Google Cloud Identity
Google Cloud Identity is a hosted directory for managing workforce users, groups, sign-in, applications, and devices. It gives an organization controlled identities for Google Cloud and other Google services without requiring every user to have Google Workspace productivity apps.
itCloud computing | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Don't Panic
Don't Panic: Google Cloud Identity
Cloud Identity is Google's managed directory for workforce users, groups, sign-in settings, applications, and endpoints. It exists because work access should not depend on whichever personal Google Account happened to be used first. The name sounds like somebody's login wearing a ceremonial hat. It is actually the organization's container for identities.
The useful arrangement has three parts. Directory says which people and groups exist. Authentication proves that a person has arrived. Authorization decides what that identity may do. Cloud Identity handles the directory and much of sign-in. Google Cloud IAM handles resource permissions. Creating a user is therefore not a key to a project. It is a name on the guest list, which is a much less exciting object than people tend to assume.
Federation lets an external identity provider authenticate the user, but it does not make the Google directory vanish in a puff of enterprise architecture. Cloud Identity federation still needs a corresponding Google user before the first single sign-on attempt. Provisioning creates that user and group record. Single sign-on performs authentication. Both flows must agree on the same primary email address, or a perfectly valid sign-in arrives looking for someone else.
Groups are the quiet machinery that keeps access from becoming a spreadsheet with better branding. Put a person in the team group, grant the group an IAM role, and let the Google resource hierarchy apply that role where it belongs. When work changes, group membership changes. Direct grants to individual users are reserved for exceptions, because exceptions are where future administrators discover archaeology.
The sharp edges are lifecycle edges. A suspended user can return after synchronization if the authoritative source still says active. An external identity-provider outage can also leave administrators needing a recovery path. Test joiners, movers, leavers, renamed users, factor recovery, and emergency administration. A successful sign-in proves only that the front door opened.
Read the Intro for the full architecture and the boundaries between Cloud Identity, IAM, Google Workspace, Identity Platform, and Workforce Identity Federation. Use Slides for the identity chain and design choices. Keep the Cheatsheet nearby when comparing federation patterns, editions, lifecycle tests, and failure signals. The Reference tab leads from Google's overview to planning, federation, and administrator guidance.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://docs.cloud.google.com/identity/docs/overview
Supports
- Cloud Identity as an identity-as-a-service solution for centrally managing users and groups
- Federation with external identity providers
- Managed organizational accounts replacing uncontrolled personal accounts
- Relationship between Cloud Identity users and groups and Google Cloud IAM
- https://cloud.google.com/identity/
Supports
- Single sign-on, multi-factor authentication, endpoint management, and application integration capabilities
- Cloud Identity positioning across identity, access, application, and endpoint management
- https://docs.cloud.google.com/identity/docs/editions
Supports
- Free and Premium edition definitions
- Premium not being required to use Google Cloud
- Current feature boundaries for directory, endpoint, security, application integration, reporting, support, and licensing
- Cloud Identity Free serving users who do not need Google Workspace services such as Gmail and Google Calendar
- https://docs.cloud.google.com/architecture/identity/best-practices-for-planning
Supports
- Cloud Identity and Google Workspace accounts as containers for users and groups
- Organizations as containers for Google Cloud projects and resources
- Shared identity platform, APIs, and administrative tools between Cloud Identity and Google Workspace
- Cloud Identity as a subset of Google Workspace features for users, groups, and authentication
- https://docs.cloud.google.com/architecture/identity/overview-google-authentication
Supports
- Google Sign-In, managed users, groups, and organization-resource relationships
- External identity provider and external authoritative source definitions
- SAML federation prerequisites and corresponding user existence before first sign-in
- Provisioning and SSO identity mappings
- Groups as access-control principals
- https://docs.cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy
Supports
- Cloud Identity or Google Workspace account prerequisite for an organization resource
- One account being associated with one organization resource
- Organization relationship to folders and projects
- Super administrator responsibility for domain ownership and assigning the Organization Administrator role
- https://docs.cloud.google.com/iam/docs/resource-hierarchy-access-control
Supports
- IAM policies and role inheritance across organization, folder, project, and resource levels
- Separation of principals from authorization policies
- https://docs.cloud.google.com/architecture/identity/reference-architectures
Supports
- Authoritative source and central identity provider as separate architecture decisions
- Google, external, and mixed identity architecture patterns
- https://docs.cloud.google.com/iam/docs/federated-identity-architectures
Supports
- Cloud Identity federation, sync-free Workforce Identity Federation, SCIM, and hybrid patterns
- Cloud Identity federation requiring users and groups to be provisioned before sign-in
- Workforce Identity Federation service-coverage and synchronization differences
- https://docs.cloud.google.com/architecture/identity/best-practices-for-federating
Supports
- External identity provider as source of truth
- Automated user provisioning and consistent primary-email identity mapping
- SAML single sign-on flow
- Multi-factor authentication and super-administrator safeguards
- https://docs.cloud.google.com/iam/docs/user-identities
Supports
- Cloud Identity federation requiring corresponding Google accounts
- Workforce Identity Federation providing sync-free, attribute-based access to IAM-supported services
- https://support.google.com/cloudidentity/answer/10344342?hl=en
Supports
- User and group synchronization from an external directory
- Organizational-unit mapping
- Safeguards and simulation
- External active state reactivating a Google-side suspended user on synchronization
- https://support.google.com/a/answer/9807615?hl=en
Supports
- Delegating specific administrator roles instead of full super-administrator access
- https://support.google.com/cloudidentity/?hl=en
Supports
- Current administrator task guidance for setup, users, groups, applications, security, devices, reports, and troubleshooting
- https://learn.microsoft.com/en-us/azure/cost-management-billing/manage/microsoft-entra-id-free
Supports
- Microsoft Entra ID Free user and group management, directory synchronization, and single sign-on capabilities
- Microsoft Entra ID Free availability without a separate charge
- https://www.okta.com/products/workforce-identity/
Supports
- Okta Workforce Identity features for workforce single sign-on, multi-factor authentication, lifecycle management, governance, and directory management
- https://www.pingidentity.com/en/platform/pingone-for-workforce.html
Supports
- PingOne for Workforce as a centralized workforce authentication and access service for applications, directories, and devices
- https://jumpcloud.com/platform
Supports
- JumpCloud cloud directory capabilities across identity, access, and device management
- https://www.onelogin.com/solutions/workforce-iam
Supports
- OneLogin workforce identity features for cloud directory, single sign-on, multi-factor authentication, and lifecycle management
- https://www.ibm.com/products/verify-workforce-identity
Supports
- IBM Verify Workforce Identity features for workforce access, multi-factor authentication, adaptive access, single sign-on, and lifecycle management
- https://www.keycloak.org/
Supports
- Keycloak as open-source identity and access management software with single sign-on, identity brokering, and SAML and OpenID Connect support
- https://workspace.google.com/
Supports
- Google Workspace product positioning as Google collaboration and productivity services
