How to Manage Temporary Partner Access on Google Cloud?

Identity & Access Management (IAM)
Answer Correct answer: B — Create a workforce identity pool and federate it with the partner team’s identity provider to enable automatic access revocation.

Your organization has hired a small, temporary partner team for 18 months. The temporary team will work alongside your DevOps team to develop your organization's application that is hosted on Google Cloud. You must give the temporary partner team access to your application's resources on Google Cloud and ensure that partner employees lose access. If they are removed from their employer's organization. What should you do?

  1. Create a temporary username and password for the temporary partner team members. Auto-clean the usernames and passwords after the work engagement has ended.
  2. Create a workforce identity pool and federate the identity pool with the identity provider (IdP) of the temporary partner team. Correct Answer
  3. Implement just-in-time privileged access to Google Cloud for the temporary partner team.
  4. Add the identities of the temporary partner team members to your identity provider (IdP).

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests external identity delegation by highlighting that federated workforce pools eliminate manual deprovisioning risks when temporary staff leave their employer.

This scenario evaluates workforce identity federation for external contractors on Google Cloud, confirming that linking a partner’s IdP guarantees automatic access revocation when employees depart.

Candidates frequently select Option D, assuming native IdP integration offers tighter control, but it requires manual offboarding and delays access termination.

Community Discussion (3 comments)

Pime13 👍 1 Selected: B
b: https://cloud.google.com/iam/docs/workforce-identity-federation https://cloud.google.com/iam/docs/temporary-elevated-access One way to protect sensitive resources is to limit access to them. However, limiting access to sensitive resources also creates friction for anyone who occasionally needs to access those resources. For example, a user might need break-glass, or emergency, access to sensitive resources to resolve an incident. In these situations, we recommend giving the user permission to access the resource temporarily. We also recommend that, to improve auditing, you record the user's justification for accessing the resource.
MoAk 👍 1 Selected: B
Answer is B
yokoyan 👍 4
I think it's B.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Workforce identity federation is explicitly designed for external users like contractors and partners who need secure, time-bound access to cloud resources. By creating an identity pool and federating it with the partner’s existing IdP, Google Cloud delegates authentication entirely to the vendor’s system. When a contractor leaves their employer, their credentials become invalid at the source IdP, instantly cutting off all GCP access without any administrative intervention. This aligns perfectly with the requirement for automatic revocation.

Why the Other Options Are Wrong

Option A relies on static credentials that are insecure and impossible to automatically sync with an external company’s HR system. Option C describes just-in-time access, which is intended for short-term privilege escalation for internal staff rather than sustained project collaboration. Option D suggests migrating external identities into your internal IdP, which creates orphaned accounts that persist until manually deleted, violating the automatic removal requirement.

Community Comment Notes

The community consensus strongly favors this approach, with multiple learners confirming the solution points directly to official Google documentation. As noted by several contributors, workforce identity federation is the standard pattern for managing third-party access in cloud environments. Participants also highlighted that this method eliminates password fatigue while maintaining strict compliance boundaries between organizations.

Official Reference

Exam Strategy

When dealing with external teams or contractors, always look for federation-based solutions that delegate authentication to the partner’s IdP. Avoid manual account creation or long-lived credentials, as they introduce compliance risks and increase administrative overhead during offboarding.

Frequently Asked Questions

Why can't I just add partner users to my internal IdP?

Adding external users to your IdP creates permanent accounts that require manual deletion. Federation delegates authentication to their IdP, enabling instant automatic revocation.

Is JIT access suitable for an 18-month contract?

No. JIT is designed for short-term privilege escalation for internal staff. Workforce federation supports sustained, policy-driven access for long-term external collaborations.

Related Analysis

← Back to PCSE Study Guide