Yandex Identity and Access Management release notes
Labels next to update description indicate the interface supporting the update: management console, CLI, API, or Terraform.
March 2026
-
Added the following roles:
Yandex Cloud AI Studio
User role Description ai.guardrails.adminEnables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such guardrails. ai.guardrails.auditorEnables viewing metadata on guardrails for model responses. ai.guardrails.editorEnables viewing info on guardrails for model responses, as well as creating, applying, modifying, and deleting such guardrails. ai.guardrails.userEnables applying guardrails for model responses and viewing metadata on such guardrails. ai.guardrails.viewerEnables viewing info on guardrails for model responses. Yandex MPP Analytics for PostgreSQL
User role Description managed-greenplum.maintenanceTask.editorEnables viewing info on maintenance tasks for Greenplum® clusters and modifying such tasks, as well as viewing info on Greenplum® clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations. managed-greenplum.maintenanceTask.viewerEnables viewing info on Greenplum® clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations. managed-greenplum.userEnables using Greenplum® clusters. Yandex Managed Service for Apache Airflow™
User role Description managed-airflow.maintenanceTask.editorEnables viewing info on maintenance tasks for Apache Airflow™ clusters and modifying such tasks, as well as viewing info on Apache Airflow™ clusters, access permissions granted for them, and on the service quotas. managed-airflow.maintenanceTask.viewerEnables viewing info on Apache Airflow™ clusters, access permissions granted for them, and their maintenance tasks, as well as on the service quotas. Yandex Managed Service for Apache Kafka®
User role Description managed-kafka.maintenanceTask.editorEnables viewing info on maintenance tasks for Apache Kafka® clusters and modifying such tasks, as well as viewing info on Apache Kafka® clusters, access permissions granted for them, and on the service quotas and resource operations. managed-kafka.maintenanceTask.viewerEnables viewing info on Apache Kafka® clusters, access permissions granted for them, their maintenance tasks, and on the service quotas and resource operations. managed-kafka.userEnables using Apache Kafka® clusters. Yandex Managed Service for Apache Spark™
User role Description managed-spark.maintenanceTask.editorEnables viewing info on maintenance tasks for Apache Spark™ clusters and modifying such tasks, as well as viewing info on Apache Spark™ clusters, access permissions granted for them, and on service quotas. managed-spark.maintenanceTask.viewerEnables viewing info on Apache Spark™ clusters, access permissions granted for them, their maintenance tasks, and on service quotas. Yandex Managed Service for ClickHouse®
User role Description managed-clickhouse.maintenanceTask.editorEnables viewing info on maintenance tasks for ClickHouse® clusters and modifying such tasks, as well as viewing info on ClickHouse® clusters, access permissions granted for them, and on the service quotas and resource operations. managed-clickhouse.maintenanceTask.viewerEnables viewing info on ClickHouse® clusters, their maintenance tasks, access permissions granted for them, and on the service quotas and resource operations. managed-clickhouse.userEnables using ClickHouse® clusters. Yandex Managed Service for MySQL®
User role Description managed-mysql.maintenanceTask.editorEnables viewing info on maintenance tasks for MySQL® clusters and modifying such tasks, as well as viewing info on MySQL® clusters and access permissions granted for them, on hosts and cluster backups, and on the service quotas and resource operations. managed-mysql.maintenanceTask.viewerEnables viewing info on MySQL® clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations. managed-mysql.switcherEnables re-assigning the master host in MySQL® clusters, viewing info on MySQL® clusters, hosts, databases, and users, as well as viewing cluster logs, quotas, and resource operations. managed-mysql.userEnables using MySQL® clusters. Yandex Managed Service for OpenSearch
User role Description managed-opensearch.maintenanceTask.editorEnables viewing info on maintenance tasks for OpenSearch clusters and modifying such tasks, as well as viewing info on OpenSearch clusters, access permissions granted for them, and on the service quotas and resource operations. managed-opensearch.maintenanceTask.viewerEnables viewing info on OpenSearch clusters, access permissions granted for them, their maintenance tasks, and on the service quotas and resource operations. managed-opensearch.userEnables using OpenSearch clusters. Yandex Managed Service for PostgreSQL
User role Description managed-postgresql.maintenanceTask.editorEnables viewing info on maintenance tasks for PostgreSQL clusters and modifying such tasks, as well as viewing info on PostgreSQL clusters and access permissions granted for them, on hosts and cluster backups, and on the service quotas and resource operations. managed-postgresql.maintenanceTask.viewerEnables viewing info on PostgreSQL clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on the service quotas and resource operations. managed-postgresql.switcherEnables re-assigning the master host in PostgreSQL clusters, viewing info on PostgreSQL clusters, hosts, databases, and users, as well as viewing cluster logs, quotas, and resource operations. managed-postgresql.userEnables using PostgreSQL clusters. Yandex Managed Service for Sharded PostgreSQL
User role Description managed-spqr.maintenanceTask.editorEnables viewing info on maintenance tasks for Sharded PostgreSQL clusters and modifying such tasks, as well as viewing info on Sharded PostgreSQL clusters, access permissions granted for them, cluster hosts, the service quotas, and resource operations. managed-spqr.maintenanceTask.viewerEnables viewing info on Sharded PostgreSQL clusters, their maintenance tasks, access permissions granted for them, hosts, and on the service quotas and resource operations. Yandex Managed Service for Trino
User role Description managed-trino.maintenanceTask.editorEnables viewing info on maintenance tasks for Trino clusters and modifying such tasks, as well as viewing info on Trino clusters, access permissions granted for them, and on the service quotas. managed-trino.maintenanceTask.viewerEnables viewing info on Trino clusters, access permissions granted for them, their maintenance tasks, and on the service quotas. Yandex Managed Service for Valkey™
User role Description managed-redis.maintenanceTask.editorEnables viewing info on maintenance tasks for Valkey™ clusters and modifying such tasks, as well as viewing info on Valkey™ clusters and access permissions granted for them, on hosts and cluster backups, and on the service quotas and resource operations. managed-redis.maintenanceTask.viewerEnables viewing info on Valkey™ clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations. managed-redis.switcherEnables re-assigning the master host in Valkey™ clusters and viewing info on Valkey™ hosts and clusters, their logs, as well as info on quotas and resource operations. managed-redis.userEnables using Valkey™ clusters. Yandex StoreDoc
User role Description managed-mongodb.maintenanceTask.editorEnables viewing info on maintenance tasks for Yandex StoreDoc clusters and modifying such tasks, as well as viewing info on Yandex StoreDoc clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations. managed-mongodb.maintenanceTask.viewerEnables viewing info on Yandex StoreDoc clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations. managed-mongodb.switcherEnables re-assigning the master host in Yandex StoreDoc clusters and viewing info on Yandex StoreDoc clusters, hosts, shards, databases, users, cluster logs, quotas, and resource operations. managed-mongodb.userEnables using Yandex StoreDoc clusters.
February 2026
-
Added support for managing access policies.
Management console -
Added commands for access policy management at the organization, cloud, and folder level:
yc organization-manager organization list-access-policy-bindingsyc organization-manager organization bind-access-policyyc organization-manager organization unbind-access-policyCLI
-
Added the following roles:
Yandex Cloud Backup
User role Description backup.auditorAllows viewing details on virtual machines and BareMetal servers connected to Cloud Backup, backup policies and service quotas, your cloud and folder.
December 2025
-
Added the
yc iam access-key issue-ephemeralcommand for issuing ephemeral keys.CLI -
Added support for the
yandex_iam_oauth_client_secretresource to manage OAuth client secrets.Terraform -
Added the
labelsfield to theyandex_iam_service_accountresource to work with labels.Terraform -
For the
yandex_iam_oauth_clientresource, changed thescopesandredirect_urisfields to the set type to prevent comparison collisions.Terraform -
Added the following roles:
Yandex Cloud Backup
User role Description backup.userEnables connecting backup providers, connecting VMs and Yandex BareMetal servers to Cloud Backup, associating and disassociating backup policies with VMs and Yandex BareMetal servers, and viewing Cloud Backup resource and quota details. Yandex Managed Service for MySQL®
User role Description managed-mysql.clusters.connectorEnables Yandex Cloud users to connect to databases in Yandex Managed Service for MySQL® clusters via Yandex Identity and Access Management. Yandex Managed Service for PostgreSQL
User role Description managed-postgresql.clusters.connectorEnables Yandex Cloud users to connect to databases in Yandex Managed Service for PostgreSQL clusters via Yandex Identity and Access Management. Yandex Monium
User role Description monium.adminEnables managing Monium resources, viewing and writing all types of telemetry data, and managing projects and access to projects. monium.editorEnables managing Monium resources, viewing and writing all types of telemetry data. monium.viewerEnables viewing details on Monium resources and reading all types of telemetry data. monium.auditorEnables viewing details on Monium resources. monium.alerts.editorEnables viewing the list of alerts, their settings, and trigger history, as well as creating, modifying, and deleting alerts. monium.alerts.viewerEnables viewing the list of alerts, their settings, and trigger history. monium.channels.editorEnables viewing the list of alert notification channels and their details, as well as creating, modifying, and deleting such channels. monium.channels.viewerEnables viewing the list of alert notification channels and their details. monium.contextLinks.editorEnables viewing configured context links on dashboard charts, as well as creating, editing, and deleting such links. monium.contextLinks.viewerEnables viewing configured context links on dashboard charts. monium.dashboards.editorEnables viewing dashboards and their widgets, as well as creating, editing, and deleting dashboards. monium.dashboards.viewerEnables viewing dashboards and their widgets. monium.escalationPolicies.editorEnables viewing the list of alert escalation policies and their settings, as well as creating, updating, and deleting such policies. monium.escalationPolicies.viewerEnables viewing the list of alert escalation policies and their settings. monium.escalations.editorEnables viewing details on alert notifications and escalations, as well as creating, editing, and deleting escalations. monium.escalations.viewerEnables viewing details on alert notifications and escalations. monium.logErrorLabels.editorEnables viewing, editing, and deleting the existing labels as well as adding new ones to errors in logs. monium.logErrorLabels.viewerEnables viewing labels for log errors. monium.logs.readerEnables reading logs and viewing log error statistics. monium.logs.writerEnables writing logs. monium.metrics.readerEnables reading metrics, their values, and labels. monium.metrics.writerEnables writing metrics. monium.mutes.editorEnables viewing, creating, editing, and deleting mutes, i.e., rules for temporarily disabling alert notifications. monium.mutes.viewerEnables viewing mutes, i.e., rules for temporarily disabling alert notifications. monium.quickLinks.editorEnables viewing the list of configured quick links and their details in the project menu, as well as creating, editing, and deleting such links. monium.quickLinks.viewerEnables viewing the list of configured quick links and their details in the project menu. monium.serviceLevelObjectives.editorEnables viewing configured service level objectives (SLOs), as well as creating, editing, and deleting them. monium.serviceLevelObjectives.viewerEnables viewing configured service level objectives (SLOs). monium.shards.editorEnables viewing details on shards, clusters, services and their quotas, as well as creating, updating, and deleting shards. monium.shards.viewerEnables viewing details on shards, clusters, services and their quotas. monium.telemetry.readerEnables reading all types of Monium telemetry data, such as metrics, logs, and distributed tracing data. monium.telemetry.writerEnables writing all types of Monium telemetry data, such as metrics, logs, and distributed tracing data. monium.traces.readerEnables viewing distributed tracing data. monium.traces.writerEnables writing distributed tracing data. Yandex MPP Analytics for PostgreSQL
User role Description managed-greenplum.clusters.connectorEnables Yandex Cloud users to connect to databases in Yandex MPP Analytics for PostgreSQL clusters via Yandex Identity and Access Management. Yandex Security Deck
User role Description security-deck.alertSinks.adminEnables managing alert sinks and alerts, as well as access to them. security-deck.alertSinks.editorEnables managing alert sinks, alerts, and comments in them. security-deck.alertSinks.userEnables viewing details on alert sinks and using them. security-deck.alertSinks.viewerEnables viewing details on alerts and alert sinks as well as on access permissions granted for them. security-deck.alertSinks.auditorEnables viewing details on alert sinks and access permissions granted for them.
November 2025
-
Added the ability to view a list of subject’s accesses using the CLI and API.
Management consoleCLIAPI -
Added the following roles:
Yandex Cloud Interconnect
User role Description cic.adminEnables managing Cloud Interconnect resources. Yandex Cloud Router
User role Description cloud-router.adminEnables managing Cloud Router resources. cloud-router.prefixEditorEnables managing IP prefixes of cloud subnets in routing instances, as well as viewing info on Cloud Router resources. Yandex Identity Hub
User role Description organization-manager.idpInstances.billingAdminEnables managing your subscription to the paid Yandex Identity Hub features. organization-manager.idpInstances.billingViewerEnables viewing the list of users who employ the Yandex Identity Hub authentication quota in the current reporting period, as well as viewing info on a subscription to the paid-for Yandex Identity Hub features and stats regarding the use of the quotas within this subscription.
October 2025
-
Supported managing service access to user resources via the management console
.Management console -
Added the following roles:
Managed databases
User role Description mdb.restorerEnables restoring managed database clusters from backups and grants read access to such clusters and their logs. Yandex Identity Hub
User role Description organization-manager.groups.externalConverterEnables adding an attribute with an external group ID to Yandex Identity Hub user groups when synchronizing with user groups in Active Directory or another external source. organization-manager.groups.externalCreatorEnables creating Yandex Identity Hub user groups when synchronizing with user groups in Active Directory or another external source. organization-manager.userpools.syncAgentEnables synchronizing Yandex Identity Hub users and groups with users and groups in Active Directory or another external source. Yandex Managed Service for Apache Kafka®
User role Description managed-kafka.restorerEnables restoring Apache Kafka® clusters from backups, viewing information about such clusters and their logs, as well as information about Managed Service for Apache Kafka® quotas and resource operations. Yandex Managed Service for ClickHouse®
User role Description managed-clickhouse.restorerEnables restoring ClickHouse® clusters from backups, viewing information about ClickHouse® clusters and their logs, as well as information about Managed Service for ClickHouse® quotas and resource operations. Yandex Managed Service for MySQL®
User role Description managed-mysql.restorerEnables restoring MySQL® clusters from backups, viewing information about MySQL® clusters, hosts, databases, and users, cluster logs, as well as information about Managed Service for MySQL® quotas and resource operations. Yandex Managed Service for OpenSearch
User role Description managed-opensearch.restorerEnables restoring OpenSearch clusters from backups, viewing information about OpenSearch clusters and their logs, as well as information about Managed Service for OpenSearch quotas and resource operations. Yandex Managed Service for PostgreSQL
User role Description managed-postgresql.restorerEnables restoring PostgreSQL clusters from backups, viewing information about PostgreSQL clusters, hosts, databases, and users, cluster logs, as well as information about Managed Service for PostgreSQL quotas and resource operations. Yandex Managed Service for Sharded PostgreSQL
User role Description managed-spqr.restorerEnables restoring Sharded PostgreSQL clusters from backups, viewing information about Sharded PostgreSQL clusters, hosts, databases, and users, cluster logs, as well as information about Managed Service for Sharded PostgreSQL quotas and resource operations. Yandex Managed Service for Valkey™
User role Description managed-redis.restorerEnables restoring Valkey™ clusters from backups, viewing information about Valkey™ hosts and clusters, their logs, as well as information about Yandex Managed Service for Valkey™ quotas and resource operations. Yandex MPP Analytics for PostgreSQL
User role Description managed-greenplum.restorerEnables restoring Greenplum® clusters from backups, viewing information about Greenplum® clusters and hosts, their logs, as well as information about Yandex MPP Analytics for PostgreSQL quotas and resource operations. Yandex StoreDoc
User role Description managed-mongodb.restorerEnables restoring MongoDB clusters from backups, viewing information about MongoDB clusters, hosts, shards, databases, and users, cluster logs, as well as information about Yandex StoreDoc quotas and resource operations.
Q3 2025
- Implemented management of OAuth client secrets using the CLI and API.
CLIAPI - Added a group of commands for OAuth client management to the CLI and API.
CLIAPI
Q2 2025
- Enabled creating and using refresh tokens.
CLI
Q1 2025
- Added new scopes for API keys and the ability to assign more than one scope per service.
Management consoleCLITerraformAPI - Workload identity federations are now available to all users.
Management consoleCLITerraformAPI - Added creating an ID token for service account, a special short-lived token for authentication in third-party systems.
Management consoleCLITerraformAPI
Q4 2024
- Added sending the
CreateIamTokendata event when creating an IAM token. - Expanded the scope of limited lifetime API keys to work with Yandex Managed Service for YDB in compatibility mode with PostgreSQL, Yandex Cloud Postbox, and Yandex Serverless Containers.
Management consoleCLITerraformAPI - You can now see the service account's last authentication date and time. You can get the information in the
last_authenticated_atfield using theyc iam user-account getYandex Cloud CLI command.CLI
Q3 2024
- Added Workload Identity Federations that allow you to grant access to external applications without using long-lived access keys.
Management consoleCLITerraformAPI - You can now create API keys with limited scope and validity period.
Management consoleCLITerraformAPI - Added the ResolveAgent REST API method.
API - Added the ability to revoke an IAM token using the Yandex Cloud CLI.
CLI - Added
All users in organization XandAll users in federation Nsystem groups. - Added the Terraform data source used to get the service agent ID.
Terraform
Q2 2024
- Added the last used date info for service account access keys. You can find this info on the service account page in the management console
or in thelast_used_atfield when using the API to invoke access key management methods.Management consoleAPI
Q1 2024
- Added the Security Token Service component to get temporary access keys compatible with AWS S3 API. This feature is at the Preview stage.
CLIAPI - Added OAuth client authentication support by authenticating a service account token.
- Added the option of using masked token ID for Audit Trails logs.
- Improved the key rotation mechanism in OpenID Connect
.