StephenPink Posted June 2, 2021 Posted June 2, 2021 Hey all, With the push for MFA (now on for staff, for 365) I'm keen to do the same for Google - however really don't want staff to have to have two apps, and for it to be as straight forward as being said. So came across this: Federating Google Cloud with Azure Active Directory as I hadn't realised you could federate Google with Azure! I was wondering if anyone has done this, and if there are any first-hand experiences? Currently we sync both Google and Azure from on-prem AD - and I figure if I can change our Google instance to sync from Azure, instead of on-prem AD, that can then leverage the Azure MFA/conditional access, all without requiring staff to do any further setup... Cheers, Stephen
CyBeRkId2002 Posted June 2, 2021 Posted June 2, 2021 ooo, following with interest as this is something that has been on my radar for a while!
Boredguy Posted June 2, 2021 Posted June 2, 2021 We configured our G-Suite domain to authenticate via Azure a few years ago to prevent students/staff signing up with their school domain name. Worked perfectly fine so not reason why it still wouldn't work with MFA enabled.
jmak Posted June 2, 2021 Posted June 2, 2021 I used the Cloud Connector Enterprise app in Azure AD Connect. https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial Sign in worked perfectly. Provision of btw accounts was great too. I did have a few issues with existing accounts - they linked successfully and sign in worked, but users didn't have access to Google services. I'm sure it was fixable, but I only had 40ish accounts and most of them had no data, so I stopped and started again. Just one to test before you commit.
Shadow_Walker Posted June 2, 2021 Posted June 2, 2021 I used the Cloud Connector Enterprise app in Azure AD Connect. https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial Sign in worked perfectly. Provision of btw accounts was great too. I did have a few issues with existing accounts - they linked successfully and sign in worked, but users didn't have access to Google services. I'm sure it was fixable, but I only had 40ish accounts and most of them had no data, so I stopped and started again. Just one to test before you commit. Yes we used the same for our trust. Has made the process a million times better. Just have to make sure everything syncs up perfectly but will be the odd account which will have few issues mainly email is different.
StephenPink Posted June 3, 2021 Author Posted June 3, 2021 Thanks guys, sounds promising! Were any of you doing it as a migration from an on-prem AD sync to Azure sync or was it just Azure from the get go? @jmak - totally agree, one to test however not sure how I can test easily without disruption... that's my main reasoning behind trying to find people that have done it before haha! Cheers, Stephen
highsky Posted June 3, 2021 Posted June 3, 2021 You can also enable, if not already, the SSO from the domain PC to O365 using the AD Connect sync option and a GPO. O365 MFA offers the option to whitelist IPs from MFA, if the school IP doesn't need that enabled. Google not yet, but using the SSO that is not an issue when using multiple classes.
StephenPink Posted January 17, 2025 Author Posted January 17, 2025 Resurrecting this again as still on the list and may be prioritised this year, however there are now 2 scenarios; 1. Local AD > Google This one is currently Local AD > Google using GCDS and Password Sync (and then Local AD > Entra using Entra Connect) Figure this would probably me more straight forward - those that mentioned Cloud Connector Enterprise app is this still the way to go? Not sure I fully understand that one though... What would be the biggest risks/gotchas to look out for here? 2. Separate AD and Google This is a Local AD > Entra using Entra Connect, and then a completely separate Google domain. The UPN/Email is the same (99%) but the accounts/identities are not connected in any way. Seems like this is more complex! Not even sure where to start with this? Again also, biggest risks/gotchas to look out for here? Any recommendations/suggestions for companies that may be able to help with this sort of work? Primary driving force for this is MFA - enforcing MFA across all sites, but don't want people to have set up multiple MFA apps/accounts for what they see as the "same" account. And just generally shoring up identities to reduce confusion/likelihood of poor passwords etc etc Cheers
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now