Keep on-premises Active Directory as the identity source while adopting Google Cloud. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Use Google Cloud Directory Sync to synchronize AD accounts to cloud identities and configure SAML SSO..
Why this is the answer
To maintain on-premises Active Directory as the identity source for Google Cloud, you should use Google Cloud Directory Sync (GCDS). GCDS synchronizes user accounts and groups from your Active Directory to Cloud Identity (or Google Workspace), creating corresponding cloud identities. This allows users to sign in to Google Cloud services with their existing AD credentials. Subsequently, configuring SAML Single Sign-On (SSO) between Cloud Identity and your on-premises AD federation service (e.g., ADFS) enables a seamless authentication experience, where users are redirected to your AD for authentication. Authenticating directly to AD using the Admin Directory API is not a standard or secure method for user authentication to Google Cloud services. Cloud Identity-Aware Proxy (IAP) provides access control to applications based on identity, but it doesn't directly synchronize identities from on-premises AD or act as an identity provider in this context. Creating a Compute Engine AD replica is for extending your AD domain to Google Cloud for domain-joined VMs, not for synchronizing identities for Google Cloud services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed