Jump to
Cloud Identity

Cloud Identity

The native directory, security, and device management foundation for Google Cloud’s Unified Identity platform.

Try it free
Try Cloud Identity Premium
  • Secure employee access to Google Cloud, Google Workspace, and thousands of pre-integrated SaaS applications.

  • Defend against credential theft with phishing-resistant MFA and mandatory step-up re-authentication for sensitive console actions.

  • Enforce unified endpoint management and device policies across Windows, macOS, iOS, and Android devices.

Benefits

Choose the identity model that fits your organization

Google Cloud Unified Identity meets your enterprise where it is today. Easily secure native users, federate your existing human identity providers, or establish keyless access for machines and AI agents.

Cloud Identity

Native employee and device directory

Centrally manage local users, groups, and device policies (EMM) built into Google Cloud. Features continuous session security, advanced endpoint verification, and native console re-authentication.

Workforce Identity Federation

Federated human identity

Let employees and partners sign in using external IdPs like Okta or Microsoft Entra ID. Workforce Identity Federation simplifies account sync overhead while supporting both cloud-first and on-premises AD setups.

Workload Identity Federation

Keyless machine and AI identity

Securely connect programmatic workloads, CI/CD pipelines, and emerging AI agents to Google Cloud without service account keys, using short-lived federated credentials (OIDC/SAML/SPIFFE) with Workload Identity Federation.

Key features

Modernize IT and strengthen security

Advanced administrative and security capabilities

Phishing-resistant MFA and session guardrails

Enforce hardware-backed Titan Security Keys and software-based passkeys to eliminate credential theft. Deploy the Google Credential Provider for Windows (GCPW) to secure physical machine logins with FIDO2-compliant keys, and protect privileged browser sessions using mandatory step-up re-authentication.

Endpoint management

Gather deep inventory and security posture metadata across Android, iOS, Windows, and macOS fleets. Use Endpoint Verification to check encryption status, OS versions, and screen-lock compliance, allowing you to enforce granular, context-aware access policies without intrusive agents.

SAML 2.0/OIDC SSO and inbound SCIM provisioning

Enable federated single sign-on (SSO) and streamline user lifecycle management using secure SAML 2.0 and OpenID Connect (OIDC) protocols. Reduce administrative IT overhead by deploying automated user provisioning and inbound SCIM custom integrations to sync security groups instantly from external identity providers.

Works with your favorite apps

Cloud Identity integrates with hundreds of cloud applications out of the box—and we’re constantly adding more to the list so you can count on us to be your single identity platform today and in the future. See our pre-integrated apps catalog to verify compatibility with your existing software stack and ensure a seamless deployment.

Multiple product logos such as Gmail, Google Calendar, Google Chat, Slack, Trello, Workday, Asana, Docusign, Dropbox
View all features

Documentation

Find resources and documentation for Cloud Identity

Tutorial

Active Directory user account provisioning

How to set up user and group provisioning between Active Directory and your Cloud Identity or Google Workspace account by using Google Cloud Directory Sync (GCDS).

Learn more
Google Cloud Basics

Set up Cloud Identity

Learn how to set up Cloud Identity and become a Google Cloud administrator.

Learn more
Tutorial

Sign up for Cloud Identity from the Google Cloud console

How to sign up for Cloud Identity through the Google Cloud console.

Learn more

Not seeing what you’re looking for?

View all product documentation

Use cases

Real-world identity solutions: deploying Cloud Identity

Use case
Secure Privileged Admin Access to Google Cloud

Shield your highest-risk administrative sessions from compromise and lateral movement. By implementing continuous session verification and requiring biometric re-authentication for sensitive actions within the Web Console, you ensure that even if an active session is hijacked, malicious actors cannot modify core billing structures or alter IAM policies.

Read the admin security setup guide

Use case
Manage and Secure a Hybrid Device Fleet (BYOD)

Enable a secure, productive "work-from-anywhere" culture without exposing sensitive corporate data. Enforce compliance verification for personal and corporate-owned machines, automatically push secure Wi-Fi configurations, and maintain the ability to selectively wipe corporate data from mobile fleets without invading employee personal privacy.

Read the endpoint management documentation

Use case
Bridge Legacy On-Premises Apps to the Cloud

Eliminate password fatigue and close security gaps on self-hosted or legacy infrastructure. Bring traditional, directory-dependent systems—such as on-premises databases, VPNs, and legacy developer tools—under your central identity umbrella, allowing employees to log in securely with their primary corporate credentials.

Read the Secure LDAP architecture blog

Use case
Extend On-Premises Active Directory to the Cloud

Modernize your identity infrastructure without disrupting current operations. Seamlessly mirror your existing on-premises Active Directory users, groups, and attributes directly into your Google Cloud directory, establishing a unified source of truth and simplifying administration as you transition to a cloud-first architecture.

Read the Active Directory synchronization guide


View all technical guides
Generate a solution
What problem are you trying to solve?

What you'll get:
check_smallStep-by-step guide
check_smallReference architecture
check_smallAvailable pre-built solutions
This service was built with Gemini Enterprise Agent Platform. You must be 18 or older to use it. Do not enter sensitive, confidential, or personal info.

All features

Learn more about Cloud Identity features

Account security and MFA

Help protect users from phishing attacks with Google’s intelligence and threat signals and multi-factor authentication (MFA), including push notifications, Google Authenticator, phishing-resistant Titan Security Keys, passkeys, and using your Android or iOS device as a security key.

Device security with endpoint management

Improve your company’s device security posture on Android, iOS, Windows, and macOS devices using a unified console. Set up devices in minutes and keep your company data more secure with endpoint management. Enforce security policies, wipe company data, deploy apps, view reports, and export details.

Easy app access with SSO

Enable employees to work from virtually anywhere, on any device, with single sign-on (SSO) to thousands of SaaS apps, including Salesforce, SAP SuccessFactors, Google Workspace, and more.

Works with your favorite apps

Cloud Identity integrates with hundreds of cloud applications out of the box—and we’re constantly adding more to the list so you can count on us to be your single identity platform today and in the future. See current list.

Digital workspace

Enable employees to set up quickly with a digital workspace—sign in once and access 5000+ apps, including pre-integrated SAML 2.0 and OpenID Connect (OIDC) apps, custom apps, and on-premises apps.

Unified management console

Use a single admin console to manage user, access, app, and device policies, monitor your security and compliance posture with reporting and auditing capabilities, and investigate threats with Security Center.

Automated user provisioning

Reduce administrative overhead involved in managing your users in individual third-party cloud apps by automating user provisioning to create, update, or delete user profile information in one place and have it reflected in your cloud apps.

Hybrid identity management

Increase the ROI of your existing investments by extending your Microsoft Active Directory (AD) users to the cloud with Directory Sync and enabling simpler user access to traditional apps and infrastructure with secure LDAP.

Context-aware access

A core component of Google’s Chrome Enterprise Premium security model, context-aware access enables you to enforce granular and dynamic access controls based on a user’s identity and the context of the access request, without the need for a traditional VPN.

Account takeover protection

Strengthen user security with Google’s automatic multilayered hijacking protection. Detect anomalous login behavior and present users with additional challenges to prevent account takeovers.

Technical support

Get help when issues arise with 24/7 support from a real person. Phone, email, and chat support is available in 14 languages, included with your Cloud Identity subscription.

Advanced Protection Program

A constantly evolving and easy-to-use bundle of Google’s strongest account security settings, ensuring that your most at-risk users always have the strongest possible protection.

Bring your own device (BYOD) support

Endpoint management supports and enables BYOD, making it easy to keep your company data safer while letting employees use their favorite personal devices to get work done.

Quick and easy endpoint management deployment

As soon as your employee’s device gets enrolled in endpoint management, all Wi-Fi and email configurations including server-side certificates get pushed to the device instantly.

No agent required

Agentless setup for basic device management offers wipe and inventory controls for all devices in your fleet, with no user setup or disruption.

User-friendly MFA methods

Cloud Identity supports a variety of MFA methods—hardware security keys, phone as a security key, mobile device push notifications, SMS, and voice calls—meaning you can choose the right option for your employees.

Rich MFA auditing and reporting

Monitor employee usage, set alerts, and examine potential risks via detailed reports and audit logs.

Easy access to on-premises apps

With secure LDAP, users can securely access traditional LDAP-based apps and infrastructure, using their Cloud Identity credentials.

Automate life cycle management

Provision and deprovision users in real time from a unified admin console.

Pricing

Cloud Identity pricing details

Cloud Identity is $7.2/mo per user. Try Cloud Identity Premium or learn more about Cloud Identity features and editions pricing.


Gartner, Gartner Peer Insights ‘Voice of the Customer’: Unified Endpoint Management, Peer Contributors, 5 January 2021. The GARTNER PEER INSIGHTS CUSTOMERS’ CHOICE badge is a trademark and service mark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. Gartner Peer Insights Customers’ Choice constitute the subjective opinions of individual end-user reviews, ratings, and data applied against a documented methodology; they neither represent the views of, nor constitute an endorsement by, Gartner or its affiliates.

Take the next step

Start building on Google Cloud with $300 in free credits and 20+ always free products.

Try Cloud Identity
Cloud Identity
Start free
Contact us
Google Cloud
Morty Proxy This is a proxified and sanitized view of the page, visit original site.