StudyToCert

All certifications / Associate Cloud Engineer / Lessons

Google Cloud Associate Cloud Engineer Associate Cloud Engineer · Domain 4: Configuring access and security

IAM roles: basic, predefined and custom roles, and least privilege

▶ Watch the overview video

Last reviewed September 25, 2026 · Leer en español

In Google Cloud you never grant permissions directly; you grant roles, which are collections of permissions. A permission has the form service.resource.verb, such as compute.instances.start or storage.objects.get. Picking the right role is the core of least privilege: give each principal only the access its job requires, at the narrowest scope that works.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 4 more sections, 4 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study Associate Cloud Engineer for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Associate Cloud Engineer study plan