Introducing new session manage... Note

Introducing new session management tools with native, granular controls

Google Cloud has enhanced its session management to bolster security and mitigate credential theft. A default 16-hour session length is now applied to all customers who hadn't previously configured their own. This security standard has been extended globally to ensure broader protection. The session controls have evolved beyond simple administrative settings to become a granular feature integrated with Context-Aware Access. This update provides administrators with increased flexibility, better automation, and a more streamlined security workflow. Support for infrastructure as code through Terraform, gcloud CLI, and REST APIs enables programmatic management of session policies. Policies can now be targeted with precision using Google Groups, allowing for distinct session lengths for different user groups like elevated privilege users. Session controls can also be applied to specific applications such as the Google Cloud Console and gcloud CLI, preventing over-restrictive blanket policies. Administrators can now manage these policies directly within the Google Cloud Console via Access Context Manager, offering a unified experience. These changes allow for tighter reauthentication boundaries in high-risk areas without hindering developer productivity.