You are the Security Admin in your company. You want to synchronize all security groups that have an email address from your LDAP directory in Cloud IAM.
I'm just hoping the LDAP directory doesn't have any email addresses like 'security_admin@company.com'. That would make this whole process a bit too meta for my liking.
D mentions using the group object class attribute, but I don't want to make assumptions about my LDAP directory structure. A is the way to go, no doubt.
A) Configure Google Cloud Directory Sync to sync security groups using LDAP search rules that have ''user email address'' as the attribute to facilitate one-way sync.
Option C looks like it could work, but I don't want to deal with the hassle of a management tool. I'll stick with the Google Cloud Directory Sync in A.
B) Configure Google Cloud Directory Sync to sync security groups using LDAP search rules that have ''user email address'' as the attribute to facilitate bidirectional sync.
A) Configure Google Cloud Directory Sync to sync security groups using LDAP search rules that have ''user email address'' as the attribute to facilitate one-way sync.
Option A seems like the most straightforward approach to synchronize the security groups with email addresses from the LDAP directory. One-way sync should be sufficient for this use case.
A) Configure Google Cloud Directory Sync to sync security groups using LDAP search rules that have ''user email address'' as the attribute to facilitate one-way sync.
I think option C is the best choice. Using a management tool to sync based on email address attribute and creating a group in the Google domain will automatically assign Google Cloud IAM roles.
I disagree, I believe the answer is B. We need to configure Google Cloud Directory Sync for bidirectional sync to ensure all security groups with email addresses are synchronized.
I think the answer is A. We should configure Google Cloud Directory Sync to sync security groups using LDAP search rules that have 'user email address' as the attribute for one-way sync.
upvoted 0 times
...
Log in to Pass4Success
Sign in:
Report Comment
Is the comment made by USERNAME spam or abusive?
Commenting
In order to participate in the comments you need to be logged-in.
You can sign-up or
login
Tashia
1 months agoCrista
1 months agoEric
1 months agoBrett
14 days agoTy
18 days agoShayne
2 months agoMitsue
8 days agoElin
1 months agoDavida
1 months agoChuck
2 months agoRosalind
6 days agoMichel
7 days agoJacqueline
15 days agoNobuko
2 months agoTommy
7 days agoCarmen
1 months agoJohnetta
1 months agoBrittni
1 months agoTitus
2 months agoArthur
2 months agoDevora
3 months ago