Google Cloud Identity
Google Cloud Identity is a hosted directory for managing workforce users, groups, sign-in, applications, and devices. It gives an organization controlled identities for Google Cloud and other Google services without requiring every user to have Google Workspace productivity apps.
itCloud computing | OpenSkills.info
Course pathWalk it in order
Look it upDip in anytime
Go furtherLeaves this page
Intro
Google Cloud Identity
Cloud access begins with a person, not a permission.
Before Google Cloud can decide what someone may do, it needs an identity for that person. Cloud Identity provides a managed directory of workforce users and groups. It also provides controls for sign-in, applications, and endpoints.
That job is different from Google Cloud Identity and Access Management, usually called IAM. Cloud Identity answers, “Who is this user or group?” IAM answers, “What may this principal do on this resource?” You connect the two by granting IAM roles to users or groups from your Cloud Identity directory.
The core mental model
Treat Cloud Identity as the workforce identity layer around your Google services:
- A verified domain establishes the organization’s namespace.
- The Cloud Identity account contains managed users and groups for that domain.
- Google Sign-In authenticates those users, either directly or through an external identity provider.
- Google services recognize the resulting Google identities.
- Google Cloud IAM policies grant those identities access to resources.
A Cloud Identity account is a directory container. It is not one employee’s login. A user account inside that directory is the employee’s managed Google Account.
This distinction matters during planning. Your directory contains people and groups. Your Google Cloud organization contains folders, projects, and service resources. One Cloud Identity or Google Workspace account can be associated with one Google Cloud organization resource.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
Sources
- https://docs.cloud.google.com/identity/docs/overview
Supports
- Cloud Identity as an identity-as-a-service solution for centrally managing users and groups
- Federation with external identity providers
- Managed organizational accounts replacing uncontrolled personal accounts
- Relationship between Cloud Identity users and groups and Google Cloud IAM
- https://cloud.google.com/identity/
Supports
- Single sign-on, multi-factor authentication, endpoint management, and application integration capabilities
- Cloud Identity positioning across identity, access, application, and endpoint management
- https://docs.cloud.google.com/identity/docs/editions
Supports
- Free and Premium edition definitions
- Premium not being required to use Google Cloud
- Current feature boundaries for directory, endpoint, security, application integration, reporting, support, and licensing
- Cloud Identity Free serving users who do not need Google Workspace services such as Gmail and Google Calendar
- https://docs.cloud.google.com/architecture/identity/best-practices-for-planning
Supports
- Cloud Identity and Google Workspace accounts as containers for users and groups
- Organizations as containers for Google Cloud projects and resources
- Shared identity platform, APIs, and administrative tools between Cloud Identity and Google Workspace
- Cloud Identity as a subset of Google Workspace features for users, groups, and authentication
- https://docs.cloud.google.com/architecture/identity/overview-google-authentication
Supports
- Google Sign-In, managed users, groups, and organization-resource relationships
- External identity provider and external authoritative source definitions
- SAML federation prerequisites and corresponding user existence before first sign-in
- Provisioning and SSO identity mappings
- Groups as access-control principals
- https://docs.cloud.google.com/resource-manager/docs/cloud-platform-resource-hierarchy
Supports
- Cloud Identity or Google Workspace account prerequisite for an organization resource
- One account being associated with one organization resource
- Organization relationship to folders and projects
- Super administrator responsibility for domain ownership and assigning the Organization Administrator role
- https://docs.cloud.google.com/iam/docs/resource-hierarchy-access-control
Supports
- IAM policies and role inheritance across organization, folder, project, and resource levels
- Separation of principals from authorization policies
- https://docs.cloud.google.com/architecture/identity/reference-architectures
Supports
- Authoritative source and central identity provider as separate architecture decisions
- Google, external, and mixed identity architecture patterns
- https://docs.cloud.google.com/iam/docs/federated-identity-architectures
Supports
- Cloud Identity federation, sync-free Workforce Identity Federation, SCIM, and hybrid patterns
- Cloud Identity federation requiring users and groups to be provisioned before sign-in
- Workforce Identity Federation service-coverage and synchronization differences
- https://docs.cloud.google.com/architecture/identity/best-practices-for-federating
Supports
- External identity provider as source of truth
- Automated user provisioning and consistent primary-email identity mapping
- SAML single sign-on flow
- Multi-factor authentication and super-administrator safeguards
- https://docs.cloud.google.com/iam/docs/user-identities
Supports
- Cloud Identity federation requiring corresponding Google accounts
- Workforce Identity Federation providing sync-free, attribute-based access to IAM-supported services
- https://support.google.com/cloudidentity/answer/10344342?hl=en
Supports
- User and group synchronization from an external directory
- Organizational-unit mapping
- Safeguards and simulation
- External active state reactivating a Google-side suspended user on synchronization
- https://support.google.com/a/answer/9807615?hl=en
Supports
- Delegating specific administrator roles instead of full super-administrator access
- https://support.google.com/cloudidentity/?hl=en
Supports
- Current administrator task guidance for setup, users, groups, applications, security, devices, reports, and troubleshooting
