BigQuery tables now support tags for conditional access control using IAM policies

June 28, 2024 at 9:51:29 AM

TL;DR BigQuery tables now support tags for conditional access control using IAM policies, a feature that is generally available. Tags, key-value pairs, can be attached to tables or datasets to manage access. Policies can be applied based on specific tags, such as granting the BigQuery Data Viewer role to datasets with a certain tag. This allows for streamlined permission management across related resources.

BigQuery tables now support tags for conditional access control using IAM policies

You can now use tags on BigQuery tables to conditionally grant or deny access with Identity and Access Management (IAM) policies. This feature is generally available. Tags can also be attached to BigQuery datasets during creation to control access.

Tags and IAM Policies

  • Tags: Key-value pairs attached to tables or datasets, or inherited from other Google Cloud resources.
  • Conditional Policies: Policies can be conditionally applied based on the presence of specific tags. For example, the BigQuery Data Viewer role can be conditionally granted on datasets with the environment:dev tag.

Example Use Case

If you are an organization administrator and your data analysts are part of the analysts@example.com group with the BigQuery Data Viewer role on the userData project, you can use tags to control access for a new data analyst intern to only view the anonymousData dataset.

tag-key-value-example.png

Limitations

  • Unsupported Tables: Tags are not supported on BigQuery Omni tables, hidden datasets, or temporary tables.
  • Cross-Region Queries: Tags are not used in access control checks for cross-region queries in BigQuery Omni.
  • Tag Limits: A maximum of 50 tags can be attached to a dataset or table.
  • Wildcard Queries: Conditional access for tagged tables is not considered in wildcard queries.
  • Service Limitations: Some services outside BigQuery cannot verify IAM tag conditions properly. Positive tag conditions may result in denied access, and negative tag conditions may not be checked.

For more details on creating tags, visit the BigQuery help center.

Have more questions on this topic? Ask our AI assistant for in-depth insights.

Read more from sources 👇

The Only Digital Marketing Feed You'll Ever Need.

Stay informed your way. Tailored updates when and how you want them. 100% Free.

10,000+ Users

500+ Sources

1000+ Tools

Or

Related Posts

Google Sheets Integrates BigQuery Saved Queries

Google Sheets Integrates BigQuery Saved Queries

Google
Google

Official Source

Official Source

Google is a Official Source. The source has been verified by Swipe Insight team.

Official Source
Audit your GA4 account in Minutes

Audit your GA4 account in Minutes

Sponsored
GA4 Auditor
GA4 Auditor

Verified Sponsor

Verified Sponsor

GA4 Auditor is a Verified Sponsor. Want to get featured here? Contact us.

Verified Sponsor
BigQuery Expands Search Index Capabilities with INT64 and TIMESTAMP Support

BigQuery Expands Search Index Capabilities with INT64 and TIMESTAMP Support

Google Cloud
Google Cloud

Official Source

Official Source

Google Cloud is a Official Source. The source has been verified by Swipe Insight team.

Official Source
Google Ends Free Access to Gemini in BigQuery, Announces Paid Plans

Google Ends Free Access to Gemini in BigQuery, Announces Paid Plans

Google Cloud
Google Cloud

Official Source

Official Source

Google Cloud is a Official Source. The source has been verified by Swipe Insight team.

Official Source
Google Cloud Enhances Looker with Major User Experience Updates

Google Cloud Enhances Looker with Major User Experience Updates

Sean Zinsmeister
Sean Zinsmeister

Official Source

Official Source

Sean Zinsmeister is a Official Source. The source has been verified by Swipe Insight team.

Official Source
BigQuery Launches Gemini-Enhanced SQL Translation Features

BigQuery Launches Gemini-Enhanced SQL Translation Features

Google Cloud
Google Cloud

Official Source

Official Source

Google Cloud is a Official Source. The source has been verified by Swipe Insight team.

Official Source
BigQuery Data Transfer Service Launches Data Source Change Log for Schema Updates

BigQuery Data Transfer Service Launches Data Source Change Log for Schema Updates

Google Cloud
Google Cloud

Official Source

Official Source

Google Cloud is a Official Source. The source has been verified by Swipe Insight team.

Official Source
BigQuery Introduces AI-Augmented Data Preparation with Gemini

BigQuery Introduces AI-Augmented Data Preparation with Gemini

Google Cloud
Google Cloud

Official Source

Official Source

Google Cloud is a Official Source. The source has been verified by Swipe Insight team.

Official Source

Related Tools

GA4 Auditor logo

GA4 Auditor

Verified Tool

Verified Tool

GA4 Auditor is a Verified Tool. Want to get this badge? Contact us.

Verified Tool

Automated GA4 audits with actionable insights

Get Featured Here

Showcase your tool in this list.

Contact Us
GA4 SQL logo

GA4 SQL

Verified Tool

Verified Tool

GA4 SQL is a Verified Tool. Want to get this badge? Contact us.

Verified Tool

Generate GA4 BigQuery queries easily

Data Analysis
TapClicks logo

TapClicks

Automated marketing solutions powered by your data

Data Engineering
Stitch logo

Stitch

Automated cloud data pipelines, no coding needed

Data Engineering
Akkio logo

Akkio

AI-powered analytics for agencies

Data Analysis
Databricks logo

Databricks

Generative AI-powered data intelligence platform

Data Engineering
NinjaCat logo

NinjaCat

AI-powered marketing data and analytics platform

Reporting
Funnel logo

Funnel

Aggregate and analyze marketing data seamlessly

Reporting
Fivetran logo

Fivetran

Effortlessly centralize and move data from any source

Data Engineering
Power My Analytics logo

Power My Analytics

Automate and integrate your marketing data

Reporting

Get Featured Here

Showcase your tool in this list.

Contact Us