Google Associate Cloud EngineerConfiguring access and securityMedium

A large enterprise is migrating its on-premises user directory to Google Cloud Identity. They have an existing identity provider (IdP) that manages all employee identities. They want to enable their employees to access Google Cloud resources using their existing IdP credentials without synchronizing user accounts into Google Cloud. Which Google Cloud IAM feature should they implement?

  1. ACloud Identity Groups
  2. BDomain-wide Delegation
  3. CWorkforce Identity Federation
  4. DManaged Service for Microsoft Active Directory
Show answer & explanation

Correct answer: C. Workforce Identity Federation

Workforce Identity Federation allows external identity providers (like an on-premises IdP) to authenticate and authorize users to access Google Cloud resources without synchronizing user accounts to Google Cloud Directory. This is ideal for managing access for employees from existing IdPs.

Why the other options are wrong

  • A. Cloud Identity Groups are for managing groups within Google Cloud Identity, not for federating external IdPs.
  • B. Domain-wide Delegation is used for service accounts to impersonate users within a Google Workspace domain, not for federating external human identities.
  • D. Managed Service for Microsoft Active Directory provides a managed AD service on Google Cloud, which is not about federating an existing external IdP.

Workforce Identity Federation

Workforce Identity Federation enables employees and partners to access Google Cloud resources using their existing external identity provider (IdP) credentials.

  • Eliminates the need to synchronize user accounts into Google Cloud Directory.
  • Supports various IdPs (e.g., Okta, Azure AD, custom SAML/OIDC providers).
  • Simplifies identity management for large organizations with existing IdPs.

Memory trick: Federation means linking, not copying, identities.

More Configuring access and security questions