To limit access for users within a project or organization, you can use Identity and Access Management (IAM) roles for Database Migration Service and your relevant destination database product. You can control access to Database Migration Service-related resources, as opposed to granting users the Viewer, Editor, or Owner role to the entire Google Cloud project.
This page focuses details all of the roles that user and service accounts need during a homogeneous Cloud SQL migration with Database Migration Service. For more information about when you use these permissions during the migration process, see Migrate your SQL Server databases to Cloud SQL for SQL Server.
Accounts involved in performing migration jobs
There are three accounts involved in data migrations performed with Database Migration Service:
- User account that performs the migration
- This is the Google Account that you sign in with to create the connection profiles, upload the backup files to the Cloud Storage storage, create and run the migration job.
- Database Migration Service service account
- This is the service account that is created for you when you enable the Database Migration Service API. The email address associated with this account is generated automatically and can't be changed. This email address uses the following format: