Today, we are announcing a new cloud security capability called context-based restrictions.

Context-based restrictions give account owners and administrators the ability to define and enforce access restrictions for IBM Cloud® resources based on the context of the access request, such as network attributes.

These restrictions work with traditional IAM policies (which are based on identity) to provide an extra layer of protection. Since both IAM access and context-based restrictions define access, context-based restrictions offer protection even in the face of compromised or mismanaged credentials.

How do context-based restrictions work?

An account administrator manages context-based restrictions via rules. A context-based restrictions rule associates an IBM Cloud resource with one or more contexts, where each context describes a set of conditions that an access request must satisfy in order for that access to be permitted.

Today, a context can describe conditions based on any combination of the following:

  • The client IP from which the request originated.
  • The service endpoint type on which the request was received (e.g., public vs private).

Note that the concept of contexts is defined to be extensible and allows for future support of additional conditions.

Start using context-based restrictions

Strengthen your security strategy by applying context-based restrictions to your resources. To learn how to restrict account management service requests to the contexts you define, complete this tutorial

Today, you can create context-based restrictions for the following services:

  • IAM Users
  • IAM Groups
  • IAM Access Policy Management
  • IAM Custom roles

Support for additional services will be added in the future.

You can create context-based restrictions with your method of choice: 

To learn more, see What are context-based restrictions?

Categories

More from Announcements

IBM TechXchange underscores the importance of AI skilling and partner innovation

3 min read - Generative AI and large language models are poised to impact how we all access and use information. But as organizations race to adopt these new technologies for business, it requires a global ecosystem of partners with industry expertise to identify the right enterprise use-cases for AI and the technical skills to implement the technology. During TechXchange, IBM's premier technical learning event in Las Vegas last week, IBM Partner Plus members including our Strategic Partners, resellers, software vendors, distributors and service…

Introducing Inspiring Voices, a podcast exploring the impactful journeys of great leaders

< 1 min read - Learning about other people's careers, life challenges, and successes is a true source of inspiration that can impact our own ambitions as well as life and business choices in great ways. Brought to you by the Executive Search and Integration team at IBM, the Inspiring Voices podcast will showcase great leaders, taking you inside their personal stories about life, career choices and how to make an impact. In this first episode, host David Jones, Executive Search Lead at IBM, brings…

IBM watsonx Assistant and NICE CXone combine capabilities for a new chapter in CCaaS

5 min read - In an age of instant everything, ensuring a positive customer experience has become a top priority for enterprises. When one third of customers (32%) say they will walk away from a brand they love after just one bad experience (source: PWC), organizations are now applying massive investments to this experience, particularly with their live agents and contact centers.  For many enterprises, that investment includes modernizing their call centers by moving to cloud-based Contact Center as a Service (CCaaS) platforms. CCaaS solutions…

See what’s new in SingleStoreDB with IBM 8.0

3 min read - Despite decades of progress in database systems, builders have compromised on at least one of the following: speed, reliability, or ease. They have two options: one, they could get a document database that is fast and easy, but can’t be relied on for mission-critical transactional applications. Or two, they could rely on a cloud data warehouse that is easy to set up, but only allows lagging analytics. Even then, each solution lacks something, forcing builders to deploy other databases for…