Google Cloud Platform Administration for IT Teams Training Course
| Course code | SD-CC-012 |
|---|---|
| Duration | 5 days |
| Level | Intermediate to Advanced |
| Category | Cloud Computing |
| Delivery | Classroom or live online |
| Language | English |
| Certificate | Certificate of completion |
Course overview
Google Cloud administrators must turn project requests into controlled, supportable environments without slowing delivery. That means designing resource hierarchies that match the business, applying least-privilege access, connecting networks safely, monitoring services before incidents become outages, and controlling spend across multiple projects. This course addresses the operational gap between knowing individual Google Cloud services and administering a governed Google Cloud estate for teams, applications and shared platforms.
Participants work through the administration practices used to operate Google Cloud Platform at scale: organisations, folders, projects, billing accounts, IAM roles and service accounts; VPC design, firewall rules, Cloud VPN and private access; Compute Engine, Cloud Storage and managed services; logging, monitoring, alerting and incident investigation. They also apply organisation policies, Security Command Center findings, quotas, labels, budgets and Terraform-based infrastructure workflows. The emphasis is on making sound operational decisions, documenting controls and diagnosing common platform failures with Google Cloud Console and gcloud.
Instructor demonstrations are followed by guided configuration labs, troubleshooting scenarios and team design reviews using a realistic multi-project company environment. Participants finish by producing a Google Cloud administration runbook containing a resource hierarchy, IAM model, network baseline, monitoring and alerting plan, cost-control measures, and an operational handover checklist. This practical artefact gives attendees a structured starting point for improving their own Google Cloud operations after the course.
The course is suited to IT professionals who already support cloud-hosted workloads and now need responsibility for Google Cloud governance, operations or platform administration. It is particularly valuable where teams are moving from isolated projects to centrally managed landing zones and repeatable controls.
Course objectives
By the end of this course, participants will be able to:
- Design an organisation, folder and project hierarchy aligned to business units, environments and delegated administration
- Configure IAM roles, groups, service accounts and workload identity controls using least-privilege principles
- Build a VPC network baseline with subnets, firewall rules, Cloud NAT, private Google access and hybrid connectivity options
- Administer Compute Engine instances, Cloud Storage buckets and managed service access using operational configuration standards
- Investigate service health and application incidents with Cloud Logging, Cloud Monitoring dashboards, alerts and log queries
- Apply organisation policies, Security Command Center findings, audit logs and quota controls to reduce platform risk
- Create budgets, labels, billing reports and cost-allocation rules for multi-project cloud spend management
- Produce a Google Cloud administration runbook with governance, operational, monitoring and escalation procedures
Benefits of attending
For you
- Gain evidence-based confidence administering multi-project Google Cloud environments rather than isolated services
- Build a reusable administration runbook that can support a cloud operations or platform engineering portfolio
- Develop practical fluency with Google Cloud Console, gcloud, Cloud Monitoring and Terraform workflows
- Strengthen credibility when advising teams on IAM, networking, auditability, resilience and cloud cost controls
- Prepare for broader responsibilities in Google Cloud platform administration, cloud operations and infrastructure leadership
For your organisation
- Establish more consistent project, folder and billing-account structures across Google Cloud workloads
- Reduce excessive access and configuration drift through stronger IAM, service-account and organisation-policy practices
- Improve incident response through usable dashboards, alerts, audit logs and documented escalation procedures
- Increase visibility of cloud expenditure with labels, budgets and accountable cost-allocation conventions
- Create a repeatable operational baseline that enables application teams to consume Google Cloud with fewer support delays
Target competencies
Who should attend
- Cloud Administrators — who configure and support Google Cloud projects, identities, networks and shared services
- Systems Administrators — who are extending on-premises operational responsibilities into Google Cloud
- Platform Engineers — who need repeatable governance and operational standards for internal cloud consumers
- DevOps Engineers — who manage deployment environments and need to work within secure Google Cloud controls
- IT Infrastructure Managers — who oversee cloud operations, access governance, resilience and service performance
- Security Engineers — who need to review IAM, organisation policies, audit evidence and cloud security findings
Requirements and prerequisites
Participants should have practical experience administering IT systems and a working understanding of TCP/IP networking, DNS, identity and access management, Linux or Windows command-line administration, and virtual machines. Familiarity with public-cloud concepts such as regions, zones, virtual networks, compute instances, object storage and role-based access control is assumed. Attendees should be able to navigate a browser-based management console and read basic command output. Previous Google Cloud certification, Terraform experience and software development skills are not required. The course teaches gcloud and Terraform administration workflows from an operational, rather than programming, perspective.
Training methodology
The course combines instructor-led architecture sessions with guided administration labs in a realistic multi-project Google Cloud environment. Participants configure policies, IAM, networks, compute resources, budgets and observability controls using Google Cloud Console and gcloud, then inspect the operational consequences through troubleshooting scenarios. Small-group reviews test design choices against security, resilience and cost constraints. Each day closes with a practical artefact, and the final workshop consolidates these into an administration runbook and prioritised action plan for the participant's own environment.
Course outline
Day 1: Google Cloud foundations and governance structure
- Google Cloud resource hierarchy: organisation, folders, projects and resources
- Resource Manager inheritance and delegated administration boundaries
- Cloud Billing accounts, project linkage and billing permissions
- IAM principals, predefined roles, custom roles and policy inheritance
- Google Groups and service-account governance patterns
- Organisation Policy Service constraints and policy enforcement
- Google Cloud Console and gcloud CLI administration workflows
Workshop: Build a multi-department organisation hierarchy with folders, projects, groups, delegated IAM roles and selected organisation policies.
Day 2: Networks, connectivity and workload administration
- VPC architecture, auto-mode versus custom-mode networks and subnet planning
- Firewall rules, hierarchical firewall policies and network tags
- Cloud Router, Cloud NAT and controlled outbound internet access
- Private Google Access and Private Service Connect use cases
- Cloud VPN and Cloud Interconnect hybrid connectivity design choices
- Compute Engine instance administration, machine types and instance templates
- Cloud Storage buckets, retention policies, lifecycle rules and access controls
Workshop: Configure a segmented VPC baseline for development and production workloads, including firewall policy, private access and Cloud NAT.
Day 3: Identity, security controls and compliance evidence
- Least-privilege IAM design for administrators, developers and service accounts
- Service account keys, impersonation and Workload Identity Federation
- Cloud Audit Logs configuration, retention and administrative activity review
- Security Command Center findings, severity triage and remediation workflows
- Secret Manager administration and application secret access patterns
- VPC Service Controls service perimeters and data exfiltration controls
- Quotas, API enablement and controlled service consumption
Workshop: Investigate a simulated access-control and security-finding case, then document corrective IAM, logging and policy actions.
Day 4: Observability, reliability and operational response
- Cloud Monitoring metrics, monitored resources and service-level indicators
- Cloud Logging log buckets, sinks, retention and log-based metrics
- Monitoring dashboards for infrastructure and application operations
- Alerting policies, notification channels and alert-noise reduction
- Logs Explorer queries for incident investigation and root-cause analysis
- Uptime checks, synthetic monitoring and availability validation
- Backup, recovery and regional resilience considerations for Google Cloud services
Workshop: Create an operations dashboard and alert policy set, then use logs and metrics to diagnose a simulated service degradation.
Day 5: Cost control, automation and administration runbooks
- Billing reports, cost tables, labels and project-level cost allocation
- Cloud Billing budgets, threshold alerts and anomaly investigation
- Rightsizing Compute Engine and managing idle-resource costs
- Terraform state, providers, modules and plan-review workflow
- Infrastructure-as-code controls for repeatable Google Cloud administration
- Operational runbooks, change records and escalation paths
- Landing-zone improvement roadmap and governance maturity priorities
Workshop: Produce a Google Cloud administration runbook and 90-day improvement plan covering governance, operations, observability and cost controls.
Tools & standards covered
Google Cloud Console, gcloud CLI, Terraform, Google Cloud Monitoring
A typical training day
| 08:30 – 10:30 | First session |
| 10:30 – 10:45 | Refreshment break |
| 10:45 – 12:30 | Second session |
| 12:30 – 13:30 | Lunch and networking |
| 13:30 – 15:00 | Third session |
| 15:00 – 15:15 | Refreshment break |
| 15:15 – 16:30 | Workshop and daily review |
Live online deliveries follow the same structure in the East Africa Time zone, with shorter screen blocks and longer breaks.
What the fee includes
- Instruction by a practitioner facilitator
- Full course workbook and materials
- Exercise files, templates and case studies
- Certificate of completion
- Refreshments and lunch (classroom deliveries)
- Post-course application plan
- Facilitator follow-up on request
- Group rates from five participants
How you can take this course
Classroom
Scheduled sessions in Nairobi, Mombasa, Kigali, Dar es Salaam, Dubai and Cape Town.
Live online
The same facilitator and materials, delivered live for distributed teams and individuals.
In-house
Delivered privately for your team, at your offices or a venue of your choice, tailored to your context. Request a proposal.
Certification
Participants who complete the full five days receive the Skillset Development Certificate of Completion, stating the course title, course code, dates and delivery format — suitable for professional-development records and employer reimbursement.
Frequently asked questions
Upcoming sessions
New dates are being scheduled. Ask us about the next session or an in-house delivery for your team.
Ask about datesGroup of 5+?
Request in-house delivery or group rates →Related courses in Cloud Computing
NIST Cybersecurity Framework for Cloud Security Training Course
Cloud programmes often accumulate controls without a clear way to demonstrate that identity, data protection, monitoring, recovery, and supp…
Cloud Security Alliance CCM Controls Implementation Training Course
Cloud security programmes often contain sound policies but lack a consistent way to translate cloud risks, provider assurances and technical…
Cloud Operations Skills for DevOps Engineers Training Course
DevOps engineers are often expected to operate cloud platforms that change every day: Kubernetes workloads scale unexpectedly, Terraform pla…
Ansible Cloud Automation for Infrastructure Teams Training Course
Infrastructure teams are often asked to provision cloud environments quickly while maintaining consistent security controls, naming standard…