Stay organized with collections
Save and categorize content based on your preferences.
This page documents production updates to Access Context Manager. You can
periodically check this page for announcements about new or updated features,
bug fixes, known issues, and deprecated functionality.
You can see the latest product updates for all of Google Cloud on the
Google Cloud page, browse and filter all release notes in the
Google Cloud console,
or programmatically access release notes in
BigQuery.
To get the latest product updates delivered to you, add the URL of this page to your
feed
reader, or add the
feed URL directly.
Generally available: App allowlist support for context-aware access
You can now create an access binding with a map of applications to access levels to apply
access levels to specific applications, avoiding unintended effects on other applications. For more information, see Create an access binding with a map of applications to access levels.
June 28, 2024
Generally available: You can now use an internal IP address when specifying an IP address range in basic access levels.
Previously, all VPC networks in a host project were added to a perimeter. You can now do the following:
Add individual VPC networks as members of a perimeter.
Create an ingress rule to authorize individual VPC networks to access a perimeter.
June 30, 2022
Support to add individual VPC networks to a perimeter is now available in Preview.
Previously, the entire VPC host project was added to a perimeter. VPC Service Controls now supports the following enhancements:
You can now add individual VPC networks as members of a perimeter.
You can create an ingress rule to authorize individual VPC networks to access a perimeter.
March 31, 2022
General availability of scoped policies for VPC Service Controls.
To delegate administration of VPC Service Controls perimeters and access levels to folder-level and project-level administrators, you can use scoped policies. You can create access policies that are scoped to specific folders or projects.
General availability of dry run mode for service perimeters.
This release introduces dry run configurations for your service perimeters, allowing you to test changes to perimeters before enforcing the changes. For more information, read about dry run mode.
June 11, 2020
General availability of the Access Context Manager Bulk API.
Use the Access Context Manager Bulk API to replace all of your organization's access levels in one operation. For more information, see Making bulk changes to access levels.
June 01, 2020
General availability of custom access levels.
Custom access levels provide a way to use Common Expression Language to craft custom conditions. Create custom access levels using the gcloud command line tool, the Access Context Manager API, and in the Google Cloud Console using the Advanced Mode for configuring access levels.
April 03, 2020
Beta release of the Access Context Manager Bulk API.
The Access Context Manager Bulk API can be used for operations such as replacing all of your organization's access levels. For more information, see Making bulk changes to access levels.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-08-25 UTC."],[[["\u003cp\u003eThis page provides production updates for Access Context Manager, including new features, bug fixes, known issues, and deprecated functionality.\u003c/p\u003e\n"],["\u003cp\u003eRecent updates include app allowlist support for context-aware access, and the ability to use internal IP addresses within basic access levels.\u003c/p\u003e\n"],["\u003cp\u003eYou can receive updates by adding this page's URL or feed URL to your feed reader.\u003c/p\u003e\n"],["\u003cp\u003eYou can find product updates for all of Google Cloud on the Google Cloud page, browse them on the Google Cloud console, or programmatically access them in BigQuery.\u003c/p\u003e\n"]]],[],null,["# Access Context Manager release notes\n\nThis page documents production updates to Access Context Manager. You can\nperiodically check this page for announcements about new or updated features,\nbug fixes, known issues, and deprecated functionality.\n\n\nYou can see the latest product updates for all of Google Cloud on the\n[Google Cloud](/release-notes) page, browse and filter all release notes in the\n[Google Cloud console](https://console.cloud.google.com/release-notes),\nor programmatically access release notes in\n[BigQuery](https://console.cloud.google.com/bigquery?p=bigquery-public-data&d=google_cloud_release_notes&t=release_notes&page=table).\n\nTo get the latest product updates delivered to you, add the URL of this page to your\n[feed\nreader](https://wikipedia.org/wiki/Comparison_of_feed_aggregators), or add the\n[feed URL](https://cloud.google.com/feeds/access-context-manager-release-notes.xml) directly.\n\nMarch 21, 2025\n--------------\n\nAccess Context Manager now supports custom organization policies. This feature is generally available ([GA](https://cloud.google.com/products#product-launch-stages)). For more information, see [Create custom constraints for Access Context Manager](https://cloud.google.com/access-context-manager/docs/custom-constraints).\n\nOctober 03, 2024\n----------------\n\n**Generally available**: App allowlist support for context-aware access\n\nYou can now create an access binding with a map of applications to access levels to apply\naccess levels to specific applications, avoiding unintended effects on other applications. For more information, see [Create an access binding with a map of applications to access levels](https://cloud.google.com/beyondcorp-enterprise/docs/securing-console-and-apis#create_an_access_binding_with_a_map_of_applications_to_access_levels).\n\nJune 28, 2024\n-------------\n\n[Generally available](https://cloud.google.com/products/#product-launch-stages): You can now use an internal IP address when specifying an IP address range in basic access levels.\n\nFor more information, see [Creating a basic access level](https://cloud.google.com/access-context-manager/docs/create-basic-access-level).\n\nFebruary 17, 2023\n-----------------\n\nThe ability to [add individual VPC networks](https://cloud.google.com/vpc-service-controls/docs/vpc-perimeters-management) to a perimeter is generally available ([GA](https://cloud.google.com/products#product-launch-stages)).\n\nPreviously, all VPC networks in a host project were added to a perimeter. You can now do the following:\n\n- Add individual VPC networks as members of a perimeter.\n- Create an ingress rule to authorize individual VPC networks to access a perimeter.\n\nJune 30, 2022\n-------------\n\nSupport to add individual VPC networks to a perimeter is now available in [Preview](https://cloud.google.com/products/#product-launch-stages).\n\nPreviously, the entire VPC host project was added to a perimeter. VPC Service Controls now supports the following enhancements:\n\n- You can now add individual VPC networks as members of a perimeter.\n- You can create an ingress rule to authorize individual VPC networks to access a perimeter.\n\nMarch 31, 2022\n--------------\n\nGeneral availability of scoped policies for VPC Service Controls.\n\nTo delegate administration of VPC Service Controls perimeters and access levels to folder-level and project-level administrators, you can use [scoped policies](https://cloud.google.com/access-context-manager/docs/scoped-policies). You can create access policies that are scoped to specific folders or projects.\n\nApril 22, 2021\n--------------\n\nGeneral Availability release of [Ingress and egress rules](https://cloud.google.com/vpc-service-controls/docs/ingress-egress-rules) for VPC Service Controls.\n\nOctober 22, 2020\n----------------\n\nAccess levels now support checking the [Storage encryption](https://cloud.google.com/access-context-manager/docs/access-level-attributes#storage-encryption) (`allowedEncryptionStatuses`), [Require admin approval](https://cloud.google.com/access-context-manager/docs/access-level-attributes#require-admin-approval) (`requireAdminApproval`) and [Require corp owned device](https://cloud.google.com/access-context-manager/docs/access-level-attributes#require-corp-owned-device) (`requireCorpOwned`) attributes of requests originating from [mobile devices](https://cloud.google.com/access-context-manager/docs/use-mobile-devices).\n\nJune 30, 2020\n-------------\n\nGeneral availability of dry run mode for service perimeters.\n\nThis release introduces dry run configurations for your service perimeters, allowing you to test changes to perimeters before enforcing the changes. For more information, read about [dry run mode](https://cloud.google.com/vpc-service-controls/docs/dry-run-mode).\n\nJune 11, 2020\n-------------\n\nGeneral availability of the Access Context Manager Bulk API.\n\nUse the Access Context Manager Bulk API to replace all of your organization's access levels in one operation. For more information, see [Making bulk changes to access levels](https://cloud.google.com/access-context-manager/docs/bulk-operations).\n\nJune 01, 2020\n-------------\n\nGeneral availability of custom access levels.\n\n[Custom access levels](https://cloud.google.com/access-context-manager/docs/custom-access-levels) provide a way to use Common Expression Language to craft custom conditions. [Create custom access levels](https://cloud.google.com/access-context-manager/docs/create-custom-access-level) using the `gcloud` command line tool, the Access Context Manager API, and in the Google Cloud Console using the Advanced Mode for configuring access levels.\n\nApril 03, 2020\n--------------\n\nBeta release of the Access Context Manager Bulk API.\n\nThe Access Context Manager Bulk API can be used for operations such as replacing all of your organization's access levels. For more information, see [Making bulk changes to access levels](https://cloud.google.com/access-context-manager/docs/bulk-operations).\n\nFebruary 25, 2020\n-----------------\n\nAccess Context Manager support for mobile devices has entered Beta. You can now [create access levels that target iOS and Android devices](https://cloud.google.com/access-context-manager/docs/use-mobile-devices).\n\nCurrently, the **[OS policy](https://cloud.google.com/access-context-manager/docs/access-level-attributes#os-policy)** and **[Require screen lock](https://cloud.google.com/access-context-manager/docs/access-level-attributes#require-screen-lock)** device attributes are supported for use with iOS and Android devices.\n\nTo take advantage of the new feature, your organization must use Google Workspace [basic mobile device management](https://support.google.com/a/answer/7400753).\n\nJanuary 06, 2020\n----------------\n\nThe Access Context Manager v1beta API is being deprecated in July 2020.\n\nOctober 07, 2019\n----------------\n\nAccess Context Manager's v1alpha API is re-enabled.\n\nThe v1alpha API no longer uses `AccessZone`. `AccessZone` has been replaced with `ServicePerimeter`.\n\nTo use the v1alpha API, you must be whitelisted.\n\nAugust 05, 2019\n---------------\n\nError handling in Access Context Manager API v1alpha:\n\n- Attempting to call any v1alpha API method will start returning errors as of 08/12/2019. \nAccess Context Manager API v1alpha is being deprecated in Q3 2019.\n\nMarch 19, 2019\n--------------\n\nThe following access level attributes are now available:\n\n- Regions\n- For Device policy:\n - Require admin approval\n - Require corp owned device\n - Require verified Chrome OS\n\nMarch 08, 2019\n--------------\n\nGeneral availability of Access Context Manager.\n\nJune 01, 2018\n-------------\n\nAccess Context Manager Closed Beta launch."]]