I’m creating the integration between my GCP cloud and my Microsoft Entra ID so I can use Microsoft as the identity provider. However, when I go to IAM to set up the integration, Google requires me to create an organization. When I try to create it, I get a message saying that my account is not an organization administrator. The message is exactly: ‘This is not an administrator account for a Google Cloud organization. If you are the administrator of a company and have full control over that company’s Google Cloud resources, proceed with this task to create an administrator account. Otherwise, ask your company’s administrator to start this checklist.’
My account has Owner and Support User privileges. I’m starting everything from scratch and there are no other users in ‘My First Project’. It’s possible that someone in the past attempted to create the organization. I’d like to know whether I need to find out who tried to create the organization before me, and then add them to the project in order to create the organization. Or is there another way to create the organization, and do I need to add any additional permissions to my account besides Owner?
Yes, because to use SSO, either Okta or Entra, you have to have Organization. To have organization, you have to have Google Workspace and associated domain with it. So :
In Google Cloud, only a Google Workspace or Cloud Identity super admin can create or manage an organization resource. If your account is just a regular Google account with Owner role in a project, you won’t be able to create an organization until it’s tied to a verified domain under Workspace or Cloud Identity. The most direct path is to sign in with a super admin account for the domain you want to use, then follow Admin Console > Account > Domains to verify ownership, which will automatically create the organization in Cloud Console. If you don’t have a super admin account, you’ll need to work with whoever manages your Workspace/Cloud Identity domain to perform this step before you can set up Entra ID SSO.