Skip to content
All insights
ProtectMicrosoft 365ExplainerJuly 20, 2026

Running Google Workspace and Microsoft side by side

An IT manager at a fast-growing medical device company came to us with a clear ask: keep Google Workspace for email, Drive, and the day-to-day collaboration his team runs on, but manage and secure the fleet of laptops on Microsoft, using Defender, Intune, and zero-touch provisioning for a mostly remote workforce. Running the two side by side is a common request, and it works well, as long as you settle one thing first: identity.

Identity is the piece that decides everything

Microsoft's device and security tools don't run on their own. They key off a person's work identity, which in the Microsoft world lives in Entra ID (formerly Azure Active Directory). Google keeps its own directory too. Left alone, that's two separate identities for every employee, two directories that don't talk, and no single answer to who works at the company. That's the version of side by side that gets painful.

The version that works flips one thing: you make Entra ID the authoritative directory and put Google Workspace behind it with single sign-on (SSO). People sign in once through Microsoft and land in Google. Entra ID becomes the source of truth for who works there, and Google follows it.

What making Entra ID authoritative unlocks

Once Google authentication flows through Entra ID, the pieces the client wanted line up:

  • Zero-touch provisioning (Windows Autopilot), Intune device management, and Defender all key off the one identity, so a new laptop can configure and secure itself the first time someone signs in.
  • Conditional Access now applies to Google sign-ins. You can require a managed, compliant device before anyone reaches Google Workspace, so the same access rules that protect the rest of the environment also protect Gmail and Drive.

What you license, and what you can leave out

You don't have to buy the whole Microsoft 365 stack to do this. Email and files stay in Google, so Exchange Online and SharePoint can stay on the shelf. What you license is the identity, management, and security layer: Entra ID, Intune, and Defender. If you also want the desktop Office apps on those machines, Microsoft 365 Business Premium bundles all of it, identity, management, security, and the Office apps, at about $22 per user per month.

Layer Where it runs
Email, calendar, Drive, and Docs Google Workspace
Identity and single sign-on Entra ID, authoritative
Device setup and management Intune with Windows Autopilot
Endpoint security Defender
Access rules Conditional Access

One thing to name plainly: this is an addition, not a swap. You keep paying for Google Workspace and add the Microsoft security layer on top.

The overhead is real

Running both platforms means two sets of licenses. For a team built around Google, that added cost buys device management, endpoint security, and one set of access rules without moving anyone off the tools they know. It's a trade worth making on purpose, with the number in front of you.

What has to be true for it to hold up

A few assumptions sit under a clean side-by-side setup. Get them right up front and the arrangement stays quiet:

  • Provisioning has to be automated. Adding or removing someone in Entra ID should add or remove their Google access too. Without that, you are maintaining two directories by hand, and stale accounts are the usual result.
  • Offboarding runs through Entra ID. Because Google sits behind it, disabling someone's Entra identity should close the door on Google as well. Confirm that path works before you rely on it.
  • Keep a break-glass account. One cloud-only administrator account that does not depend on the federation, so a misconfigured sign-in rule can't lock you out of your own tenant.
  • Non-Windows devices need a plan. Autopilot covers Windows. Macs, iPhones, and Android devices enroll in Intune too, but through their own paths, so map those in if they are in scope.
The failure mode to avoid

The side-by-side setup goes wrong when the two directories never get connected. Federation and provisioning are the whole point. Skip them and you have two identities, two directories, and none of the automation. Connect them and the rest follows.

If you're weighing the same setup

Keeping Google Workspace and running security on Microsoft is a sound design when identity is settled first. If that's the direction you're leaning, we can map what stays in Google, what Entra ID takes over, what to license, and where the risks sit for your environment. Bring us your current setup and we'll lay out the coexistence design.

See where you stand. Then move forward.

Book a free intro call. We'll talk through where you are today and map a plan for growth, protection, automation, and alignment.

30 minutesNo obligationGet an initial estimate within one week