How to Grant Console Access Without Syncing Identities?
Your organization шs using a third-party identity and authentication provider to centrally manage users. You want to use this identity provider to grant access to the Google Cloud console without syncing identities to Google Cloud. Users should receive permissions based on attributes. What should you do?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests your knowledge of Google Cloud’s Workforce Identity Federation versus identity synchronization, with the trap being solutions that require Cloud Identity sync or app-level proxies like IAP.
Workforce Identity Federation enables secure Google Cloud console access using external identity providers without syncing identities. This page confirms that attribute mapping via CEL is the correct configuration method.
Option B is frequently chosen because administrators often default to Cloud Identity directory sync, but it explicitly violates the requirement to avoid identity synchronization.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Workforce Identity Federation directly integrates external identity providers with Google IAM, allowing users to authenticate to the Google Cloud console without creating or syncing local identities. The service evaluates incoming OIDC tokens and uses Common Expression Language (CEL) to dynamically map external attributes to specific IAM roles. This architecture satisfies the requirement for zero identity synchronization while enabling precise, attribute-based authorization.Why the Other Options Are Wrong
Option B requires periodic synchronization of users and groups to Cloud Identity, which directly contradicts the explicit constraint of not syncing identities. Option C describes Google Cloud Identity Platform, which is designed primarily for authenticating end-users into custom web and mobile applications rather than granting administrative console access. Option D configures External Identities for Identity-Aware Proxy, which protects specific workloads behind a reverse proxy rather than managing broad IAM permissions for the Google Cloud console.Community Comment Notes
Several learners confirmed that Workforce Identity Federation eliminates the need for directory synchronization while maintaining full IAM control. As one commenter noted, "Workforce Identity Federation lets you use an external identity provider... so that the users can access Google Cloud services." Others simply agreed that option A aligns with the official documentation and best practices for workforce access models.Official Reference
Exam Strategy
Always scan for explicit constraints like 'without syncing identities' to immediately eliminate directory synchronization options. Match the access scope (console vs. application vs. proxy) to the correct Google Cloud security product before evaluating technical implementation details.
Frequently Asked Questions
Why not use Cloud Identity directory sync instead?
Directory sync creates local Google Cloud identities, violating the explicit requirement to avoid identity synchronization.
Can CEL be used for role assignment in Workforce Identity Federation?
Yes, CEL expressions evaluate incoming OIDC claims to dynamically assign IAM roles based on external attributes.