GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit
DI-38: Document AAD specific IdP SSO only federation creation a GCP Identity stub account pair post sync
- Dominant language
- Shell
- Stars
- 36
- Forks
- 26
- PR merge metrics
- No merged PRs in 30d
Description
see design issue 38 https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/blob/dev/solutions/landing-zone/architecture.md#di-38-identity-federation
see https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/architecture.md#di-4-cloud-identity-federation
See Identity Onboarding and Federation options at https://cloud.google.com/architecture/landing-zones/decide-how-to-onboard-identities
- using Option 2
- using https://cloud.google.com/architecture/identity/federating-gcp-with-azure-active-directory
- https://cloud.google.com/architecture/identity/reference-architectures#using_an_external_idp
#### SSO only
- Verify details of backing IAM Identity user/role as part SSO federated IdP user auth during IAP session https://cloud.google.com/iap/docs/concepts-overview
- Verify GCP Identity role for application use is available via the IAP session token - thinking https://cloud.google.com/iap/docs/signed-headers-howto#controlling_access_with_sign_in_attributes
- see https://cloud.google.com/architecture/identity/single-sign-on
"To use SSO, a user must have a user account in Cloud Identity or Google Workspace and a corresponding identity in the external IdP"
Contributor guide
Assessment
This issue has not been assessed yet.