Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is planning to migrate several core business applications to Google Cloud while maintaining its existing Microsoft Entra ID (formerly Azure Active Directory) as the authoritative identity provider (IdP).
The organization wants to implement automated user provisioning and Single Sign-On (SSO) with Cloud Identity to support centralized access control. The architecture must satisfy the following requirements:
Which identity federation strategy should the cloud architect implement?
Cloud Identity federation establishes a trust relationship between Google Cloud and an external Identity Provider (IdP) such as Microsoft Entra ID. By pairing automated directory synchronization with SAML 2.0 Single Sign-On (SSO), user identities and credentials remain centralized in Entra ID while granting access to Google Cloud resources.
user@example.com) on both the Google Cloud sign-in prompt and the Entra ID redirect screen.Mapping Entra ID UPNs configured with custom domain suffixes to Cloud Identity email addresses aligns the authentication identifier with the notification transport address, eliminating user confusion during identity-provider redirects.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.