Jump to content

Recommended Posts

Posted

Hey all,

 

With the push for MFA (now on for staff, for 365) I'm keen to do the same for Google - however really don't want staff to have to have two apps, and for it to be as straight forward as being said. So came across this: Federating Google Cloud with Azure Active Directory as I hadn't realised you could federate Google with Azure! I was wondering if anyone has done this, and if there are any first-hand experiences? Currently we sync both Google and Azure from on-prem AD - and I figure if I can change our Google instance to sync from Azure, instead of on-prem AD, that can then leverage the Azure MFA/conditional access, all without requiring staff to do any further setup...

 

Cheers,

Stephen

Posted

We configured our G-Suite domain to authenticate via Azure a few years ago to prevent students/staff signing up with their school domain name.

 

Worked perfectly fine so not reason why it still wouldn't work with MFA enabled.

Posted

I used the Cloud Connector Enterprise app in Azure AD Connect.

 

https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial

 

Sign in worked perfectly. Provision of btw accounts was great too. I did have a few issues with existing accounts - they linked successfully and sign in worked, but users didn't have access to Google services. I'm sure it was fixable, but I only had 40ish accounts and most of them had no data, so I stopped and started again. Just one to test before you commit.

Posted
I used the Cloud Connector Enterprise app in Azure AD Connect.

 

https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial

 

Sign in worked perfectly. Provision of btw accounts was great too. I did have a few issues with existing accounts - they linked successfully and sign in worked, but users didn't have access to Google services. I'm sure it was fixable, but I only had 40ish accounts and most of them had no data, so I stopped and started again. Just one to test before you commit.

Yes we used the same for our trust. Has made the process a million times better. Just have to make sure everything syncs up perfectly but will be the odd account which will have few issues mainly email is different.

Posted

Thanks guys, sounds promising! Were any of you doing it as a migration from an on-prem AD sync to Azure sync or was it just Azure from the get go?

@jmak - totally agree, one to test however not sure how I can test easily without disruption... that's my main reasoning behind trying to find people that have done it before haha!

 

Cheers,

Stephen

Posted

You can also enable, if not already, the SSO from the domain PC to O365 using the AD Connect sync option and a GPO.

 

 

O365 MFA offers the option to whitelist IPs from MFA, if the school IP doesn't need that enabled.

Google not yet, but using the SSO that is not an issue when using multiple classes.

  • 3 years later...
Posted

Resurrecting this again as still on the list and may be prioritised this year, however there are now 2 scenarios;

 

1. Local AD > Google

This one is currently Local AD > Google using GCDS and Password Sync (and then Local AD > Entra using Entra Connect)

Figure this would probably me more straight forward - those that mentioned Cloud Connector Enterprise app is this still the way to go? Not sure I fully understand that one though...

What would be the biggest risks/gotchas to look out for here?

 

2. Separate AD and Google

This is a Local AD > Entra using Entra Connect, and then a completely separate Google domain. The UPN/Email is the same (99%) but the accounts/identities are not connected in any way.

Seems like this is more complex! Not even sure where to start with this?

Again also, biggest risks/gotchas to look out for here?

 

Any recommendations/suggestions for companies that may be able to help with this sort of work?

 

Primary driving force for this is MFA - enforcing MFA across all sites, but don't want people to have set up multiple MFA apps/accounts for what they see as the "same" account. And just generally shoring up identities to reduce confusion/likelihood of poor passwords etc etc

 

Cheers

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...