[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-06-16 (世界標準時間)。"],[[["Identity-Aware Proxy (IAP) can utilize external identity providers such as email/password, OAuth, SAML, OIDC, and phone number, rather than solely relying on Google accounts."],["Identity Platform enables multi-tenancy, allowing for the segregation of user populations into isolated pools or \"tenants,\" which is useful in B2B scenarios where a company sells services to other companies."],["Multi-tenancy is not always necessary, for instance, when an application needs to block access to users outside a specific network, or in cases where subsidiaries of a conglomerate share high-level benefits and therefore can authenticate at the project level."],["To enhance security and prevent token leakage, it's possible to assign each IAP resource its own tenant, ensuring that tokens are only valid within the context of that specific tenant."],["A single IAP resource can accommodate multiple tenants, and the tenant to be used can be determined programmatically or by user selection, with user access managed via claims carried in the JSON Web Token."]]],[]]