implementing-beyondcorp-zero-trust-access-model skill (Anthropic-Cybersecurity-Skills)
- Install
- SKILL.md (verbatim)
- When to Use
- Prerequisites
- Workflow
- Step 1: Configure Access Context Manager with Access Levels
- Step 2: Deploy Identity-Aware Proxy on Applications
- Step 3: Configure IAM Bindings with Access Level Conditions
- Step 4: Deploy Endpoint Verification on Corporate Devices
- Step 5: Implement BeyondCorp Enterprise Threat Protection
- Step 6: Monitor and Audit BeyondCorp Access Decisions
- Key Concepts
- Tools & Systems
- Common Scenarios
- Scenario: Migrating 50+ Internal Applications from VPN to BeyondCorp
- Output Format
- Other files in this skill
- assets/template.md (verbatim)
- Project Information
- Pre-Migration Checklist
- Identity Provider Configuration
- Google Cloud Infrastructure
- Endpoint Verification
- Access Level Design
- Application Migration Tracker
- Session Policy Configuration
- Post-Migration Validation
- Functional Testing
- Security Testing
- Monitoring
- VPN Decommission Timeline
- Sign-Off
- references/api-reference.md (verbatim)
- Dependencies
- CLI Usage
- Functions
- getgcloudtoken() -> str
- listiapresources(projectid, token) -> list
- getiapsettings(projectid, resource, token) -> dict
- listaccesslevels(orgid, policyname, token) -> list
- auditiapbindings(projectid, token) -> list
- assesszerotrustposture(projectid, token) -> dict
- generatereport(projectid, token) -> dict
- Google Cloud APIs Used
- Output Schema
- references/standards.md (verbatim)
- NIST SP 800-207: Zero Trust Architecture
- CISA Zero Trust Maturity Model v2.0 (April 2023)
- Google BeyondCorp Papers
- Google Cloud IAP Documentation
- NIST SP 800-63-3: Digital Identity Guidelines
- DoD Zero Trust Reference Architecture v2.0
- references/workflows.md (verbatim)
- Phase 1: Discovery and Planning (Weeks 1-2)
- 1.1 Application Inventory
- 1.2 Device Inventory
- 1.3 Access Level Design
- Phase 2: Infrastructure Setup (Weeks 3-4)
- 2.1 Google Cloud Configuration
- 2.2 Access Context Manager Setup
- 2.3 Endpoint Verification Deployment
- Phase 3: Application Migration (Weeks 5-10)
- 3.1 GCP-Hosted HTTPS Applications
- 3.2 On-Premises Applications
- 3.3 SaaS Applications
- Phase 4: Policy Enforcement (Weeks 11-12)
- 4.1 Gradual Enforcement
- 4.2 Re-authentication Configuration
- Phase 5: VPN Decommission (Weeks 13-16)
- 5.1 Parallel Operation
- 5.2 VPN Retirement
- Phase 6: Continuous Monitoring (Ongoing)
- 6.1 Access Analytics
- 6.2 Policy Optimization
What it does. 'Implement Google''s BeyondCorp zero trust access model using Cloud Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).
| Upstream | mukul975/Anthropic-Cybersecurity-Skills |
| Skill file | skills/implementing-beyondcorp-zero-trust-access-model/SKILL.md |
| License | Apache-2.0 (skill folder LICENSE) |
| Author | mukul975 |
| Fetched | 2026-09-10 |
Install
npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-beyondcorp-zero-trust-access-model, or copy the skill folder into~/.claude/skills/implementing-beyondcorp-zero-trust-access-model/.- Raw file:
curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/implementing-beyondcorp-zero-trust-access-model/SKILL.md
SKILL.md (verbatim)
name: implementing-beyondcorp-zero-trust-access-model
description: 'Implement Google''s BeyondCorp zero trust access model using Cloud
IAP, Access Context Manager, Endpoint Verification, Chrome Enterprise Premium, and
BeyondCorp Enterprise Connectors to enforce identity- and device-aware access for
VPN-less application access. Use for replacing VPN, enforcing device posture checks,
or securing remote/hybrid access to GCP-hosted or on-prem apps; not for raw network-level
protocols.
'
domain: cybersecurity
subdomain: zero-trust-architecture
tags:
- beyondcorp
- zero-trust
- google-cloud
- iap
- identity-aware-proxy
- ztna
- access-context-manager
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- PR.AA-01
- PR.AA-05
- PR.IR-01
- GV.PO-01
mitre_attack:
- T1078
- T1190
- T1059
- T1078.004
- T1530
Implementing BeyondCorp Zero Trust Access Model
When to Use
- When replacing traditional VPN infrastructure with identity-based application access
- When migrating to Google Cloud and requiring zero trust access for internal applications
- When implementing device trust verification as a prerequisite for resource access
- When needing context-aware access policies based on user identity, device posture, and location
- When securing access for remote and hybrid workforce without network-level trust
Do not use when applications require raw network-level access (e.g., UDP-based protocols not supported by IAP), for consumer-facing public applications, or when the organization lacks an identity provider with MFA capabilities.
Prerequisites
- Google Cloud organization with Cloud Identity or Google Workspace
- Identity-Aware Proxy (IAP) API enabled on the GCP project
- Chrome Enterprise Premium license for endpoint verification
- Applications deployed behind a Google Cloud Load Balancer or on App Engine/Cloud Run
- Endpoint Verification extension deployed on all corporate devices
- Access Context Manager API enabled
Workflow
Step 1: Configure Access Context Manager with Access Levels
Define access levels that represent trust tiers based on device and user attributes.
# Enable required APIs
gcloud services enable iap.googleapis.com
gcloud services enable accesscontextmanager.googleapis.com
gcloud services enable beyondcorp.googleapis.com
# Create an access policy (organization level)
gcloud access-context-manager policies create \
--organization=ORG_ID \
--title="BeyondCorp Enterprise Policy"
# Create a basic access level for corporate managed devices
cat > corporate-device-level.yaml << 'EOF'
- devicePolicy:
allowedEncryptionStatuses:
- ENCRYPTED
osConstraints:
- osType: DESKTOP_CHROME_OS
minimumVersion: "13816.0.0"
- osType: DESKTOP_WINDOWS
minimumVersion: "10.0.19045"
- osType: DESKTOP_MAC
minimumVersion: "13.0.0"
requireScreenlock: true
requireAdminApproval: true
regions:
- US
- GB
- DE
EOF
gcloud access-context-manager levels create corporate-managed \
--policy=POLICY_ID \
--title="Corporate Managed Device" \
--basic-level-spec=corporate-device-level.yaml
# Create a custom access level using CEL expressions
gcloud access-context-manager levels create high-trust \
--policy=POLICY_ID \
--title="High Trust Level" \
--custom-level-spec=high-trust-cel.yaml
Step 2: Deploy Identity-Aware Proxy on Applications
Enable IAP on backend services to enforce identity verification before granting access.
# Create OAuth consent screen
gcloud iap oauth-brands create \
--application_title="Corporate Applications" \
--support_email=security@company.com
# Create OAuth client for IAP
gcloud iap oauth-clients create BRAND_NAME \
--display_name="BeyondCorp IAP Client"
# Enable IAP on a backend service (GCE/GKE behind HTTPS LB)
gcloud compute backend-services update internal-app-backend \
--iap=enabled,oauth2-client-id=CLIENT_ID,oauth2-client-secret=CLIENT_SECRET \
--global
# Enable IAP on App Engine
gcloud iap web enable \
--resource-type=app-engine \
--oauth2-client-id=CLIENT_ID \
--oauth2-client-secret=CLIENT_SECRET
# Enable IAP on Cloud Run service
gcloud run services add-iam-policy-binding internal-api \
--member="serviceAccount:service-PROJECT_NUM@gcp-sa-iap.iam.gserviceaccount.com" \
--role="roles/run.invoker" \
--region=us-central1
Step 3: Configure IAM Bindings with Access Level Conditions
Bind IAP access to specific groups with access level requirements.
# Grant access to engineering group with corporate device requirement
gcloud iap web add-iam-policy-binding \
--resource-type=backend-services \
--service=internal-app-backend \
--member="group:engineering@company.com" \
--role="roles/iap.httpsResourceAccessor" \
--condition="expression=accessPolicies/POLICY_ID/accessLevels/corporate-managed,title=Require Corporate Device"
# Grant access to contractors with high-trust requirement
gcloud iap web add-iam-policy-binding \
--resource-type=backend-services \
--service=internal-app-backend \
--member="group:contractors@company.com" \
--role="roles/iap.httpsResourceAccessor" \
--condition="expression=accessPolicies/POLICY_ID/accessLevels/high-trust,title=Require High Trust"
# Configure re-authentication settings (session duration)
gcloud iap settings set --project=PROJECT_ID \
--resource-type=compute \
--service=internal-app-backend \
--reauth-method=LOGIN \
--max-session-duration=3600s
Step 4: Deploy Endpoint Verification on Corporate Devices
Roll out Chrome Enterprise Endpoint Verification for device posture collection.
# Deploy Endpoint Verification via Chrome policy (managed browsers)
# In Google Admin Console > Devices > Chrome > Apps & extensions
# Force-install: Endpoint Verification extension ID: callobklhcbilhphinckomhgkigmfocg
# Verify device inventory in Admin SDK
gcloud endpoint-verification list-endpoints \
--filter="deviceType=CHROME_BROWSER" \
--format="table(deviceId, osVersion, isCompliant, encryptionStatus)"
# Create device trust connector for third-party EDR signals
gcloud beyondcorp app connections create crowdstrike-connector \
--project=PROJECT_ID \
--location=global \
--application-endpoint=host=crowdstrike-api.internal:443,port=443 \
--type=TCP_PROXY_TUNNEL \
--connectors=projects/PROJECT_ID/locations/us-central1/connectors/connector-1
# List enrolled devices and their compliance status
gcloud alpha devices list --format="table(name,deviceType,complianceState)"
Step 5: Implement BeyondCorp Enterprise Threat Protection
Enable URL filtering, malware scanning, and DLP for Chrome Enterprise users.
# Configure Chrome Enterprise Premium threat protection rules
# In Google Admin Console > Security > Chrome Enterprise Premium
# Create a BeyondCorp Enterprise connector for on-prem apps
gcloud beyondcorp app connectors create onprem-connector \
--project=PROJECT_ID \
--location=us-central1 \
--display-name="On-Premises App Connector"
gcloud beyondcorp app connections create hr-portal \
--project=PROJECT_ID \
--location=us-central1 \
--application-endpoint=host=hr.internal.company.com,port=443 \
--type=TCP_PROXY_TUNNEL \
--connectors=projects/PROJECT_ID/locations/us-central1/connectors/onprem-connector
# Enable security investigation tool for access anomaly detection
gcloud logging read '
resource.type="iap_tunnel"
jsonPayload.decision="DENY"
timestamp >= "2026-02-22T00:00:00Z"
' --project=PROJECT_ID --format=json --limit=100
Step 6: Monitor and Audit BeyondCorp Access Decisions
Set up comprehensive logging and alerting for zero trust policy enforcement.
# Create a log sink for IAP access decisions
gcloud logging sinks create iap-access-audit \
--destination=bigquery.googleapis.com/projects/PROJECT_ID/datasets/beyondcorp_audit \
--log-filter='resource.type="iap_tunnel" OR resource.type="gce_backend_service"'
# Query BigQuery for access pattern analysis
bq query --use_legacy_sql=false '
SELECT
protopayload_auditlog.authenticationInfo.principalEmail AS user,
resource.labels.backend_service_name AS application,
JSON_EXTRACT_SCALAR(protopayload_auditlog.requestMetadata.callerSuppliedUserAgent, "$") AS device,
protopayload_auditlog.status.code AS decision_code,
COUNT(*) AS request_count
FROM `PROJECT_ID.beyondcorp_audit.cloudaudit_googleapis_com_data_access`
WHERE timestamp > TIMESTAMP_SUB(CURRENT_TIMESTAMP(), INTERVAL 24 HOUR)
GROUP BY user, application, device, decision_code
ORDER BY request_count DESC
LIMIT 50
'
# Create an alert policy for repeated access denials
gcloud alpha monitoring policies create \
--display-name="BeyondCorp Repeated Access Denials" \
--condition-display-name="High denial rate" \
--condition-filter='resource.type="iap_tunnel" AND jsonPayload.decision="DENY"' \
--condition-threshold-value=10 \
--condition-threshold-duration=300s \
--notification-channels=projects/PROJECT_ID/notificationChannels/CHANNEL_ID
Key Concepts
| Term | Definition |
|---|---|
| BeyondCorp | Google's zero trust security framework that shifts access controls from network perimeter to per-request identity and device verification |
| Identity-Aware Proxy (IAP) | Google Cloud service that intercepts HTTP requests and verifies user identity and device context before forwarding to backend applications |
| Access Context Manager | GCP service that defines fine-grained attribute-based access control policies using access levels and service perimeters |
| Endpoint Verification | Chrome Enterprise extension that collects device attributes (OS version, encryption, screen lock) for access level evaluation |
| Access Levels | Named conditions in Access Context Manager that define minimum requirements (device posture, IP range, geography) for resource access |
| Chrome Enterprise Premium | Google's commercial BeyondCorp offering providing threat protection, URL filtering, DLP, and continuous access evaluation |
Tools & Systems
- Google Cloud IAP: Identity-aware reverse proxy enforcing per-request authentication and authorization for GCP-hosted applications
- Access Context Manager: Policy engine defining access levels based on device attributes, IP ranges, and geographic locations
- Chrome Enterprise Premium: Extended BeyondCorp capabilities including real-time threat protection and data loss prevention
- Endpoint Verification: Device posture collection agent deployed as Chrome extension to all corporate endpoints
- BeyondCorp Enterprise Connectors: Secure tunnel connectors enabling IAP protection for on-premises applications
- Cloud Audit Logs: Immutable log records of all IAP access decisions for compliance and forensic analysis
Common Scenarios
Scenario: Migrating 50+ Internal Applications from VPN to BeyondCorp
Context: A technology company with 3,000 employees uses Cisco AnyConnect VPN for accessing internal applications. The VPN introduces latency, creates a single point of failure, and grants excessive network access after authentication.
Approach:
- Inventory all 50+ applications and categorize by hosting (GCP, on-prem, SaaS) and protocol (HTTPS, TCP, SSH)
- Deploy Endpoint Verification to all corporate devices and establish baseline device posture data over 2 weeks
- Create access levels in Access Context Manager: corporate-managed, contractor-device, high-trust
- Enable IAP on GCP-hosted HTTPS applications first (App Engine, Cloud Run, GKE services)
- Deploy BeyondCorp Enterprise connectors for on-premises applications
- Migrate users in 3 phases: IT/Engineering (week 1-2), General staff (week 3-4), Executives/Finance (week 5-6)
- Configure re-authentication policies: 8 hours for general apps, 1 hour for financial systems
- Set up BigQuery audit pipeline for continuous monitoring and anomaly detection
- Decommission VPN after 30-day parallel operation period
Pitfalls: Some legacy applications may not support HTTPS proxying and require TCP tunnel mode. Device enrollment takes time; plan a 2-week onboarding period before enforcing device posture requirements. Break-glass accounts with bypassed access levels must be created and tested for identity provider outages.
Output Format
BeyondCorp Zero Trust Implementation Report
==================================================
Organization: TechCorp Inc.
Implementation Date: 2026-02-23
Migration Phase: Phase 2 of 3
ACCESS ARCHITECTURE:
Identity Provider: Google Workspace
Access Proxy: Google Cloud IAP
Device Management: Chrome Enterprise + Endpoint Verification
Threat Protection: Chrome Enterprise Premium
On-Prem Connector: BeyondCorp Enterprise Connector (3 instances)
ACCESS LEVEL COVERAGE:
Access Level: corporate-managed
Devices enrolled: 2,847 / 3,000 (94.9%)
Compliant devices: 2,712 / 2,847 (95.3%)
Access Level: high-trust
Devices enrolled: 312 / 350 (89.1%)
Compliant devices: 298 / 312 (95.5%)
APPLICATION MIGRATION:
GCP HTTPS apps (IAP-protected): 32 / 35 (91.4%)
On-prem apps (via connector): 12 / 15 (80.0%)
SaaS apps (via SAML/OIDC): 8 / 8 (100%)
Total migrated: 52 / 58 (89.7%)
SECURITY METRICS (last 30 days):
Total access requests: 1,247,832
Denied by IAP policy: 3,412 (0.27%)
Denied by access level: 1,208 (0.10%)
Re-authentication triggered: 45,219
Anomalous access patterns: 12 (investigated)
VPN-related incidents (before): 8/month
BeyondCorp incidents (after): 1/month
VPN DECOMMISSION STATUS:
Parallel operation remaining: 14 days
Users still on VPN: 148 (5%)
Planned decommission: 2026-03-15
Other files in this skill
- LICENSE
- assets/template.md
- references/api-reference.md
- references/standards.md
- references/workflows.md
- scripts/agent.py
- scripts/process.py
assets/template.md (verbatim)
BeyondCorp Zero Trust Access - Migration Checklist
Project Information
| Field | Value |
|---|---|
| Organization | Acme Corporation |
| Project ID | acme-prod-beyondcorp |
| Lead Engineer | J. Smith, Security Architecture |
| Start Date | 2026-01-15 |
| Target Completion | 2026-04-15 |
Pre-Migration Checklist
Identity Provider Configuration
- Google Workspace or Cloud Identity configured as primary IdP
- MFA enforced for all users (FIDO2 security keys for privileged accounts)
- User groups defined and synchronized (engineering, finance, contractors, executives)
- Service accounts inventoried and mapped to applications
- Break-glass accounts created with documented access procedures
Google Cloud Infrastructure
- IAP API enabled on all production projects
- Access Context Manager API enabled at organization level
- BeyondCorp Enterprise API enabled
- Cloud Audit Logs enabled for IAP data access
- OAuth consent screen configured
- IAP OAuth clients created per application tier
Endpoint Verification
- Endpoint Verification extension deployed to Chrome managed browsers
- Device inventory populated (2,847 devices enrolled)
- Device compliance baseline established (target: 95%)
- Non-compliant device remediation plan documented
- BYOD enrollment policy defined
Access Level Design
| Access Level | Device Policy | Encryption | Screen Lock | Geo Restriction | Applications |
|---|---|---|---|---|---|
| basic-access | Any enrolled | Not required | Not required | None | Public wiki, cafeteria menu |
| standard-access | Enrolled + managed | Required | Required | US, GB, DE | Email, calendar, chat |
| enhanced-access | Managed + EDR | Required | Required | US, GB | Internal tools, CI/CD |
| high-trust | Managed + EDR + patched | Required | Required | US only | Finance, HR, admin panels |
Application Migration Tracker
| Application | Hosting | Protocol | Current Access | IAP Status | Access Level | Migration Date |
|---|---|---|---|---|---|---|
| Internal Wiki | App Engine | HTTPS | VPN | Enabled | basic-access | 2026-02-01 |
| CI/CD Dashboard | GKE | HTTPS | VPN | Enabled | enhanced-access | 2026-02-08 |
| HR Portal | On-prem | HTTPS | VPN | Connector deployed | high-trust | 2026-02-15 |
| Finance System | Compute Engine | HTTPS | VPN | Enabled | high-trust | 2026-02-22 |
| Git Repository | GKE | SSH+HTTPS | VPN | Enabled | enhanced-access | 2026-02-08 |
| Monitoring | Cloud Run | HTTPS | VPN | Enabled | standard-access | 2026-02-01 |
| Admin Console | On-prem | HTTPS | VPN | Connector pending | high-trust | 2026-03-01 |
Session Policy Configuration
| Application Tier | Session Duration | Re-auth Method | Re-auth Trigger |
|---|---|---|---|
| General (Tier 1) | 8 hours | LOGIN | Session expiry |
| Sensitive (Tier 2) | 4 hours | LOGIN | Session expiry, device change |
| Critical (Tier 3) | 1 hour | SECURE_KEY (FIDO2) | Session expiry, IP change |
| Admin (Tier 4) | 30 minutes | SECURE_KEY (FIDO2) | Any context change |
Post-Migration Validation
Functional Testing
- All migrated applications accessible through IAP without VPN
- Access denied for users not in authorized groups
- Access denied for non-compliant devices
- Re-authentication triggers working per policy
- Break-glass access procedure tested successfully
- On-premises connector failover tested
Security Testing
- Direct application access blocked (only through IAP)
- IAP bypass attempts detected and logged
- Session hijacking mitigations verified
- Cross-tenant access properly denied
- Audit logs capturing all access decisions
Monitoring
- BigQuery audit pipeline operational
- Alert policies configured for repeated denials
- Dashboard showing real-time access metrics
- Monthly access review process documented
VPN Decommission Timeline
| Phase | Date | Action | Status |
|---|---|---|---|
| Parallel Start | 2026-03-01 | VPN and BeyondCorp running side by side | Pending |
| VPN Monitoring | 2026-03-01 to 2026-03-15 | Track remaining VPN usage | Pending |
| VPN Block New | 2026-03-15 | Block new VPN connections | Pending |
| VPN Shutdown | 2026-04-01 | Decommission VPN infrastructure | Pending |
| Post-Mortem | 2026-04-15 | Migration lessons learned review | Pending |
Sign-Off
| Role | Name | Date | Signature |
|---|---|---|---|
| CISO | _________________ | __________ | __________ |
| Security Architect | _________________ | __________ | __________ |
| IT Operations Lead | _________________ | __________ | __________ |
| Application Owner | _________________ | __________ | __________ |
references/api-reference.md (verbatim)
API Reference: BeyondCorp Zero Trust Assessment Agent
Dependencies
| Library | Version | Purpose |
|---|---|---|
| requests | >=2.28 | HTTP client for Google Cloud IAP and Access Context Manager APIs |
CLI Usage
python scripts/agent.py \
--project my-gcp-project \
--output-dir /reports/ \
--output beyondcorp_report.json
Functions
get_gcloud_token() -> str
Runs gcloud auth print-access-token to obtain Bearer token.
list_iap_resources(project_id, token) -> list
GET IAP tunnel destination groups for the project.
get_iap_settings(project_id, resource, token) -> dict
GET IAP settings for a specific compute service resource.
list_access_levels(org_id, policy_name, token) -> list
GET /accessPolicies/{name}/accessLevels from Access Context Manager.
audit_iap_bindings(project_id, token) -> list
POST getIamPolicy and filters for IAP-related role bindings.
assess_zero_trust_posture(project_id, token) -> dict
Evaluates IAP coverage, binding security, checks for allUsers exposure.
generate_report(project_id, token) -> dict
Computes zero trust score (0-100) based on findings.
Google Cloud APIs Used
| API | Endpoint |
|---|---|
| IAP | iap.googleapis.com/v1/projects/{id}/iap_tunnel/... |
| Access Context Manager | accesscontextmanager.googleapis.com/v1/accessPolicies/... |
| Resource Manager | cloudresourcemanager.googleapis.com/v1/projects/{id}:getIamPolicy |
Output Schema
{
"project": "my-project",
"posture": {"iap_resources": 5, "findings": []},
"zero_trust_score": 85
}
references/standards.md (verbatim)
BeyondCorp Zero Trust Standards & References
NIST SP 800-207: Zero Trust Architecture
- Section 2: Zero Trust Tenets - defines the core principles BeyondCorp implements
- Section 3.1: Policy Engine (PE) and Policy Administrator (PA) - maps to IAP and Access Context Manager
- Section 3.2: Trust Algorithm - corresponds to Access Levels evaluation
- Section 4.1: Device Agent/Gateway-Based Deployment - matches BeyondCorp connector model
- URL: https://csrc.nist.gov/publications/detail/sp/800-207/final
CISA Zero Trust Maturity Model v2.0 (April 2023)
- Identity Pillar: MFA enforcement, continuous validation - maps to IAP re-authentication
- Device Pillar: Device health monitoring, compliance enforcement - maps to Endpoint Verification
- Network Pillar: Micro-segmentation, encrypted traffic - maps to IAP tunnel encryption
- Application Pillar: Application access authorization - maps to per-service IAP policies
- Data Pillar: Data access governance, DLP - maps to Chrome Enterprise Premium DLP
- URL: https://www.cisa.gov/zero-trust-maturity-model
Google BeyondCorp Papers
- BeyondCorp: A New Approach to Enterprise Security (2014)
- Describes the original BeyondCorp architecture eliminating the privileged intranet
- URL: https://research.google/pubs/pub43231/
- BeyondCorp: Design to Deployment at Google (2016)
- Details the migration strategy from VPN to BeyondCorp
- URL: https://research.google/pubs/pub44860/
- BeyondCorp: The Access Proxy (2017)
- Describes the access proxy component that became IAP
- URL: https://research.google/pubs/pub45728/
- Migrating to BeyondCorp (2018)
- Covers the phased migration approach and lessons learned
- URL: https://research.google/pubs/pub46134/
Google Cloud IAP Documentation
- IAP Overview: https://cloud.google.com/iap/docs/concepts-overview
- IAP for Compute Engine: https://cloud.google.com/iap/docs/enabling-compute-howto
- IAP for App Engine: https://cloud.google.com/iap/docs/app-engine-quickstart
- Access Context Manager: https://cloud.google.com/access-context-manager/docs
- Endpoint Verification: https://cloud.google.com/endpoint-verification/docs
- BeyondCorp Enterprise: https://cloud.google.com/beyondcorp-enterprise/docs
NIST SP 800-63-3: Digital Identity Guidelines
- Section 4: Defines identity assurance levels (IAL1-3) relevant to access level design
- URL: https://pages.nist.gov/800-63-3/
DoD Zero Trust Reference Architecture v2.0
- Section 3.4: Identity, Credential, and Access Management pillar
- Section 3.5: Device pillar - endpoint compliance requirements
- URL: https://dodcio.defense.gov/Portals/0/Documents/Library/ZTRAv2.0.pdf
references/workflows.md (verbatim)
BeyondCorp Zero Trust Implementation Workflow
Phase 1: Discovery and Planning (Weeks 1-2)
1.1 Application Inventory
- Enumerate all internal applications accessed via VPN or corporate network
- Classify each application by:
- Hosting environment: GCP (App Engine, GKE, Compute Engine, Cloud Run), on-premises, SaaS
- Protocol: HTTPS, TCP, SSH, RDP
- Authentication method: SAML, OIDC, Kerberos, LDAP, custom
- Sensitivity: Public, Internal, Confidential, Restricted
- Document current access patterns: which groups access which applications
- Identify applications that cannot be proxied (raw UDP, custom protocols)
1.2 Device Inventory
- Enumerate all corporate-managed and BYOD devices
- Document OS distribution: Windows, macOS, ChromeOS, Linux, iOS, Android
- Verify device management coverage: Intune, Jamf, Chrome Enterprise
- Identify gaps in device management enrollment
1.3 Access Level Design
- Define trust tiers based on organizational risk appetite:
- Tier 1 (Basic): Any authenticated user from any device
- Tier 2 (Standard): Authenticated user from enrolled device with screen lock
- Tier 3 (Enhanced): Authenticated user from compliant device with disk encryption
- Tier 4 (High): Authenticated user from managed device with EDR, specific geography
- Map applications to required trust tiers
- Define exception process for access level overrides
Phase 2: Infrastructure Setup (Weeks 3-4)
2.1 Google Cloud Configuration
- Enable required APIs: IAP, Access Context Manager, BeyondCorp Enterprise, Cloud Audit Logs
- Configure OAuth consent screen and IAP OAuth clients
- Set up IAP service accounts with minimal permissions
- Configure Cloud DNS for IAP-protected applications
2.2 Access Context Manager Setup
- Create access policy at the organization level
- Define access levels using basic conditions (device policy, IP ranges, regions)
- Define custom access levels using CEL expressions for complex conditions
- Test access levels with a pilot group before broad deployment
2.3 Endpoint Verification Deployment
- Deploy Endpoint Verification Chrome extension via Google Admin Console policy
- Configure extension settings: data collection scope, reporting frequency
- Allow 1-2 weeks for device inventory population
- Validate device attribute collection against access level requirements
Phase 3: Application Migration (Weeks 5-10)
3.1 GCP-Hosted HTTPS Applications
- Ensure applications are behind an HTTPS Load Balancer
- Enable IAP on each backend service
- Configure IAM bindings with access level conditions
- Test access with pilot users before expanding
- Monitor IAP access logs for false denials
3.2 On-Premises Applications
- Deploy BeyondCorp Enterprise connectors in on-premises DMZ
- Create app connections mapping external DNS to internal endpoints
- Configure IAP tunnels for TCP-based applications
- Validate network connectivity from connector to internal applications
- Test end-to-end access through IAP connector
3.3 SaaS Applications
- Configure SAML/OIDC federation from Google Workspace to SaaS apps
- Apply conditional access policies at the IdP level
- Enable session controls and re-authentication requirements
Phase 4: Policy Enforcement (Weeks 11-12)
4.1 Gradual Enforcement
- Start with audit-only mode: log but do not block non-compliant access
- Review audit logs to identify users/devices that would be blocked
- Communicate requirements and provide remediation guidance
- Enable enforcement in stages: Tier 2 first, then Tier 3, then Tier 4
4.2 Re-authentication Configuration
- Set session duration per application based on sensitivity:
- General applications: 8-hour session
- Sensitive applications: 4-hour session
- Critical applications: 1-hour session
- Configure re-authentication method: LOGIN (full re-auth) or SECURE_KEY (FIDO2 touch)
Phase 5: VPN Decommission (Weeks 13-16)
5.1 Parallel Operation
- Run VPN and BeyondCorp in parallel for 30 days
- Monitor VPN usage to identify remaining dependencies
- Migrate stragglers and address edge cases
- Document break-glass procedures for BeyondCorp failure scenarios
5.2 VPN Retirement
- Disable new VPN connections
- Notify all users of VPN decommission date
- Remove VPN client from managed devices
- Decommission VPN infrastructure
- Redirect VPN DNS entries to BeyondCorp access portal
Phase 6: Continuous Monitoring (Ongoing)
6.1 Access Analytics
- Build BigQuery dashboards for access pattern analysis
- Configure alerting for anomalous access patterns:
- Access from new geographies
- Access outside business hours
- Repeated authentication failures
- Device compliance changes
- Perform monthly access reviews of IAP bindings
6.2 Policy Optimization
- Review access level effectiveness quarterly
- Adjust device posture requirements based on threat landscape
- Update session duration policies based on incident trends
- Validate break-glass procedures monthly
Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.