Our current setup is: HCM/SIS feeds AD, AD then syncs to our SSO platform (Onelogin) and also our provisioning tool creates their Google accounts (may look more into GCDS depending on this discussion). Users in the SSO platform have RBAC to SAML apps.
Would Cloud Identity (free or paid) remove the need for our current SSO platform (which has all our SaaS apps via SAML)?
Would the conversion be: HCM/SIS feeds AD, AD feeds Google (GCDS), and then our apps SSO/SAML apps are configured in Cloud Identity?
Does anyone know the limitations of the SAML configurations within Cloud Identity? I know Google Workspace SAML is limited and doesn't support some types like Shiboleth last I checked, so we can't as of now migrate SAML apps into GW