to control access for a new data analyst intern to only view the anonymousData dataset.

tag-key-value-example.png

Limitations

  • Unsupported Tables: Tags are not supported on BigQuery Omni tables, hidden datasets, or temporary tables.
  • Cross-Region Queries: Tags are not used in access control checks for cross-region queries in BigQuery Omni.
  • Tag Limits: A maximum of 50 tags can be attached to a dataset or table.
  • Wildcard Queries: Conditional access for tagged tables is not considered in wildcard queries.
  • Service Limitations: Some services outside BigQuery cannot verify IAM tag conditions properly. Positive tag conditions may result in denied access, and negative tag conditions may not be checked.

For more details on creating tags, visit the BigQuery help center.

Have more questions on this topic? Ask our AI assistant for in-depth insights.

Read more from sources 👇

Want Personalized Digital Marketing Insights at Your Preferred Time?

Our Smart Newsletter brings you the latest insights on the topics you love, delivered at your preferred time and frequency.

Discover More

Looker Studio to Add Native Microsoft Excel Connector

Looker Studio to Add Native Microsoft Excel Connector

Sean Zinsmeister
Sean Zinsmeister

Official Source

Official Source

Sean Zinsmeister is a Official Source. The source has been verified by Swipe Insight team.

Official Source
BigQuery Now Allows Drag-and-Drop Tabs

BigQuery Now Allows Drag-and-Drop Tabs

Google Cloud
Google Cloud

Official Source

Official Source

Google Cloud is a Official Source. The source has been verified by Swipe Insight team.

Official Source
Google Ads Updates Gambling and Games Policy to Include Lottery-Courier Ads in 33 States

Google Ads Updates Gambling and Games Policy to Include Lottery-Courier Ads in 33 States

Google
Google

Official Source

Official Source

Google is a Official Source. The source has been verified by Swipe Insight team.

Official Source
Microsoft Ads Launches Property Center and Global Lodging Campaigns

Microsoft Ads Launches Property Center and Global Lodging Campaigns

Microsoft Advertising
Microsoft Advertising

Official Source

Official Source

Microsoft Advertising is a Official Source. The source has been verified by Swipe Insight team.

Official Source
Google Merchant Center Broadens Conversion Tracking Scope Trending ️‍🔥

Google Merchant Center Broadens Conversion Tracking Scope

Google
Google

Official Source

Official Source

Google is a Official Source. The source has been verified by Swipe Insight team.

Official Source
YouTube Adds Option to Request Removal of AI-Generated Content Simulating Your Face/Voice

YouTube Adds Option to Request Removal of AI-Generated Content Simulating Your Face/Voice

Google
Google

Official Source

Official Source

Google is a Official Source. The source has been verified by Swipe Insight team.

Official Source