Migrate an on-prem corporate app to GCP with minimal user disruption and strict password storage rules. Which authentication approach should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Federate authentication via SAML 2.0 to the existing Identity Provider.
Why this is the answer
Federating authentication via SAML 2.0 to the existing Identity Provider (IdP) is the best approach because it allows users to continue using their existing corporate credentials without migrating password hashes or creating new passwords, ensuring minimal disruption and adhering to strict password storage rules. The IdP remains the authoritative source for authentication. G Suite Password Sync replicates password hashes, which might violate strict password storage rules. Provisioning users with Google Cloud Directory Sync creates user accounts but doesn't handle authentication itself; it still requires a separate authentication mechanism. Asking users to set matching passwords is insecure, prone to errors, and places the burden on the user.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed