Customer Google Sign-In Marketplace Questionnaire
Customer Google Sign-In Marketplace Questionnaire
1. Purpose
Use this document as the customer-facing questionnaire for onboarding Google sign-in through Microsoft Entra External ID.
For portal form labels and helper copy text, use:
docs/46-customer-google-signin-marketplace-portal-copy.md
The customer must complete all required sections before implementation scheduling.
2. Submission rules
- Customer must submit all required fields in sections 3 through 9.
- Customer must not send secrets in plain text email.
- Customer must provide secret values through an approved secret handoff channel.
- Customer must provide at least one named technical owner and one named security approver.
3. Organization profile (required)
- Legal organization name:
- Primary business domain (example: customer.com):
- Primary deployment region:
- Technical owner name:
- Technical owner email:
- Security owner name:
- Security owner email:
4. Google identity profile (required)
- Tenant type (Cloud Identity Premium or Google Workspace):
- Verified domain used for workforce sign-in:
- Google super admin email:
- Break-glass admin email:
- Confirmation that both admin accounts can sign in locally to Google Admin:
5. Google federation credentials (required)
Note: Google API key is not sufficient for Google sign-in federation.
- Google OAuth project ID:
- Google OAuth Client ID:
- Google OAuth Client Secret reference (secret manager path, vault URI, or ticket reference):
- OAuth consent screen support email:
6. Entra context (required)
- Entra tenant ID:
- Entra tenant domain:
- Target user flow name for pilot:
- Confirmation that customer approves Google provider in the target user flow:
7. Pilot definition (required)
- Pilot user email:
- Pilot group name:
- Pilot start window in UTC:
- Pilot end window in UTC:
- Confirmation that local fallback sign-in remains enabled during pilot:
8. Governance approvals (required)
- Identity change approver name:
- Identity change approver email:
- Rollback approver name:
- Rollback approver email:
- Approved change window in UTC:
9. Optional automation onboarding fields
Complete this section only if customer wants automated group lifecycle after pilot acceptance.
- Automation requested (true or false):
- Google delegated admin email for automation:
- Google service account identifier:
- Approved Admin SDK scopes:
- Secret reference for automation credential material:
- Customer approval for Entra-to-Google group synchronization:
10. Customer attestation
Customer must confirm the statements below:
- We confirm domain ownership and identity admin authority.
- We confirm Google OAuth values are correct for the target tenant.
- We confirm break-glass account is tested and operational.
- We confirm local fallback is approved for pilot safety.
- We confirm listed approvers are authorized for change and rollback decisions.
Signature name:
Signature date (UTC):
11. Internal Synkronyx intake check
Synkronyx delivery owner must verify:
- Required sections are complete.
- Secret references are reachable.
- Pilot scope is constrained.
- Rollback path is approved.
- Customer attestation is signed.