Your org uses an external IdP for users and groups. You want employees to sign into the Google Cloud console using that IdP and show each user's name and photo at sign-in. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure Workforce Identity Federation with the external IdP and map attributes (name, photo)..
Why this is the answer
Workforce Identity Federation is designed for exactly this scenario: allowing external identities (from your IdP) to access Google Cloud resources, including the console. It supports attribute mapping, which lets you transfer user details like name and photo from your IdP to Google Cloud, ensuring they display correctly at sign-in. Creating service accounts per user is an overly complex and insecure workaround not intended for user sign-in. Workload Identity Federation is for workloads (like VMs or GKE pods) accessing Google Cloud, not human users. Creating a Google Group with all emails doesn't integrate with an external IdP for sign-in and doesn't provide attribute mapping for name and photo display.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed