How to Grant Console Access Without Syncing Identities?

Identity & Access Management
Answer Correct answer: A — Configure the central identity provider as a workforce identity pool provider in Workforce Identity Federation and map attributes using CEL.

Your organization шs using a third-party identity and authentication provider to centrally manage users. You want to use this identity provider to grant access to the Google Cloud console without syncing identities to Google Cloud. Users should receive permissions based on attributes. What should you do?

  1. Configure the central identity provider as a workforce identity pool provider in Workforce Identity Federation. Create an attribute mapping by using the Common Expression Language (CEL). Correct Answer
  2. Configure a periodic synchronization of relevant users and groups with attributes to Cloud Identity. Activate single sign-on by using the Security Assertion Markup Language (SAML).
  3. Set up the Google Cloud Identity Platform. Configure an external authentication provider by using OpenID Connect and link user accounts based on attributes.
  4. Activate external identities on the Identity-Aware Proxy. Use the Security Assertion Markup Language (SAML) to configure authentication based on attributes to the central authentication provider.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests your knowledge of Google Cloud’s Workforce Identity Federation versus identity synchronization, with the trap being solutions that require Cloud Identity sync or app-level proxies like IAP.

Workforce Identity Federation enables secure Google Cloud console access using external identity providers without syncing identities. This page confirms that attribute mapping via CEL is the correct configuration method.

Option B is frequently chosen because administrators often default to Cloud Identity directory sync, but it explicitly violates the requirement to avoid identity synchronization.

Community Discussion (4 comments)

Pime13 👍 1 Selected: A
https://cloud.google.com/iam/docs/workforce-identity-federation Workforce Identity Federation lets you use an external identity provider (IdP) to authenticate and authorize a workforce—a group of users, such as employees, partners, and contractors—using IAM, so that the users can access Google Cloud services. With Workforce Identity Federation you don't need to synchronize user identities from your existing IdP to Google Cloud identities, as you would with Cloud Identity's Google Cloud Directory Sync (GCDS). Workforce Identity Federation extends Google Cloud's identity capabilities to support syncless, attribute-based single sign on.
MoAk 👍 1 Selected: A
A is good.
3fd692e 👍 1 Selected: A
Clearly A.
yokoyan 👍 4 Selected: A
I think it's A.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Workforce Identity Federation directly integrates external identity providers with Google IAM, allowing users to authenticate to the Google Cloud console without creating or syncing local identities. The service evaluates incoming OIDC tokens and uses Common Expression Language (CEL) to dynamically map external attributes to specific IAM roles. This architecture satisfies the requirement for zero identity synchronization while enabling precise, attribute-based authorization.

Why the Other Options Are Wrong

Option B requires periodic synchronization of users and groups to Cloud Identity, which directly contradicts the explicit constraint of not syncing identities. Option C describes Google Cloud Identity Platform, which is designed primarily for authenticating end-users into custom web and mobile applications rather than granting administrative console access. Option D configures External Identities for Identity-Aware Proxy, which protects specific workloads behind a reverse proxy rather than managing broad IAM permissions for the Google Cloud console.

Community Comment Notes

Several learners confirmed that Workforce Identity Federation eliminates the need for directory synchronization while maintaining full IAM control. As one commenter noted, "Workforce Identity Federation lets you use an external identity provider... so that the users can access Google Cloud services." Others simply agreed that option A aligns with the official documentation and best practices for workforce access models.

Official Reference

Exam Strategy

Always scan for explicit constraints like 'without syncing identities' to immediately eliminate directory synchronization options. Match the access scope (console vs. application vs. proxy) to the correct Google Cloud security product before evaluating technical implementation details.

Frequently Asked Questions

Why not use Cloud Identity directory sync instead?

Directory sync creates local Google Cloud identities, violating the explicit requirement to avoid identity synchronization.

Can CEL be used for role assignment in Workforce Identity Federation?

Yes, CEL expressions evaluate incoming OIDC claims to dynamically assign IAM roles based on external attributes.

Related Analysis

← Back to PCSE Study Guide