Google Cloud Organization Setup with Cloud Identity Free - Create an Org and Move Your Projects Under It
When I started the Shared VPC lab I hit a wall on the very first command - gcloud compute shared-vpc enable simply does not work on a standalone project. Shared VPC, Organization Policies, folders, hierarchical firewall policies and org-level IAM all need one thing first - a Google Cloud Organization. And most of us who started with a personal Gmail account and a couple of projects do not have one.
So in this blog post we are going to give a domain (I am using my own, jhooq.com) a Google Cloud Organization using Cloud Identity Free - no cost and no Google Workspace subscription - verify the domain, and move the existing projects under the new organization. Everything after the org exists is scriptable with gcloud and Terraform, and I will show both.
Table of Content
- What is a Google Cloud Organization and why do you need one?
- Three things to know before you start
- Build it step by step (diagrams and commands for every step)
- The complete walkthrough - Cloud Identity signup, domain verification, gcloud
- Terraform - reference the organization, grant IAM, create folders
- Common problems
- Conclusion and what to read next
1. What is a Google Cloud Organization and why do you need one?
A Google Cloud Organization is the root of the resource hierarchy - the parent node above all your folders and projects. You do not create it directly. It is provisioned automatically the moment you set up Cloud Identity (or Google Workspace) for a domain you own.
Here is the resource hierarchy with and without an organization -
1# without an organization (what most personal accounts look like)
2Project: cl-demo-sandbox
3Project: cl-demo-sandboxcli # standalone, no parent
4
5# with an organization
6Organization: jhooq.com (123456789012)
7├── Folder: prod
8│ └── Project: cl-demo-sandbox
9└── Project: cl-demo-sandboxcli
Once the organization exists, it unlocks the whole governance layer, none of which works on standalone projects -
- Shared VPC - one host project lends its network to service projects. Needs an org, full stop.
- Organization Policies - constraints like "no public IPs on VMs" or "no service account keys" enforced on every project below.
- Folders - group projects by team or environment, and grant IAM once at the folder level.
- Hierarchical firewall policies - firewall rules enforced from the org or folder down.
- Org-level IAM, logging and billing export - one place to see and control everything.
If you only have one project and no plans to share networks, you do not need an organization. The moment there is a second team, a second environment or a compliance requirement, you do.
2. Three things to know before you start
1. Your email is safe. Cloud Identity Free does not host email. As long as you do not change your domain's MX records, your existing mailboxes keep working exactly as before. The admin account you create is a login identity only, it has no mailbox.
2. Use a dedicated super-admin, for example admin@yourdomain.com, not your everyday login. It keeps the org owner clean, and it avoids the "unmanaged account" tangle where your personal Google account and the organization account fight over the same email address.
3. The signup and domain verification are console and DNS steps, not gcloud or Terraform. But everything after the org exists - IAM, moving projects, folders, policies - is fully scriptable.
3. Build it step by step (diagrams and commands for every step)
Six steps - the first two are in the browser (Cloud Identity signup and the DNS record), the rest are gcloud. Click a step in the rail or use Prev / Next or the arrow keys, and click a diagram to zoom.
# UI step — a console signup wizard, not gcloud. Use the DIRECT link so you
# land on the FREE edition (not a paid Workspace trial):
# → workspace.google.com/gcpidentity/signup
#
# 1. Business details → domain: jhooq.com
# 2. Create admin account → admin@jhooq.com (+ strong password) ← must finish
# 3. Add a recovery email/phone (super-admin can't be recovered without it)
#
# 💡 Cloud Identity Free = $0, up to 50 users, gives you the Organization node.
# ⚠️ Skip the 14-day Workspace trial if the funnel offers it.
# ⚠️ do NOT change jhooq.com MX records — Cloud Identity Free doesn't host email.# add the TXT record Google gives you, at SiteGround DNS:
# TXT @ google-site-verification=XXXXXXXXXXXX
dig TXT jhooq.com +short# GCP auto-provisions the org once the domain verifies
gcloud organizations list
ORG_ID=$(gcloud organizations list --format="value(ID)")# the org already exists — just read it
data "google_organization" "org" {
domain = "jhooq.com"
}gcloud organizations add-iam-policy-binding "$ORG_ID" \
--member="user:admin@jhooq.com" \
--role="roles/resourcemanager.organizationAdmin"resource "google_organization_iam_member" "admin" {
org_id = data.google_organization.org.org_id
role = "roles/resourcemanager.organizationAdmin"
member = "user:admin@jhooq.com"
}gcloud beta projects move cl-demo-sandbox --organization="$ORG_ID"
gcloud beta projects move cl-demo-sandboxcli --organization="$ORG_ID"# a NEW project can be created directly under the org:
resource "google_project" "demo" {
name = "cl-demo-sandbox"
project_id = "cl-demo-sandbox"
org_id = data.google_organization.org.org_id
billing_account = "YOUR_BILLING_ACCOUNT_ID"
}
# existing standalone projects: use `gcloud beta projects move` (above),
# then reconcile org_id in code.gcloud projects list --filter="parent.id=$ORG_ID" \
--format="table(projectId, parent.type, parent.id)"
gcloud organizations describe "$ORG_ID"4. The complete walkthrough - Cloud Identity signup, domain verification, gcloud
Steps 1 and 2 are a console wizard plus one DNS record (the org cannot be created by gcloud). Everything after that is a command.
Give jhooq.com an Organization and move your projects under it. Steps 1–2 are a console/DNS signup (the org can't be created by gcloud); everything after the org exists is scriptable.
1 · Sign up for Cloud Identity Free
This is a console wizard, not a command. Use the direct link so you land on the free edition instead of a paid Workspace trial:
→ workspace.google.com/gcpidentity/signup
Walk through the wizard:
- Business details — enter your domain jhooq.com (the domain you actually own).
- Create your admin account — pick a dedicated super-admin username, e.g. admin@jhooq.com,
and set a strong password. This is the account you'll use at
admin.google.comand forgcloud— finish this step or no account gets provisioned. - Add a recovery email/phone when offered — a super-admin can't be recovered later without one.
- Finish → you're dropped into the Google Admin console (
admin.google.com).
💡 It's free — $0. Cloud Identity Free covers up to 50 users and gives you the Organization node, which is all you need for Shared VPC, folders, org policies and hierarchical firewall. You do not need paid Google Workspace.
⚠️ Skip the Workspace trial. If the funnel asks "does your business already use Gmail?", choose the path that keeps you on Cloud Identity — don't start the 14-day Workspace trial. The link above lands on the free edition directly.
⚠️ Don't change jhooq.com's MX records. Cloud Identity Free doesn't host email — leaving MX untouched keeps your existing mailboxes and SES sending fully intact.
admin@jhooq.comis a login identity only (no mailbox).
🛠 "Account already exists" / it bounces to a personal login? An old consumer Google account is using an address on this domain. Use the wizard's conflicting-account (Transfer) tool to claim it before continuing.
2 · Verify you own the domain
Google gives you a TXT value. Add it to jhooq.com's DNS (wherever your DNS is hosted - for jhooq.com that is Route 53, for you it may be Cloudflare, GoDaddy or Namecheap), then confirm it resolves:
1# record to add at your DNS provider: TXT @ google-site-verification=XXXXXXXXXXXX
2dig TXT jhooq.com +short
3 · The Organization is created
Once the domain verifies, GCP provisions the org node automatically. Grab its ID:
1gcloud organizations list
2# DISPLAY_NAME ID DIRECTORY_CUSTOMER_ID
3# jhooq.com 123456789012 C0abcd123
4
5ORG_ID=$(gcloud organizations list --format="value(ID)")
4 · Grant Organization Administrator
Give your admin the role that lets you manage the org, folders, IAM and policies:
1gcloud organizations add-iam-policy-binding "$ORG_ID" \
2 --member="user:admin@jhooq.com" \
3 --role="roles/resourcemanager.organizationAdmin"
5 · Move your projects under the org
1gcloud beta projects move cl-demo-sandbox --organization="$ORG_ID"
2gcloud beta projects move cl-demo-sandboxcli --organization="$ORG_ID"
6 · Verify the hierarchy
1gcloud projects list --filter="parent.id=$ORG_ID" \
2 --format="table(projectId, parent.type, parent.id)"
3gcloud organizations describe "$ORG_ID"
Both projects should now show parent.type: organization. That's the foundation — you can now
do Shared VPC, Organization Policies, hierarchical firewall, folders, and
org-level logging.
5. Terraform - reference the organization, grant IAM, create folders
The signup and the domain verification cannot be Terraformed, Google provisions the org for you. But everything after the org exists is code - read the org with a data source, grant IAM, create folders and place projects. If you are new to Terraform on Google Cloud, my post on deploying to Google Cloud Run with Terraform covers setting up the provider and a deployer service account.
The signup + domain verification can't be Terraformed — Google provisions the org once you set up Cloud Identity. But everything after the org exists is code: reference the org, grant IAM, create folders, and place projects.
providers.tf
1provider "google" {
2 region = "europe-north2"
3}
org.tf — reference the org and grant admin
1# the org already exists (created by Cloud Identity) — just read it
2data "google_organization" "org" {
3 domain = "jhooq.com"
4}
5
6resource "google_organization_iam_member" "admin" {
7 org_id = data.google_organization.org.org_id
8 role = "roles/resourcemanager.organizationAdmin"
9 member = "user:admin@jhooq.com"
10}
projects.tf — new vs existing
A new project can be created directly under the org:
1resource "google_project" "demo" {
2 name = "cl-demo-sandbox"
3 project_id = "cl-demo-sandbox"
4 org_id = data.google_organization.org.org_id
5 billing_account = "YOUR_BILLING_ACCOUNT_ID"
6}
For existing standalone projects, Terraform can't "move" them without first importing their
state — in practice the one-liner gcloud beta projects move <id> --organization=$ORG_ID is the
clean way, then reconcile with org_id in code afterwards.
folders.tf — organize (the next step in the series)
1resource "google_folder" "prod" {
2 display_name = "prod"
3 parent = data.google_organization.org.name # organizations/<ORG_ID>
4}
Tip: grant IAM to Google Groups at the org/folder level (e.g. group:gcp-admins@jhooq.com)
rather than individual users — it inherits down the whole hierarchy and is far easier to audit.
6. Common problems
1. The signup wants to start a Google Workspace trial - Use the direct Cloud Identity link from step 1. If the funnel asks whether your business already uses Gmail, pick the option that keeps you on Cloud Identity. You do not need Workspace for an organization.
2. "An account with this email already exists" - Somebody (probably you, years ago) created a consumer Google account with an address on your domain. The wizard offers a conflicting-account transfer tool to claim it. Do that before continuing, otherwise you end up with an unmanaged account outside the org.
3. Domain verification never completes - The TXT record is not published yet or you added it on the wrong name. It has to be on the apex (@), and dig TXT yourdomain.com +short must show the google-site-verification=... value. DNS propagation can take up to an hour.
4. gcloud organizations list is empty - You are logged in with your personal account, not the new super-admin. Run gcloud auth login admin@yourdomain.com.
5. gcloud beta projects move fails with a permission error - The super-admin needs roles/resourcemanager.organizationAdmin on the org (step 4) and roles/resourcemanager.projectMover or Owner on the project being moved. A project created under your personal account has your personal account as Owner, not the new admin - grant the admin Owner on the project first.
6. The project is under the org but Shared VPC still fails - Both the host and the service project must be under the same organization. Check with gcloud projects get-ancestors <project-id>.
7. Conclusion and what to read next
Creating a Google Cloud Organization is a one-time, free setup, and it is the step which turns a pile of personal projects into something you can govern. To summarise -
- Cloud Identity Free gives you the Organization node at no cost - you do not need Google Workspace.
- Keep your MX records untouched and use a dedicated super-admin account.
- Once the org exists, grant
organizationAdmin, move your projects withgcloud beta projects move, and manage the rest in Terraform.
Now that you have an organization, the next post in the series is the one this was all for - Google Cloud Shared VPC - one network, many projects.
The Google Cloud networking series -
- Google Cloud VPC peering - hub and spoke
- Google Cloud cross-project VPC peering
- Google Cloud Organization setup with Cloud Identity (this post)
- Google Cloud Shared VPC - one network, many projects
- Google Cloud Private Service Connect - publish one service privately
Posts in this series
- Google Cloud Private Service Connect (PSC) Explained - Publish a Service with a Service Attachment and Consume It Through a PSC Endpoint
- Google Cloud Shared VPC Explained - Host Project, Service Project, networkUser and Cloud NAT (gcloud and Terraform)
- Google Cloud Organization Setup with Cloud Identity Free - Create an Org and Move Your Projects Under It
- Google Cloud Cross-Project VPC Peering - Peer Two VPCs in Different Projects (gcloud and Terraform)
- Google Cloud VPC Peering - Hub and Spoke Setup Step by Step with gcloud and Terraform