Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy
A global enterprise is integrating its on-premises Active Directory with Google Cloud. They have a complex organizational unit (OU) structure and need to ensure that user and group synchronization is highly configurable, allowing for specific OUs to be included or excluded, and attributes to be mapped flexibly. Which Google Cloud service should they use for this integration?
- AWorkforce Identity Federation
- BGoogle Cloud Directory Sync (GCDS)
- CCloud Identity Free Edition
- DManaged Service for Microsoft Active Directory
Show answer & explanationAnswer & explanation
Correct answer: B. Google Cloud Directory Sync (GCDS)
Google Cloud Directory Sync (GCDS) is specifically designed for synchronizing users, groups, and organizational units from an on-premises Active Directory or LDAP server to Google Cloud Identity. It offers extensive configuration options for filtering and attribute mapping.
Why the other options are wrong
- A. Workforce Identity Federation is for federating external identity providers (like AD FS, Okta) for single sign-on, not for synchronizing users and groups into Cloud Identity.
- C. Cloud Identity Free Edition is a user and group management service, but it doesn't provide the synchronization engine for on-premises AD with granular OU and attribute mapping capabilities.
- D. Managed Service for Microsoft Active Directory provides a managed AD service on Google Cloud, but it doesn't synchronize an existing on-premises AD to Cloud Identity; it's a new AD instance.
Google Cloud Directory Sync (GCDS)
GCDS is a free tool that synchronizes users, groups, and organizational structures from an existing LDAP directory (like Active Directory) to Google Cloud Identity.
- Connects on-premises LDAP to Cloud Identity.
- Allows granular filtering of OUs and attributes.
- Supports scheduled synchronization.
Memory trick: GCDS syncs your old AD to the new cloud.