Is Identity as a Service (IDaaS), extends GSuite identity management to GCP services. You don’t have to be a GSuite customer (i.e. no Google apps such as email, calendar, drive) to use Cloud Identity. Even though, both are managed through admin.google.com.
Manages internal and external identities for either your company resources or external facing products/apps
Identities can be users/groups, apps for devices
Device management
Directory management
Security
SSO: apps
Reporting
vs. Identity Platform: Cloud Identity is just API used by IAM, Identity Platform is the service that can be configured and used by others including apps.
Cloud Identity is managed at the GSuite side to specify authentication requirement (e.g. 2-SV, password requirements, etc)
Features:
Free and Premium editions
Premium adds enterprise security, apps and devices management
SSO and 2-SV (2-steps verification, 2FA)
Sync with on-prem directories.
BeyondCorp
Trust no network!
Offer this to customers through Identity-Aware Proxy (IAP)