[[["わかりやすい","easyToUnderstand","thumb-up"],["問題の解決に役立った","solvedMyProblem","thumb-up"],["その他","otherUp","thumb-up"]],[["わかりにくい","hardToUnderstand","thumb-down"],["情報またはサンプルコードが不正確","incorrectInformationOrSampleCode","thumb-down"],["必要な情報 / サンプルがない","missingTheInformationSamplesINeed","thumb-down"],["翻訳に関する問題","translationIssue","thumb-down"],["その他","otherDown","thumb-down"]],["最終更新日 2025-09-04 UTC。"],[],[],null,["This page describes some scenarios when you might need to authenticate again,\neven if you previously authenticated successfully.\n\nGoogle Workspace session configuration\n\nIf you are accessing Google Cloud by using a Google Workspace user\naccount, your Google Workspace administrator can configure the maximum\nsession length, and whether reauthentication is required when the session\nexpires. The credentials provided by local Application Default Credentials (ADC)\nfiles also expire when the session expires. You must refresh them by running the\n[`gcloud auth application-default login` command](/sdk/gcloud/reference/auth/application-default/login)\nagain.\n\nIf you have questions about your Google Workspace session configuration,\ncontact your Google Workspace administrator. For information about\nsetting the Google Workspace session length, see\n[Set session length for Google Cloud services](https://support.google.com/a/answer/9368756).\n\nIdentity-Aware Proxy reauthentication\n\nIAP can be configured to require reauthentication to protected\nservices and applications after a specific period of time. For more information,\nsee [IAP reauthentication](/iap/docs/configuring-reauth).\n\nRefresh token expiration\n\nRefresh tokens can expire due to session length, or for other reasons. When they\nexpire, you must authenticate again. For more information, see\n[Refresh token expiration](https://developers.google.com/identity/protocols/oauth2#expiration) in the Google Identity documentation.\n\nSensitive actions\n\nThe following Google Cloud actions are considered *sensitive actions*:\n\n- Billing assignment changes\n- IAM allow policy changes at the organization, folder, or project level\n\nTo ensure that these sensitive actions aren't initiated by bad actors using\ncredential theft, Google Cloud adds an extra layer of security by\nrequiring reauthentication.\n\nReauthentication for sensitive actions is in the process of rolling out across\nGoogle Cloud accounts. The rollout is expected to be complete in 2026.\n\nWhen reauthentication is required\n\nWhen you initiate a sensitive action, you are required to reenter your password\nor complete multi-factor authentication (MFA) if all of the following conditions\nare met:\n\n- The action is initiated in the Google Cloud console.\n- You have not reauthenticated in the last 15 minutes.\n- Your user account is managed by Google.\n\nUser accounts managed by an external identity provider (IdP) and federated by\nusing Workforce Identity Federation are not required to reauthenticate.\n\nDisable reauthentication\n\nReauthenticating for sensitive actions is enabled by default. To apply for an\nexception, [contact support](https://console.cloud.google.com/support) with your reason for the\nexception."]]