Google Cloud Identity
Google Cloud Identity is a hosted directory for managing workforce users, groups, sign-in, applications, and devices. It gives an organization controlled identities for Google Cloud and other Google services without requiring every user to have Google Workspace productivity apps.
itCloud computing | OpenSkills.info
Intro
Google Cloud Identity
Cloud access begins with a person, not a permission.
Before Google Cloud can decide what someone may do, it needs an identity for that person. Cloud Identity provides a managed directory of workforce users and groups. It also provides controls for sign-in, applications, and endpoints.
That job is different from Google Cloud Identity and Access Management, usually called IAM. Cloud Identity answers, “Who is this user or group?” IAM answers, “What may this principal do on this resource?” You connect the two by granting IAM roles to users or groups from your Cloud Identity directory.
The core mental model
Treat Cloud Identity as the workforce identity layer around your Google services:
- A verified domain establishes the organization’s namespace.
- The Cloud Identity account contains managed users and groups for that domain.
- Google Sign-In authenticates those users, either directly or through an external identity provider.
- Google services recognize the resulting Google identities.
- Google Cloud IAM policies grant those identities access to resources.
A Cloud Identity account is a directory container. It is not one employee’s login. A user account inside that directory is the employee’s managed Google Account.
This distinction matters during planning. Your directory contains people and groups. Your Google Cloud organization contains folders, projects, and service resources. One Cloud Identity or Google Workspace account can be associated with one Google Cloud organization resource.
Continue the course
This section is part of the paid course.
See pricing to subscribe, or log in if you already have access.
Where this skill leads
Relevant careers
See how this topic contributes to broader role-level skill maps.
