[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-11。"],[[["\u003cp\u003eThis page details the process of configuring user access to Backup and DR Service using workforce identity federation, which allows users from external identity providers to access Google Cloud services.\u003c/p\u003e\n"],["\u003cp\u003eWorkforce identity federation users can access both the Backup and DR Service within the Google Cloud console and the management console.\u003c/p\u003e\n"],["\u003cp\u003eTo enable Backup and DR Service using a workforce identity federation, you must contact Cloud Customer Care to set up this configuration.\u003c/p\u003e\n"],["\u003cp\u003eAccessing the management console differs for workforce identity federation users, who must use a specific URL designated for external identities and may need to manually update the link to correctly access it.\u003c/p\u003e\n"],["\u003cp\u003eIAM roles need to be granted to workforce identity federation users, allowing them to access the Backup and DR Service, as well as the management console, similar to how roles are granted to Google Account users.\u003c/p\u003e\n"]]],[],null,["# Access Backup and DR Service with workforce identity federation\n\nThis page describes how to configure user access for Backup and DR Service with\nworkforce identity federation. Contact Cloud Customer Care to enable\nBackup and DR Service using a workforce identity federation.\n\n[Workforce identity federation](/iam/docs/workforce-identity-federation) lets\nyou use an external identity provider (IdP) to authenticate and authorize a\nworkforce---a group of *users*, such as employees, partners, and\ncontractors---using IAM, so that the users can access Google Cloud services.\n\nIf workforce identity federation is configured in your project, users in your\nworkforce can access the following:\n\n- Backup and DR Service in [Google Cloud console](https://console.cloud.google)\n- Management console\n\nSet up access to Backup and DR Service with workforce identity federation\n-------------------------------------------------------------------------\n\nThis section describes how to configure access for workforce identity\nfederation users to Backup and DR Service.\n\n### Configure your identity provider\n\nUse the [Configure workforce identity federation](/iam/docs/configuring-workforce-identity-federation#configure_workforce_identity_federation)\nguide to configure the workforce identity federation for your identity provider.\n\n### Grant IAM roles to workforce identity federation users\n\nIn Identity and Access Management (IAM), grant IAM roles to sets of workforce identity federation\nusers, so that they can access Backup and DR Service and the management console to\nprotect workloads:\n\n- For a list of roles specific to Backup and DR Service, see [Grant roles to users](/backup-disaster-recovery/docs/access-control).\n- For instructions about assigning these roles to external users, see [Grant IAM roles to principals](/iam/docs/configuring-workforce-identity-federation#grant_roles_to_principals).\n- The formats used for representing workforce identity federation users in IAM policies, see [Represent workforce pool users in IAM policies](/iam/docs/configuring-workforce-identity-federation#representing-workforce-users).\n\nBackup and DR Service handles workforce identity federation users the same way as\nGoogle Account users--instead of an email address, a [principal identifier](/iam/docs/configuring-workforce-identity-federation#representing-workforce-users) is used.\n\nAccess the Backup and DR Service page in the Google Cloud console\n-----------------------------------------------------------------\n\nThe [Google Cloud workforce identity federation console](/iam/docs/workforce-console-learn-more)\nprovides access to the Backup and DR Service page.\n\nFrom the **Backup and DR Service** page in [Google Cloud workforce identity federation console](https://console.cloud.google), you can deploy the management console, backup/recovery appliances,\nand view Backup and DR Service logs. You can also access the management console\nto backup resources.\n\nAccess the management console\n-----------------------------\n\nWorkforce identity federation users access the management console through a\ndifferent URL than Google-managed users, as follows:\n\n- The URL for workforce identity federation users is\n\n ```\n https://bmc-PROJECT_NUMBER-GENERATED_ID-dot-REGION.backupdr.byoid.googleusercontent.com/\n ```\n- The URL for Google managed user accounts is\n\n ```\n https://bmc-PROJECT_NUMBER-GENERATED_ID-dot-REGION.backupdr.googleusercontent.com/\n ```\n\nOnly users that are authenticated with external identities can access the URL\nfor external identities. If a user visits the URL for external identities while\nnot logged in, they are first redirected to the authentication portal where they\nspecify their workforce pool provider name. Then they are redirected to their\nidentity provider to sign in, and finally they are redirected to the management console.\n\nWorkforce identity federation users cannot directly access the management\nconsole using the URL shared by Google-managed users. To access the management\nconsole as a workforce identity federation user, manually update the link to\n[URL for workforce identity federation users](#access-mc)."]]