Editions

There are two editions of Cloud Identity: The premium edition and the free edition.

Cloud Identity premium edition is not required to use Google Cloud. As a Google Cloud customer, you can request additional Cloud Identity licenses at no cost. However, the premium edition has additional features not offered in the free edition.

See the tables below for the differences between Cloud Identity Premium Edition and the free edition.

Note: For a list of features for different Google Workspace editions, visit Compare Google Workspace editions.

Choose between free and premium service

Device management

Note: License requirements are by user, not by device. Any users who want to sign in to a managed device must have a supported license for a feature to apply.

Fundamental endpoint management

The following features are available by default.

 

Cloud Identity Free

Cloud Identity Premium
Basic mobile device management โœ” โœ”
Basic passcode enforcement (mobile) โœ” โœ”
Remote account wipe (mobile) โœ” โœ”
Fundamental management for computers โœ” โœ”
Company owned computers โœ” โœ”
Remote sign-out (computers) โœ” โœ”
Endpoint verification โœ” โœ”
Google Credential Provider for Windows โœ” โœ”
Device inventory โœ” โœ”
Basic device reports โœ” โœ”
Network management โœ” โœ”
Android app management   โœ”

Advanced endpoint management

The following features require a Cloud Identity admin to enable advanced mobile management. Advanced endpoint management also includes all the features listed for Fundamental endpoint management.

 

Cloud Identity Free

Cloud Identity Premium
Advanced mobile device management   โœ”
Standard and strong passcode enforcement   โœ”
Mobile device security policies   โœ”
iOS app management   โœ”
Device approvals   โœ”
Windows device management   โœ”
Block devices   โœ”
Remote device wipe   โœ”
Android work profiles    โœ”
Advanced device reports   โœ”

Enterprise endpoint management

The following features require a Cloud Identity admin to enable advanced mobile management and are restricted to the Premium edition. Enterprise endpoint management also includes all the features listed for Fundamental endpoint management and the features listed for Advanced endpoint management.

 

Cloud Identity Free

Cloud Identity Premium
Company owned Android devices   โœ”
Zero-touch Android enrollment   โœ”
Company owned iOS devices   โœ”
iOS data protection   โœ”
Remote device wipe (Windows)   โœ”
Devices audit log   โœ”
Report inactive company owned devices   โœ”
Selectively distribute mobile apps   โœ”
Management rules   โœ”
Mobile device certificates   โœ”
Context-Aware Access   โœ”

Directory

 

Cloud Identity Free

Cloud Identity Premium
Basic directory management โœ” โœ”
Organizational units and groups Unlimited  Unlimited
User lifecycle management โœ” * โœ”
Admin managed groups โœ” โœ”
Groups for Business โœ” โœ”
Google Cloud Directory Sync
(Synchronize Active Directory and LDAP directories
with Google)
โœ” โœ”
Admin roles and privileges โœ” โœ”
Google Admin App for Android โœ” โœ”
Google Admin App for iOS โœ” โœ”
Admin SDK/API โœ” โœ”
Secure LDAP   โœ”

* The Cloud Identity free edition increases your user cap by 50. To learn more, visit Your Cloud Identity free edition user cap.

Security

 

Cloud Identity Free

Cloud Identity Premium
User security management โœ” โœ”
Self-service password recovery โœ” โœ”
2-Step verification (2SV) including security key management โœ” โœ”
2SV enforcement controls โœ” โœ”
2SV enforcement controls with security key management โœ” โœ”
2SV enforcement controls with security key enforcement โœ” โœ”
Password strength alert โœ” โœ”
Password management โœ” โœ”
Data loss prevention *   โœ” *
First-party session management   โœ”
Google security center **   โœ” **
Context-Aware Access   โœ”

* DLP for Drive is available to Cloud Identity Premium users who are also licensed for Google Workspace editions that include Drive audit log.

** Some features in the security center, for example, data related to Gmail and Google Drive, aren't available with Cloud Identity Premium.

Single sign-on (SSO) and automated provisioning

Reporting

 

Cloud Identity Free

Cloud Identity Premium
Admin audit log โœ” โœ”
Login audit log โœ” โœ”
Security reports โœ” โœ”
SAML audit log โœ” โœ”
Groups audit log โœ” โœ”
Token audit log โœ” โœ”
App reports โœ” โœ”
Account activity reports โœ” โœ”
Devices audit log   โœ”
Auto export audit logs to BigQuery   โœ”

Chrome Browser

  Cloud Identity Free

Cloud Identity Premium

User Policies/Reporting โœ” โœ”
Chrome Sync โœ” โœ”

Billing and support

 

Cloud Identity Free

Cloud Identity Premium
Billing   โœ”
Subscription and license management โœ” โœ”
Support Find support with other Google Cloud and Google Workspace users at the official Google Cloud Community. 24x7 Email, Phone, Chat
SLA   99.9%


Google, Google Workspace, and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.

What's next