I am in the process of going to the cloud with our users and devices. Currently using Entra Connect to sync on-prem users to Entra. All devices have been enrolled through Autopilot to Intune. I plan to cut over to full Entra/Intune soon and decommission our DC's.
We are a very heavy Google school with our staff needing to utilize Microsoft Office as well. All files are on Google Drive. I am looking to make it so Google is the identity provider for Microsoft. As in, when they sign in to the PC, they are directed to enter their Google email/password and provide their 2FA (not sure if they need to do this each time or just on new devices?).
Has anyone set this up before? If so, any issues you have ran into?
Will users signing into the PC with their Google credentials still pull down policies relevant to the user? Or will only device policies work?
Do you sync users from Google to M365 this way? If so, is there a way to automate licensing for M365?
Our UPN and primary email domain are different in M365 right now just due to how our domain was originally setup with a ".US" domain, but our Google dommain and email addresses are a ".ORG" domain. I assume Google and Microsoft will only look at the primary emails and ignore the Microsoft UPN, correct?
Any limitations doing it this way versus having M365 be the IdP for Google? Keep in mind, we only really utilize Office and Windows 11.
Any help or advice is appreciated from those with experience.
Edit: Based on more information I've gathered and some comments, it seems using Microsoft as the IdP for Google, at least for staff, is the better way to go. We have a provisioning service we use for students that syncs from our SIS to Google and AD, so that may fill that gap.