nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #214

You plan to synchronize identities to Cloud Identity from a third-party identity provider (IdP). You discovered that some employees used their corporate email address to set up consumer accounts to…

The correct answer is B. Reconcile accounts that exist in Cloud Identity but not in the third-party IdP. E. Use the transfer tool to invite those corporate employees to transfer their unmanaged consumer. Two actions are needed. First (E): Google provides a Transfer Tool for Unmanaged Accounts that lets the organization invite employees to transfer their unmanaged consumer Google accounts (created with corporate emails) into organizational control - this gives the org control…

Submitted by certguy· Apr 18, 2026Configuring access within a cloud solution environment

Question

You plan to synchronize identities to Cloud Identity from a third-party identity provider (IdP). You discovered that some employees used their corporate email address to set up consumer accounts to access Google services. You need to ensure that the organization has control over the configuration, security, and lifecycle of these consumer accounts. What should you do? (Choose two.)

Options

  • AMandate that those corporate employees delete their unmanaged consumer accounts.
  • BReconcile accounts that exist in Cloud Identity but not in the third-party IdP.
  • CEvict the unmanaged consumer accounts in the third-party IdP before you sync identities.
  • DUse Google Cloud Directory Sync (GCDS) to migrate the unmanaged consumer accounts' emails
  • EUse the transfer tool to invite those corporate employees to transfer their unmanaged consumer

How the community answered

(51 responses)
  • A
    16% (8)
  • B
    75% (38)
  • C
    4% (2)
  • D
    6% (3)

Explanation

Two actions are needed. First (E): Google provides a Transfer Tool for Unmanaged Accounts that lets the organization invite employees to transfer their unmanaged consumer Google accounts (created with corporate emails) into organizational control - this gives the org control over configuration, security, and lifecycle of those accounts. Second (B): After syncing with the IdP, you should reconcile accounts that exist in Cloud Identity but have no matching entry in the IdP - these are orphaned or legacy managed accounts that could represent a security risk and need to be reviewed or deprovisioned. Option A (mandating deletion) is disruptive and loses account data/history. Option C doesn't apply because consumer accounts live on Google, not in the third-party IdP. Option D (GCDS) syncs directory data from LDAP/AD - it does not migrate unmanaged consumer accounts.

Topics

#Identity Management#Cloud Identity#Account Reconciliation#Unmanaged Accounts

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice