Google Associate Cloud EngineerConfiguring access and securityHard

A company is migrating an on-premises application to Google Cloud. The application uses a custom identity provider for user authentication. You need to configure IAM to allow users from this identity provider to access Google Cloud resources without manually creating Google accounts for each user. Which IAM feature should you implement?

  1. AManaged Service for Microsoft Active Directory
  2. BIdentity Platform
  3. CService Accounts
  4. DCloud Identity with Workforce Identity Federation
Show answer & explanation

Correct answer: D. Cloud Identity with Workforce Identity Federation

Workforce Identity Federation allows you to use an external identity provider (IdP) to authenticate and authorize users to access Google Cloud resources, without syncing user accounts to Cloud Identity or Google Directory. This is ideal for integrating custom or third-party IdPs.

Why the other options are wrong

  • A. Managed Service for Microsoft Active Directory is for extending Active Directory to Google Cloud, not for integrating a generic 'custom identity provider'.
  • B. Identity Platform (Firebase Authentication) is primarily for customer-facing applications (CIAM), not for workforce users with an existing external IdP.
  • C. Service Accounts are for applications and services, not for human users from external identity providers.

Workforce Identity Federation

A Google Cloud feature that enables users from external identity providers (IdPs) to access Google Cloud resources using their existing credentials, without requiring synchronization to Cloud Identity.

  • Supports SAML 2.0 and OIDC IdPs.
  • Eliminates the need for Google accounts for workforce users.
  • Manages access through attribute-based access control (ABAC).

Memory trick: Federate your workforce identities to connect to the cloud, without a Google account shroud.

More Configuring access and security questions