Using Google Cloud Directory Sync (GCDS)
Organizations typically have all their users in an AD that refers to a list of users stored as a directory of information. AD organizes the users in an OU.
User identities can be directly created in Google's Cloud Identity or they can be integrated from various sources, such as human resource information systems (HRIS) (Workday, Systems, Applications, and Products in Data Processing (SAP), and so on), or other identity providers (IdPs), such as Okta, Ping Identity, ForgeRock, and Azure AD using federation. We will dive into federation techniques in the next section when we talk about SSO.
These identity systems serve as the source of truth for user identities and integrate with all applications that require user-login authentication. Google Cloud integrates with all these sources of identities seamlessly using GCDS and makes your move to Google Workspace easy, as illustrated in the following diagram: