[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-04-03。"],[[["Identity-Aware Proxy (IAP) can utilize external identity providers such as email/password, OAuth, SAML, OIDC, and phone number, rather than solely relying on Google accounts."],["Identity Platform enables multi-tenancy, allowing for the segregation of user populations into isolated pools or \"tenants,\" which is useful in B2B scenarios where a company sells services to other companies."],["Multi-tenancy is not always necessary, for instance, when an application needs to block access to users outside a specific network, or in cases where subsidiaries of a conglomerate share high-level benefits and therefore can authenticate at the project level."],["To enhance security and prevent token leakage, it's possible to assign each IAP resource its own tenant, ensuring that tokens are only valid within the context of that specific tenant."],["A single IAP resource can accommodate multiple tenants, and the tenant to be used can be determined programmatically or by user selection, with user access managed via claims carried in the JSON Web Token."]]],[]]