Professional Cloud Security EngineerConfiguring access within a cloud solution environmentMedium
A company is migrating its on-premises user directory to Google Cloud. They have a complex Active Directory (AD) structure with multiple organizational units (OUs) and security groups. They need to synchronize user identities and groups from their on-premises AD to Google Cloud Identity to manage access to Google Workspace and Google Cloud resources. The synchronization must be automated and maintain the existing group memberships. Which Google Cloud service should the security engineer configure to achieve this?
- AWorkforce Identity Federation
- BIdentity Platform
- CGoogle Cloud Directory Sync (GCDS)
- DCloud Identity-Aware Proxy (IAP)
Show answer & explanationAnswer & explanation
Correct answer: C. Google Cloud Directory Sync (GCDS)
Google Cloud Directory Sync (GCDS) is specifically designed to synchronize users, groups, and organizational structures from an on-premises Active Directory or LDAP server to Google Cloud Identity, which then integrates with Google Workspace and Cloud IAM. This automates the identity management process.
Why the other options are wrong
- A. Workforce Identity Federation allows employees to use an external IdP to access Google Cloud, but GCDS handles the initial directory synchronization.
- B. Identity Platform is a customer-facing identity and access management (CIAM) platform, not for syncing internal enterprise directories.
- D. IAP provides secure access to applications running on Google Cloud, not identity synchronization.
Google Cloud Directory Sync (GCDS)
A tool that synchronizes data from an on-premises directory server (like Active Directory or OpenLDAP) to Google Cloud Directory, enabling unified identity management.
- Synchronizes users, groups, and organizational units.
- Supports Active Directory and OpenLDAP.
- Automates identity provisioning for Google Workspace and Google Cloud.
Memory trick: GCDS bridges your old 'directory' to the 'cloud's' new 'sync'.