[ Web Proxy ]
URL:
Viewing: https://cloud.google.com/docs/authentication/reauthentication#sensitive-actions [Back]  [Original]

Reauthentication  |  Authentication  |  Google Cloud Documentation Skip to main content
Google Cloud Documentation [Google Cloud Documentation]
Send feedback

Reauthentication Stay organized with collections Save and categorize content based on your preferences.

This page describes some scenarios when you might need to authenticate again, even if you previously authenticated successfully.

Google Workspace session configuration

If you are accessing Google Cloud by using a Google Workspace user account, your Google Workspace administrator can configure the maximum session length, and whether reauthentication is required when the session expires. The credentials provided by local Application Default Credentials (ADC) files also expire when the session expires. You must refresh them by running the gcloud auth application-default login command again.

If you have questions about your Google Workspace session configuration, contact your Google Workspace administrator. For information about setting the Google Workspace session length, see Set session length for Google Cloud services.

Identity-Aware Proxy reauthentication

IAP can be configured to require reauthentication to protected services and applications after a specific period of time. For more information, see IAP reauthentication.

Refresh token expiration

Refresh tokens can expire due to session length, or for other reasons. When they expire, you must authenticate again. For more information, see Refresh token expiration in the Google Identity documentation.

Sensitive actions

The following Google Cloud actions are considered sensitive actions:

Users who can perform sensitive actions are known as privileged users. To help protect against bad actors impersonating privileged users through cookie theft, Google Cloud requires reauthentication before sensitive actions can be performed.

Reauthentication for sensitive actions is in the process of rolling out across Google Cloud accounts. The rollout is expected to be complete in 2026.

When reauthentication is required

When you initiate a sensitive action, you are required to reenter your password or complete multi-factor authentication (MFA) if all of the following conditions are met:

User accounts managed by an external identity provider (IdP) and federated by using Workforce Identity Federation are not required to reauthenticate.

Disable reauthentication

Reauthenticating for sensitive actions is enabled by default. To apply for an exception, contact support with your reason for the exception.

Send feedback

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2026-08-13 UTC.

Need to tell us more? [[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-08-13 UTC."],[],[]]

Web Proxy Viewer  |  New URL  |  Original Page