Jump to content

Recommended Posts

Posted

Hi all,

Looking for some advice please, moving forward with a 365 and Google mixed environment...

 

We're a Google Workspace site, but we've never had a functioning system to manage Windows laptops. We have Lightspeed MDM for iPads, and google for ChromeOS. Implementing Intune has been a wish of mine for as long as I've been here, but now that we're changing Internet filter and alerting from one product to another, it has facilitated a more urgently pressing need for another MDM.

 

I've managed to 'sell' Intune because it will do iPads and all of our scary domain joined laptops that cause us nothing but grief. We already have a 365 tenant in place, but it currently service volume licensing and Power BI dashboards and that's it.

 

 

So, going forward my rough plan is set up Entra ID Connect on an onPrem server to sync AD to Entra ID, and then use that as an IdP for Google. Currently we used Password Sync and GCDS and I've got it set quite nicely and smooth, but both AD and Google are a bit inconsistent. 

 

Anyone got a setup like this? What I forsee and want to try and sell to exec, is a seamless integration of the above. I'm thinking we ditch PS and GCDS, have Entra ID Connect syncing AD and Entra ID, which will then present user accounts to Google for drive and mail etc. SSO between the lot.

 

Is this doable and best method? I can't see any obvious reason why we wouldn't do this and employ both Entra ID connect and GCDS? 

 

Google currently does 2FA, but again I feel (and believe me, I know this will be a ballache) moving 2FA away from Google to 365 would make more sense?

 

Curious to know what approach you've take in similar situations and any avenues I should go down?

 

THanks! 

Posted

From my own experience, Google's own authentication system is not great and we migrated to Entra ID auth. Basically Entra becomes the Login system so that when you enter your username / email on Google Classroom or other google apps, it will send you to the Microsoft 365 login page, and you authenticate their and then it logs you in. I always found this way better, we now use Entra for SSO for all our platforms. GCDS cannot be removed though, it must stay as it handles the provisioning of users from Entra to Google Workspace. Also don't put the Google Workspace admin account into Entra ID so that if there are any errors or issues with sync / login-flow, you still have access to to the Admin console - saves you from being locked out.

 

Are you planning on keeping on-Prem AD or moving fully over to Intune for all platforms? For the iPads, you should ideally have Apple school manager and Intune for 'zero-touch' deployment.

  • Like 1
Posted

Yes, I have this exact setup at one our schools.

 

Users in AD - synced to Entra and Google.

 

students have 1:1 Chromebooks, staff have Intune managed laptops.

 

We use our automate product to create users from SIMs Connected into AD and then these sync. AD is still in use due to integration with Paxton and Live Register - but this summer AD will disappear, Automate will sync users to Google and then we will enable SSO between Google and Microsoft 365 - as 365 is only used for Intune devices - and you can easily get Google login on these. 

 

  • Like 1
Posted

Half way into this process and frankly I think it's a waste of time, effort and money. I'm now of the strong opinion that you should do one or the other. A primarily Microsoft setup with Workspace just managing Chromebooks is easily doable,but the other way around is a nightmare for those actually using Windows. File storage is rubbish if any windows users are on shared devices, and the complexities just shout so one or the other. Easily possible to Google everything if that's your poison, and going all in with Chrome is probably cheaper overall. Microsofting is only a little more expensive overall due to adding in AV costs and slightly higher licensing,but you end up paying twice with a half-assed hybrid especially when you need to add P1/A5 licensing on top of what you pay for Workspace to be usable at this level.

 

As it stands ours is Google primarily but mostly Windows devices (batcrap crazy, I know) but it does work to a point. I think your plan sounds about right, although if you're primarily Google devices with a windows as the afterthought, perhaps it's worth a look at GCPW for the MS devices and keeping Google as the IdP. Might simplify if somewhat 

  • Like 2
Posted
On 05/04/2026 at 16:27, synaesthesia said:

Half way into this process and frankly I think it's a waste of time, effort and money. I'm now of the strong opinion that you should do one or the other. A primarily Microsoft setup with Workspace just managing Chromebooks is easily doable,but the other way around is a nightmare for those actually using Windows. File storage is rubbish if any windows users are on shared devices, and the complexities just shout so one or the other. Easily possible to Google everything if that's your poison, and going all in with Chrome is probably cheaper overall. Microsofting is only a little more expensive overall due to adding in AV costs and slightly higher licensing,but you end up paying twice with a half-assed hybrid especially when you need to add P1/A5 licensing on top of what you pay for Workspace to be usable at this level.

 

As it stands ours is Google primarily but mostly Windows devices (batcrap crazy, I know) but it does work to a point. I think your plan sounds about right, although if you're primarily Google devices with a windows as the afterthought, perhaps it's worth a look at GCPW for the MS devices and keeping Google as the IdP. Might simplify if somewhat 

 

I agree, fully. The biggest problem is user uptake and their willingness to change/learn. The next biggest problem is people using Word, for example, to create documents and then others accessing the same document from Docs. On paper, and for most cases, this should just work, but it always causes issues. People using word prevents all collaborative features, causes incompatibilities and we find time after time people have copies of copies. I've been in this field for for 17 years and I've given up trying to educate teachers on the best way to use files and storage systems.

 

I'm probably setting myself up for a huge future PITA, but this current hybrid setup was a mistake (before my time, and the decision would have been above my paygrade anyway). They were on 365 entirely but Google was sold as cheaper, does all that 365 does, and its better. IMO, none of those are quite true without going deeper. Certainly Windows/Office PCs syncing files up to Google is too much faff for the average user, and it causes much of the frustration felt by them and myself in IT. I would have gone down the 365 route personally, and it's why I'm trying to steer the project as illustrated above. Changing from Google to M365 now would be a huge Uturn so I can see why above doesn't want to entertain it, but unless we fully embrace Google we're setting ourselves up to fail, especially in the eyes of the users, and it's really demotivating. Rightly or wrongly, people are used to Office products.

 

 

Posted (edited)
On 04/04/2026 at 11:05, ConceroEdu_Matt said:

Yes, I have this exact setup at one our schools.

 

Users in AD - synced to Entra and Google.

 

students have 1:1 Chromebooks, staff have Intune managed laptops.

 

We use our automate product to create users from SIMs Connected into AD and then these sync. AD is still in use due to integration with Paxton and Live Register - but this summer AD will disappear, Automate will sync users to Google and then we will enable SSO between Google and Microsoft 365 - as 365 is only used for Intune devices - and you can easily get Google login on these. 

 

 

 

Interesting so you're not going AD > 365 > Google, but instead AD > 365 and AD > Google? Have you looked at Google's own GCDS for AD > Google sync? We use Locker for user creation from Bromcom. Works well, but takes a bit of fiddly setup.

 

Not sure we're at a point where we can ditch AD entirely yet. Would have to look at costs of Azure vs licenses and running costs of onPrem. I wanted AD>NET2 also, but above won't pay for the none lite version so we're stuck.

 

  

On 03/04/2026 at 00:23, NetworkDirector said:

From my own experience, Google's own authentication system is not great and we migrated to Entra ID auth. Basically Entra becomes the Login system so that when you enter your username / email on Google Classroom or other google apps, it will send you to the Microsoft 365 login page, and you authenticate their and then it logs you in. I always found this way better, we now use Entra for SSO for all our platforms. GCDS cannot be removed though, it must stay as it handles the provisioning of users from Entra to Google Workspace. Also don't put the Google Workspace admin account into Entra ID so that if there are any errors or issues with sync / login-flow, you still have access to to the Admin console - saves you from being locked out.

 

Are you planning on keeping on-Prem AD or moving fully over to Intune for all platforms? For the iPads, you should ideally have Apple school manager and Intune for 'zero-touch' deployment.

 

Thanks. Already got ASM. Several hundred iPads manually added via AC2 (don't ask... 😅), which are then handed over to a third party MDM for management and app deployment. It works, mostly.

 

Ah so you sync AD > M365 using Entra ID (cloud or connect please? I'm leaning towards onPrem connect agent) and then GCDS for AD > Google for user creation, using the federated SSO for auth? Just been reading up on the former, and it seems GCDS could be replaced with "Google Cloud / G Suite Connector"? Was this something you looked at?

Edited by Planehazza
Posted (edited)

Just a side swing, but did you look into GCPW (Google Credential provider for Windows)? If you are a school its crazy cheap and replaces the Windows login system on laptops and PCs with a Google login box, and includes 2 step auth to log onto the device.

GCPW also lets you manage the Windows devices and includes inTune device policy deployment from Google Workspace.

Edited by TwistedHelixis
  • Like 1
Posted
10 minutes ago, TwistedHelixis said:

Just a side swing, but did you look into GCPW (Google Credential provider for Windows)? If you are a school its crazy cheap and replaces the Windows login system on laptops and PCs with a Google login box, and includes 2 step auth to log onto the device.

GCPW also lets you manage the Windows devices and includes inTune device policy deployment from Google Workspace.

I haven't directly, but I'm aware of another MAT I'm in contact with that have. So far I've leaned towards Entra Google federation as the preferred method, but that does introduce a 2FA complication that GCPW might alleviate. It's the overall situation with Intune and managing Windows devices that has mainly led me down this path of keeping AD/Entra as the source, with Google basically piggy-backing off of it.

 

Introductions some security implications though, with having multiple accounts all potentially sharing same ID/passwords etc.

Posted
12 minutes ago, ConceroEdu_Matt said:

There are no costs for basic Entra, you can run it with A1

 

But no, we do AD > GCS Google and AD >Entra Connect > Entra

 

Thanks, Matt. Apologies I'm a little confused. So you guys are using GCDS to sync AD to Google? Your previous message said Automate, which I took to mean Power Automate?

Posted
1 minute ago, Planehazza said:

 

Thanks, Matt. Apologies I'm a little confused. So you guys are using GCDS to sync AD to Google? Your previous message said Automate, which I took to mean Power Automate?

Sorry! 

Automate - Concero Automate - which is Salamander Cloud for Partners - this creates users in AD from SIMS Connected
AD then syncs using GCDS for Google
AD to Entra 

  • Thanks 1
Posted
33 minutes ago, ConceroEdu_Matt said:

Sorry! 

Automate - Concero Automate - which is Salamander Cloud for Partners - this creates users in AD from SIMS Connected
AD then syncs using GCDS for Google
AD to Entra 

Ah gotcha, very similiar to mine currently then. I currently have GCDS as a single instance, but with an XML for each site ran sequentially via task scheduler. Very tempted to consolidate it to a single XML.

 

However, now that I've spotted this https://learn.microsoft.com/en-gb/entra/identity/saas-apps/google-apps-tutorial I'm quite intriqued by this. I sort of picture it as a vertical provision/sync from AD to Entra, then a horizontal sync between Entra and Google using that Enterpirse App as above. Knowing my luck, the MS licensing heathens will intervene.

 

More food for thought and homework, thanks :)

Posted

Still thinking about this one. The main priority is getting Intune and moving away from just domain joining and BitLocking devices and hoping for the best...

 

Ideally I'd love it that users sign into their W11 desktop and through Federated logins and SSO, Google Chrome and Drive just sign in automatically, but I'm thinking that perhaps this is more a risk really? It would make a HUGE difference to our users, many of whom complain about this process daily, but it brings in many a challenge and risk. Understandably, management is very reluctant to undo and change 2FA which is currently Google, but it wouldn't be a total career ending move to have it brought over to Entra instead, but it would be a huge effort and challenge, with a lot of push back.

 

Is my vision sound, or am I being a bit naive? I would love to have AD and Entra handle the source of truth for accounts etc. so that we're (well, the users) not battling yet another account etc for managing devices. Is it possible to have Google apps in Windows just do seamless SSO based on device authenticated against Entra? I don't mind if GCDS is still required for the management of user/OU sync (in fact, even if Entra is provisioning accounts through Google Cloud/G Suite Connector, I still forsee the need for GCDS to maintain Google user OU homing (various policies etc are set per OU etc.).

 

Sanity check needed, please!

Posted
3 minutes ago, synaesthesia said:

It's not possible to automatically sign into Chrome automatically without using GCPW, and even then Drive won't sign in automatically :(

 

I gotta admit I can understand why, but it's super frustrating for users. Said frustration is then passed on to me through moaning. At least with password sync and GCDS things are a LOT more consistent than they were. 

Posted (edited)
30 minutes ago, synaesthesia said:

It's not possible to automatically sign into Chrome automatically without using GCPW, and even then Drive won't sign in automatically :(

 

Although it does kind of, provided the user has opened Chrome browser first, which is SSO, the user then just needs to click on their email address which should already be listed in Google Drive for Desktop.

 

I did stumble on a script that auto logs into Drive for Desktop once the user has logged into Chrome Browser, no idea where that is, so perhaps AI can create something.

Edited by TwistedHelixis
Posted
3 minutes ago, TwistedHelixis said:

Although it does kind of, provided the user has opened Chrome browser first, which is SSO, the user then just needs to click on their email address which should already be listed in Google Drive for Desktop.

True,but only if not using shared devices or having profiles hang around longer than they should. That's the biggest barrier currently for many and with that fixed, it's almost be worth running a hybrid like this. 

 

Posted
Just now, synaesthesia said:

True,but only if not using shared devices or having profiles hang around longer than they should. That's the biggest barrier currently for many and with that fixed, it's almost be worth running a hybrid like this. 

 

Yep, shared drives is always going to be an issue, not sure about the profile issue as my GCPW schools no longer have any servers.

Posted
33 minutes ago, TwistedHelixis said:

Although it does kind of, provided the user has opened Chrome browser first, which is SSO, the user then just needs to click on their email address which should already be listed in Google Drive for Desktop.

 

I did stumble on a script that auto logs into Drive for Desktop once the user has logged into Chrome Browser, no idea where that is, so perhaps AI can create something.

 

That's the closest to SSO/automated sign in we have currently is this 😅 Telling people to sign into Chrome first so that Drive is just a click or two.

  • Like 1
Posted

ANother question for the masses. As we're moving 450 (150 are too old to go into Intune, yep, thanks education system...) from Lightspeed to Intune, now is a perfect time to also sell Shared iPad. I'm obviously going to federate against Google or Entra here. Question, given above, would it make sense to federate against Entra, or Federate against Google? What will happen if/when we federate Entra and Google? Will Apple send them to Google who then sends them to Entra? Or will it just break?  

Posted

Might be worth looking at Entra cloud sync rather than Entra connect, as that is the way Microsoft are "pushing" it.

Also possible to sync AD > Entra > Google with out 3rd party integrations. Provisions the user to their correct Google OU as well. I have done it at a few schools, but not sure how "supported" it is. It doesn't sync passwords, but if you are using Entra as SSO for Google, that should not be a problem. If of interest, I will see if I can dig out the guides I used to do it.

Posted
Just now, jnfarmer said:

Might be worth looking at Entra cloud sync rather than Entra connect, as that is the way Microsoft are "pushing" it.

Also possible to sync AD > Entra > Google with out 3rd party integrations. Provisions the user to their correct Google OU as well. I have done it at a few schools, but not sure how "supported" it is. It doesn't sync passwords, but if you are using Entra as SSO for Google, that should not be a problem. If of interest, I will see if I can dig out the guides I used to do it.

 

 

Thank you, much appreciated. So far, I've got it set that AD is syncing to Entra via onprem. I went down the path of cloud connect but it felt like onprem was better suited. I've got a meeting with a third party for support on this on Friday, so will discuss options in depth then also.

 

I planned to set up Entra > Google SSO to speed up user experience with Google Drive and Chrome. I understand there (by design) is no way to automatically zero click sign in these apps based on Windows OS login, but I'm wondering if SSO would still speed up the login steps by just having them click their email and allowing SSO to sign in. Still want to trial this, as it's one of the biggest complaints I get still after 4 years of being Google.

 

I've ran ASM > Google as the initial test, thinking it would allow me to select a test OU. Nope, it just went, great, that's on, here's ~4500 user accounts in ASM now. Aye, cheers, mate.. 🤦

 

 

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...