
Best BuyがWorkforce Identity FederationでAIワークロードを拡張しアクセスを保護Best Buy scales AI workloads and secures access with Workforce Identity Federation
匿名の公開いいねです。記事の保存・お気に入りではなく、Featured、Top 3、重要度、掲載順位には影響しません。仕組みとプライバシーAnonymous public likes are reactions, not saved articles or bookmarks. They do not affect Featured, Top 3, importance, or listing order.How it works and privacy
Best BuyはMicrosoft Entra IDとの同期負荷とセキュリティリスクをWorkforce Identity Federationで解消し、Google Cloud上のAI・分析基盤を安全にスケールさせることに成功した。
Best Buy adopted Google Cloud's Workforce Identity Federation to eliminate administrative overhead and security risks when syncing backend users from Microsoft Entra ID, enabling secure scaling of its AI and analytics workloads.
要約と収集メタデータをもとに生成した AI 解説本文です。元記事全文の転載・翻訳ではありません。This AI explainer is generated from the summaries and collected metadata, not from a reproduction or translation of the full source article.
米大手家電量販店のBest Buyが、Google Cloud上で拡大するAI・分析ワークロードの認証基盤を、Workforce Identity Federationの採用によって刷新した。Google Cloudが公開した事例によれば、同社は数千人規模のバックエンドユーザーをMicrosoft Entra IDから同期する際の運用負荷とセキュリティリスクを解消し、ワークロードを安全にスケールさせたという。
Best Buyは高度な分析とAIの用途でGoogle Cloudの利用を広げるなかで、二つの大きな課題に直面していた。一つは、Microsoft Entra IDに登録された多数のユーザーをGoogle Cloud側へ同期する際のリスク抑制であり、もう一つは、その同期作業に伴う管理上の摩擦だった。ユーザー数が増えるほど、これらの負荷は無視できないものになっていく。
Workforce Identity Federationは、Microsoft Entra IDのような外部のIDプロバイダーとGoogle CloudのIAMを連携させ、ユーザーアカウントをGoogle Cloud側に複製せずにアクセスを許可する仕組みだ。従来、外部IDの利用者にクラウドリソースへのアクセスを与えるには、アカウントを個別に作成・同期して管理する必要があり、認証情報の重複によって攻撃面が広がりやすかった。フェデレーションはこの重複をなくし、既存のIDプロバイダーを信頼の起点として一元的に扱える点に特徴がある。
こうしたIDフェデレーションの考え方は、複数のクラウドやSaaSをまたいで従業員IDを管理する大企業で採用が広がっている。長期的な認証情報を持ち回らず、短命なトークンでアクセスを制御する方式は、ゼロトラストの潮流とも整合する。小売業は店舗やEコマース、サプライチェーンでデータとAIの活用を進めており、Best Buyの事例はその基盤を支える認証・アクセス管理の重要性を示すものと言える。
もっとも、こうした構成が実際にどの程度の効果をもたらすかは、既存のID運用体制や統合するシステムの規模によって異なる可能性がある。Best Buyのケースは、AIワークロードの拡張という需要と、それを支えるアクセス保護を両立させる一つのアプローチとして参考になりそうだ。
Best Buy, the large United States electronics retailer, has adopted Google Cloud's Workforce Identity Federation to govern how its backend engineering and analytics teams access cloud-based AI and data workloads. The move, detailed on the Google Cloud blog, is notable because it illustrates how a major enterprise is trying to scale advanced analytics and AI without expanding the operational and security burden that traditionally comes with managing large numbers of user accounts across two different identity systems.
According to the source, Best Buy's technology teams encountered two significant scaling challenges as they broadened their use of Google Cloud for advanced analytics and AI. The first was mitigating risk, and the second was managing administrative friction, both of which stemmed from the need to synchronize thousands of backend users from Microsoft Entra ID, Microsoft's cloud identity platform formerly known as Azure Active Directory. In many enterprises, Entra ID serves as the authoritative directory where employee identities, groups, and access policies are defined, so connecting it to a separate cloud provider is a common but non-trivial requirement.
The conventional approach to this problem is to synchronize or provision copies of user accounts from the source directory into the target cloud environment. That method works, but it creates duplicated identities that must be kept in step. Each additional copy of a user record represents another object to update, deprovision, and audit, and any drift between the two systems can become a security gap. As the number of synced users grows into the thousands, the administrative overhead and the attack surface tend to grow with it, which appears to be the situation Best Buy sought to avoid.
Workforce Identity Federation takes a different route. Rather than copying accounts into Google Cloud, federation allows an external identity provider such as Microsoft Entra ID to remain the single source of truth, while Google Cloud grants access based on tokens issued by that provider. Users authenticate against their existing corporate identity, and access to Google Cloud resources is brokered through short-lived credentials tied to their federated identity. Because there are no long-lived, duplicated accounts to maintain, this design is intended to reduce both the synchronization workload and the security risks associated with stale or orphaned credentials.
By eliminating the need to mirror backend users, Best Buy reports that it was able to remove much of the administrative friction and reduce risk, enabling it to securely scale its AI and analytics workloads on Google Cloud. The framing suggests the benefit is as much operational as it is security-related: fewer identity objects to manage frees technical teams to focus on building analytics and AI capabilities rather than maintaining identity plumbing. It is worth noting that these are the outcomes described by the retailer and the platform provider, and specific metrics on cost or time savings are not detailed in the excerpt.
The broader context is a continued industry shift toward federated, keyless, and short-lived credential models in cloud computing. Google Cloud has promoted Workforce Identity Federation alongside a related capability, Workload Identity Federation, which applies similar principles to non-human identities such as applications and automated services rather than employees. Both fit into a wider movement, often associated with zero-trust security, that favors verifying identity continuously and minimizing standing access. Competing platforms offer comparable federation features, reflecting a common recognition that credential sprawl is a meaningful risk as organizations spread workloads across multiple clouds.
For enterprises pursuing AI, identity is an increasingly important prerequisite rather than an afterthought. AI and analytics initiatives typically draw on sensitive datasets and require many engineers, data scientists, and pipelines to touch shared resources, which makes reliable, auditable access control foundational. Best Buy's decision to integrate Google Cloud with Microsoft Entra ID also highlights the reality that most large organizations operate heterogeneous, multi-vendor environments, and that interoperability between identity systems is often a practical necessity. As a documented customer example rather than a product launch, the Best Buy case is likely intended to serve as a reference for other retailers and enterprises weighing how to expand cloud-based AI while keeping access management sustainable and secure.
本ページの本文と要約は AI による自動生成です。日本語版と英語版は言語ごとに独立して生成されるため、表現や詳しさが異なる場合があります。正確性は元記事 (cloud.google.com) をご確認ください。The body and summaries are AI-generated independently for each language, so wording and detail may differ. Verify accuracy at the original source (cloud.google.com).




