The native directory, security, and device management foundation for Google Cloud’s Unified Identity platform.
Secure employee access to Google Cloud, Google Workspace, and thousands of pre-integrated SaaS applications.
Defend against credential theft with phishing-resistant MFA and mandatory step-up re-authentication for sensitive console actions.
Enforce unified endpoint management and device policies across Windows, macOS, iOS, and Android devices.
Benefits
Google Cloud Unified Identity meets your enterprise where it is today. Easily secure native users, federate your existing human identity providers, or establish keyless access for machines and AI agents.
Cloud Identity
Native employee and device directory
Centrally manage local users, groups, and device policies (EMM) built into Google Cloud. Features continuous session security, advanced endpoint verification, and native console re-authentication.
Workforce Identity Federation
Federated human identity
Let employees and partners sign in using external IdPs like Okta or Microsoft Entra ID. Workforce Identity Federation simplifies account sync overhead while supporting both cloud-first and on-premises AD setups.
Workload Identity Federation
Keyless machine and AI identity
Securely connect programmatic workloads, CI/CD pipelines, and emerging AI agents to Google Cloud without service account keys, using short-lived federated credentials (OIDC/SAML/SPIFFE) with Workload Identity Federation.
Key features
Advanced administrative and security capabilities
Enforce hardware-backed Titan Security Keys and software-based passkeys to eliminate credential theft. Deploy the Google Credential Provider for Windows (GCPW) to secure physical machine logins with FIDO2-compliant keys, and protect privileged browser sessions using mandatory step-up re-authentication.
Gather deep inventory and security posture metadata across Android, iOS, Windows, and macOS fleets. Use Endpoint Verification to check encryption status, OS versions, and screen-lock compliance, allowing you to enforce granular, context-aware access policies without intrusive agents.
Enable federated single sign-on (SSO) and streamline user lifecycle management using secure SAML 2.0 and OpenID Connect (OIDC) protocols. Reduce administrative IT overhead by deploying automated user provisioning and inbound SCIM custom integrations to sync security groups instantly from external identity providers.
Cloud Identity integrates with hundreds of cloud applications out of the box—and we’re constantly adding more to the list so you can count on us to be your single identity platform today and in the future. See our pre-integrated apps catalog to verify compatibility with your existing software stack and ensure a seamless deployment.

What's new
Sign up for Google Cloud newsletters to receive product updates, event information, special offers, and more.
Documentation
Use cases
Shield your highest-risk administrative sessions from compromise and lateral movement. By implementing continuous session verification and requiring biometric re-authentication for sensitive actions within the Web Console, you ensure that even if an active session is hijacked, malicious actors cannot modify core billing structures or alter IAM policies.
Enable a secure, productive "work-from-anywhere" culture without exposing sensitive corporate data. Enforce compliance verification for personal and corporate-owned machines, automatically push secure Wi-Fi configurations, and maintain the ability to selectively wipe corporate data from mobile fleets without invading employee personal privacy.
Eliminate password fatigue and close security gaps on self-hosted or legacy infrastructure. Bring traditional, directory-dependent systems—such as on-premises databases, VPNs, and legacy developer tools—under your central identity umbrella, allowing employees to log in securely with their primary corporate credentials.
Modernize your identity infrastructure without disrupting current operations. Seamlessly mirror your existing on-premises Active Directory users, groups, and attributes directly into your Google Cloud directory, establishing a unified source of truth and simplifying administration as you transition to a cloud-first architecture.
Read the Active Directory synchronization guide
All features
| Account security and MFA | Help protect users from phishing attacks with Google’s intelligence and threat signals and multi-factor authentication (MFA), including push notifications, Google Authenticator, phishing-resistant Titan Security Keys, passkeys, and using your Android or iOS device as a security key. |
| Device security with endpoint management | Improve your company’s device security posture on Android, iOS, Windows, and macOS devices using a unified console. Set up devices in minutes and keep your company data more secure with endpoint management. Enforce security policies, wipe company data, deploy apps, view reports, and export details. |
| Easy app access with SSO | Enable employees to work from virtually anywhere, on any device, with single sign-on (SSO) to thousands of SaaS apps, including Salesforce, SAP SuccessFactors, Google Workspace, and more. |
| Works with your favorite apps | Cloud Identity integrates with hundreds of cloud applications out of the box—and we’re constantly adding more to the list so you can count on us to be your single identity platform today and in the future. See current list. |
| Digital workspace | Enable employees to set up quickly with a digital workspace—sign in once and access 5000+ apps, including pre-integrated SAML 2.0 and OpenID Connect (OIDC) apps, custom apps, and on-premises apps. |
| Unified management console | Use a single admin console to manage user, access, app, and device policies, monitor your security and compliance posture with reporting and auditing capabilities, and investigate threats with Security Center. |
| Automated user provisioning | Reduce administrative overhead involved in managing your users in individual third-party cloud apps by automating user provisioning to create, update, or delete user profile information in one place and have it reflected in your cloud apps. |
| Hybrid identity management | Increase the ROI of your existing investments by extending your Microsoft Active Directory (AD) users to the cloud with Directory Sync and enabling simpler user access to traditional apps and infrastructure with secure LDAP. |
| Context-aware access | A core component of Google’s Chrome Enterprise Premium security model, context-aware access enables you to enforce granular and dynamic access controls based on a user’s identity and the context of the access request, without the need for a traditional VPN. |
| Account takeover protection | Strengthen user security with Google’s automatic multilayered hijacking protection. Detect anomalous login behavior and present users with additional challenges to prevent account takeovers. |
| Technical support | Get help when issues arise with 24/7 support from a real person. Phone, email, and chat support is available in 14 languages, included with your Cloud Identity subscription. |
| Advanced Protection Program | A constantly evolving and easy-to-use bundle of Google’s strongest account security settings, ensuring that your most at-risk users always have the strongest possible protection. |
| Bring your own device (BYOD) support | Endpoint management supports and enables BYOD, making it easy to keep your company data safer while letting employees use their favorite personal devices to get work done. |
| Quick and easy endpoint management deployment | As soon as your employee’s device gets enrolled in endpoint management, all Wi-Fi and email configurations including server-side certificates get pushed to the device instantly. |
| No agent required | Agentless setup for basic device management offers wipe and inventory controls for all devices in your fleet, with no user setup or disruption. |
| User-friendly MFA methods | Cloud Identity supports a variety of MFA methods—hardware security keys, phone as a security key, mobile device push notifications, SMS, and voice calls—meaning you can choose the right option for your employees. |
| Rich MFA auditing and reporting | Monitor employee usage, set alerts, and examine potential risks via detailed reports and audit logs. |
| Easy access to on-premises apps | With secure LDAP, users can securely access traditional LDAP-based apps and infrastructure, using their Cloud Identity credentials. |
| Automate life cycle management | Provision and deprovision users in real time from a unified admin console. |
Pricing
Cloud Identity is $7.2/mo per user. Try Cloud Identity Premium or learn more about Cloud Identity features and editions pricing.
Gartner, Gartner Peer Insights ‘Voice of the Customer’: Unified Endpoint Management, Peer Contributors, 5 January 2021. The GARTNER PEER INSIGHTS CUSTOMERS’ CHOICE badge is a trademark and service mark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. Gartner Peer Insights Customers’ Choice constitute the subjective opinions of individual end-user reviews, ratings, and data applied against a documented methodology; they neither represent the views of, nor constitute an endorsement by, Gartner or its affiliates.
Start building on Google Cloud with $300 in free credits and 20+ always free products.