What you are evaluating
These are distinct products: Cloud Identity manages Google identities, Workforce Identity Federation maps an external identity provider into Google Cloud, and Identity Platform provides customer identity. Verify the selected product’s requirements separately.
A useful evaluation context
A team can evaluate external workforce federation, Google account management or customer login according to its distinct application requirements.
Documented capabilities
The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.
- Workforce Identity Federation maps OpenID Connect or SAML identities into Google Cloud without syncing a full user directory.
- Cloud Identity and Workspace remain the Google-account plane for people who need Google identities and administration.
- Identity Platform provides customer identity features such as social login, SAML, multifactor authentication, and tenancy for applications you operate.
Where it fits in the work
- Decide which lab problem you are solving: Google Cloud access, Google accounts, or customer login, and enable only that product.
- For cloud access, configure Workforce Identity Federation from your corporate identity provider into a test project and grant a synthetic role.
- For customer login, use a separate lab application with synthetic consumers and explicitly scoped authorization.
APPLY THE IDEA / ILLUSTRATIVE EXERCISE
Make the outcome observable.
In a Google Cloud test project, federate a synthetic workforce user through Workforce Identity Federation to a bounded role, and in a separate project register a synthetic customer user in Identity Platform.
Evidence to look for
The workforce user reaches only the federated cloud role, the customer user signs in only to the Identity Platform application, and neither identity appears as a standing Google Workspace administrator.
Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.
Questions for your evaluation
- Which of Cloud Identity, Workforce Identity Federation, and Identity Platform is actually in the quote, and which job does each perform?
- Does Workforce Identity Federation in the lab replace any corporate identity-provider functions, or only map groups into Google Cloud IAM?
- Which team owns each identity population and prevents customer authentication from inheriting workforce administration privileges?