A company wants to use its existing Active Directory credentials to authenticate users to the GCP Console. Which service should they integrate with?
Trap 1: Identity-Aware Proxy
IAP provides zero-trust access to apps, not federated authentication to GCP Console.
Trap 2: Cloud KMS
Cloud KMS manages encryption keys, not identity federation.
Trap 3: Cloud Directory Sync
Cloud Directory Sync synchronizes users from AD to Cloud Identity, but does not authenticate with AD credentials directly.
- A
Identity-Aware Proxy
Why it fails: IAP provides zero-trust access to apps, not federated authentication to GCP Console.
- B
Cloud Identity with SAML SSO
Cloud Identity with SAML SSO federates the existing Active Directory identity provider, letting users authenticate to the GCP Console with current credentials. This satisfies the constraint of reusing Active Directory without provisioning separate Google accounts.
- C
Cloud KMS
Why it fails: Cloud KMS manages encryption keys, not identity federation.
- D
Cloud Directory Sync
Why it fails: Cloud Directory Sync synchronizes users from AD to Cloud Identity, but does not authenticate with AD credentials directly.