Cloud Identity-Aware Proxy (IAP)
Cloud Identity-Aware Proxy or Cloud IAP is one of the platforms that can be used to deploy BeyondCorp to business infrastructure. While Cloud Identity does support BeyondCorp as well, Cloud IAP is built with the Zero Trust model and is a service designed specifically for securing user connections without creating a virtual private network (VPN).
IAP works by eliminating the need for a network-level firewall by substituting network access controls for application-level access controls. This is done through an authorization layer for applications accessed by HTTPS. IAP extends Cloud IAM functionality by ensuring that resources can only be accessed by members with the correct roles. This is where the term proxy comes in. The users aren't accessing the roles directly; they are given the role of an authorized user through IAM, thus giving access to only secure users without the need for a VPN.