Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy

A security architect is designing a new application on Google Cloud that requires users to authenticate using their existing corporate Active Directory credentials without synchronizing user data to Google Cloud Identity. The solution must support multi-factor authentication (MFA) provided by the corporate identity provider and allow for fine-grained authorization within Google Cloud. Which Google Cloud service should the architect recommend to achieve this?

  1. AWorkforce Identity Federation
  2. BGoogle Cloud Directory Sync (GCDS)
  3. CCloud Identity Free
  4. DIdentity Platform
Show answer & explanation

Correct answer: A. Workforce Identity Federation

Workforce Identity Federation allows employees to access Google Cloud resources using their existing external identity provider (IdP) credentials, such as Active Directory, without synchronizing user data to Google Cloud. It supports MFA provided by the IdP and integrates with IAM for fine-grained authorization.

Why the other options are wrong

  • B. GCDS synchronizes user data from Active Directory to Cloud Identity, which is explicitly not desired here.
  • C. Cloud Identity Free provides basic user management within Google Cloud but does not offer direct federation with external corporate IdPs for this use case.
  • D. Identity Platform is primarily for customer-facing applications and manages identities within Google Cloud, not federating external corporate identities for internal access.

Workforce Identity Federation

A Google Cloud service that allows employees to use their existing external identity provider (IdP) to access Google Cloud resources, without synchronizing user data to Google Cloud.

  • Connects external IdPs (e.g., Okta, Azure AD, Active Directory) to Google Cloud.
  • Users authenticate with their IdP, then obtain temporary Google Cloud credentials.
  • Ideal for managing employee access to Google Cloud without direct user synchronization.

Memory trick: Federation Fuses Firms' Identities.

More Configuring access within a cloud solution environment questions