PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #210
Your organization is using Active Directory and wants to configure Security Assertion Markup Language (SAML). You must set up and enforce single sign-on (SSO) for all users. What should you do?
The correct answer is A. 1. Create a new SAML profile. To enforce SAML-based SSO with Active Directory for Google Workspace or Cloud Identity, the correct sequence is: (1) Create a new SAML profile in the Google Admin console, which involves configuring the Identity Provider (IdP) details from Active Directory (entity ID, SSO URL…
Question
Options
- A
- Create a new SAML profile.
- B
- Configure prerequisites for OpenID Connect (OIDC) in your Active Directory (AD) tenant.
- C
- Create a new SAML profile.
- D
- Manage SAML profile assignments.
How the community answered
(46 responses)- A91% (42)
- B2% (1)
- C2% (1)
- D4% (2)
Explanation
To enforce SAML-based SSO with Active Directory for Google Workspace or Cloud Identity, the correct sequence is: (1) Create a new SAML profile in the Google Admin console, which involves configuring the Identity Provider (IdP) details from Active Directory (entity ID, SSO URL, certificate) and the Service Provider (SP) details to configure in AD FS or a compatible SAML IdP; (2) Assign the SAML profile to organizational units or groups to enforce SSO for all users. Option B describes OIDC (OpenID Connect), not SAML - a different federation protocol. Options C and D describe partial steps (creating a profile or managing assignments) but do not represent the complete, ordered process needed to configure and enforce SAML SSO end-to-end.
Topics
Community Discussion
No community discussion yet for this question.