Disable and enable service accounts
Stay organized with collections
Save and categorize content based on your preferences.
This page explains how to disable and enable service accounts using the
Identity and Access Management (IAM) API, the Google Cloud console, and the
gcloud CLI.
Before you begin
Enable the IAM API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
C#
To use the .NET samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the C++ samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Go samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Java samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
To use the Python samples on this page in a local development environment, install and
initialize the gcloud CLI, and then set up Application Default Credentials with
your user credentials.
IAM basic roles also contain permissions to manage service
accounts.
You should not grant basic roles in a production environment, but you can grant them in a
development or test environment.
Disable a service account
Similar to deleting a service account, when you disable a service account,
applications will no longer have access to Google Cloud resources
through that service account. If you disable the default App Engine and
Compute Engine service accounts, the instances will no longer have
access to resources in the project. If you attempt to disable an already
disabled service account, it will have no effect.
Unlike deleting a service account, disabled service accounts can easily be
re-enabled as necessary. We recommend disabling a service account before
deleting it to make sure no critical applications are using the service account.
For more information, see Disable unused service
accounts before deleting them.
Console
In the Google Cloud console, go to the Service accounts page.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
usingSystem;usingGoogle.Apis.Auth.OAuth2;usingGoogle.Apis.Iam.v1;usingGoogle.Apis.Iam.v1.Data;publicpartialclassServiceAccounts{publicstaticvoidDisableServiceAccount(stringemail){varcredential=GoogleCredential.GetApplicationDefault().CreateScoped(IamService.Scope.CloudPlatform);varservice=newIamService(newIamService.Initializer{HttpClientInitializer=credential});varrequest=newDisableServiceAccountRequest();stringresource="projects/-/serviceAccounts/"+email;service.Projects.ServiceAccounts.Disable(request,resource).Execute();Console.WriteLine("Disabled service account: "+email);}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
import("context""fmt""io"iam"google.golang.org/api/iam/v1")// disableServiceAccount disables a service account.funcdisableServiceAccount(wio.Writer,emailstring)error{// email:= service-account@your-project.iam.gserviceaccount.comctx:=context.Background()service,err:=iam.NewService(ctx)iferr!=nil{returnfmt.Errorf("iam.NewService: %w",err)}request:=&iam.DisableServiceAccountRequest{}_,err=service.Projects.ServiceAccounts.Disable("projects/-/serviceAccounts/"+email,request).Do()iferr!=nil{returnfmt.Errorf("Projects.ServiceAccounts.Disable: %w",err)}fmt.Fprintf(w,"Disabled service account: %v",email)returnnil}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
importcom.google.cloud.iam.admin.v1.IAMClient;importcom.google.iam.admin.v1.DisableServiceAccountRequest;importjava.io.IOException;publicclassDisableServiceAccount{publicstaticvoidmain(String[]args)throwsIOException{// TODO(Developer): Replace the below variables before running.StringprojectId="your-project-id";StringserviceAccountName="your-service-account-name";disableServiceAccount(projectId,serviceAccountName);}// Disables a service account.publicstaticvoiddisableServiceAccount(StringprojectId,StringaccountName)throwsIOException{Stringemail=String.format("%s@%s.iam.gserviceaccount.com",accountName,projectId);// Initialize client that will be used to send requests.// This client only needs to be created once, and can be reused for multiple requests.try(IAMClientiamClient=IAMClient.create()){iamClient.disableServiceAccount(DisableServiceAccountRequest.newBuilder().setName(String.format("projects/%s/serviceAccounts/%s",projectId,email)).build());System.out.println("Disabled service account: "+accountName);}}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
importtimefromgoogle.cloudimportiam_admin_v1fromgoogle.cloud.iam_admin_v1importtypesdefdisable_service_account(project_id:str,account:str)-> types.ServiceAccount:"""Disables a service account. project_id: ID or number of the Google Cloud project you want to use. account: ID or email which is unique identifier of the service account. """iam_admin_client=iam_admin_v1.IAMClient()request=types.DisableServiceAccountRequest()name=f"projects/{project_id}/serviceAccounts/{account}"request.name=nameiam_admin_client.disable_service_account(request=request)time.sleep(5)# waiting to make sure changes appliedget_request=types.GetServiceAccountRequest()get_request.name=nameservice_account=iam_admin_client.get_service_account(request=get_request)ifservice_account.disabled:print(f"Disabled service account: {account}")returnservice_account
Before using any of the request data,
make the following replacements:
PROJECT_ID: Your Google Cloud project
ID. Project IDs are alphanumeric strings, like my-project.
SA_ID: The ID of your service account.
This can either be the service account's email address in the form
SA_NAME@PROJECT_ID.iam.gserviceaccount.com, or the service
account's unique numeric ID.
HTTP method and URL:
POST https://iam.googleapis.com/v1/projects/PROJECT_ID/serviceAccounts/SA_ID:disable
To send your request, expand one of these options:
Open the
method reference page.
The APIs Explorer panel opens on the right side of the page.
You can interact with this tool to send requests.
Complete any required fields and click Execute.
If successful, the response body will be empty.
Enable a service account
After enabling a disabled service account, applications will regain access to
Google Cloud resources through that service account.
You can enable a disabled service account whenever you need to. If you attempt
to enable an already enabled service account, it will have no effect.
Console
In the Google Cloud console, go to the Service accounts page.
At the bottom of the Google Cloud console, a
Cloud Shell
session starts and displays a command-line prompt. Cloud Shell is a shell environment
with the Google Cloud CLI
already installed and with values already set for
your current project. It can take a few seconds for the session to initialize.
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
usingSystem;usingGoogle.Apis.Auth.OAuth2;usingGoogle.Apis.Iam.v1;usingGoogle.Apis.Iam.v1.Data;publicpartialclassServiceAccounts{publicstaticvoidEnableServiceAccount(stringemail){varcredential=GoogleCredential.GetApplicationDefault().CreateScoped(IamService.Scope.CloudPlatform);varservice=newIamService(newIamService.Initializer{HttpClientInitializer=credential});varrequest=newEnableServiceAccountRequest();stringresource="projects/-/serviceAccounts/"+email;service.Projects.ServiceAccounts.Enable(request,resource).Execute();Console.WriteLine("Enabled service account: "+email);}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
import("context""fmt""io"iam"google.golang.org/api/iam/v1")// enableServiceAccount enables a service account.funcenableServiceAccount(wio.Writer,emailstring)error{// email:= service-account@your-project.iam.gserviceaccount.comctx:=context.Background()service,err:=iam.NewService(ctx)iferr!=nil{returnfmt.Errorf("iam.NewService: %w",err)}request:=&iam.EnableServiceAccountRequest{}_,err=service.Projects.ServiceAccounts.Enable("projects/-/serviceAccounts/"+email,request).Do()iferr!=nil{returnfmt.Errorf("Projects.ServiceAccounts.Enable: %w",err)}fmt.Fprintf(w,"Enabled service account: %v",email)returnnil}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
importcom.google.cloud.iam.admin.v1.IAMClient;importcom.google.iam.admin.v1.EnableServiceAccountRequest;importjava.io.IOException;publicclassEnableServiceAccount{publicstaticvoidmain(String[]args)throwsIOException{// TODO(Developer): Replace the below variables before running.StringprojectId="your-project-id";StringserviceAccountName="your-service-account-name";enableServiceAccount(projectId,serviceAccountName);}// Enables a service account.publicstaticvoidenableServiceAccount(StringprojectId,StringaccountName)throwsIOException{Stringemail=String.format("%s@%s.iam.gserviceaccount.com",accountName,projectId);// Initialize client that will be used to send requests.// This client only needs to be created once, and can be reused for multiple requests.try(IAMClientiamClient=IAMClient.create()){iamClient.enableServiceAccount(EnableServiceAccountRequest.newBuilder().setName(String.format("projects/%s/serviceAccounts/%s",projectId,email)).build());System.out.println("Enabled service account: "+email);}}}
To authenticate to IAM, set up Application Default Credentials.
For more information, see
Before you begin.
importtimefromgoogle.cloudimportiam_admin_v1fromgoogle.cloud.iam_admin_v1importtypesdefenable_service_account(project_id:str,account:str)-> types.ServiceAccount:"""Enables a service account. project_id: ID or number of the Google Cloud project you want to use. account: ID or email which is unique identifier of the service account. """iam_admin_client=iam_admin_v1.IAMClient()request=types.EnableServiceAccountRequest()name=f"projects/{project_id}/serviceAccounts/{account}"request.name=nameiam_admin_client.enable_service_account(request=request)time.sleep(5)# waiting to make sure changes appliedget_request=types.GetServiceAccountRequest()get_request.name=nameservice_account=iam_admin_client.get_service_account(request=get_request)ifnotservice_account.disabled:print(f"Enabled service account: {account}")returnservice_account
Before using any of the request data,
make the following replacements:
PROJECT_ID: Your Google Cloud project
ID. Project IDs are alphanumeric strings, like my-project.
SA_ID: The ID of your service account.
This can either be the service account's email address in the form
SA_NAME@PROJECT_ID.iam.gserviceaccount.com, or the service
account's unique numeric ID.
HTTP method and URL:
POST https://iam.googleapis.com/v1/projects/PROJECT_ID/serviceAccounts/SA_ID:enable
To send your request, expand one of these options:
Open the
method reference page.
The APIs Explorer panel opens on the right side of the page.
You can interact with this tool to send requests.
Complete any required fields and click Execute.
If you're new to Google Cloud, create an account to evaluate how our
products perform in real-world scenarios. New customers also get $300 in
free credits to run, test, and deploy workloads.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2026-09-30 UTC."],[],[]]