Although Microsoft obviously wants you to do SSO from Azure to Google, the fact is that Azure AD is a flat-file mess while Google supports organizational units in their directory to separate users into distinct categories.
I am much happier managing users from the Google side so that I can utilize organizational units to manage user accounts.
Microsoft Active Directory supported organizational units for the last 30 years, but Microsoft dropped support for them when they started this new cloud based platform about a decade ago.
School District user account management:
OU: 0-Admin Accounts
OU: 1-Special Purpose Accounts
OU: Board of Education
OU: Community Learning Center
OU: Staff-Aides
OU: Staff-Coaches
OU: Staff-Custodians
OU: Staff-Foodservice
OU: Staff-Guidance
OU: Staff-Nurse
OU: Staff-Office Administration
OU: Staff-Psychologist
OU: Staff-Retired
OU: Staff-Speech Language
OU: Staff-Substitutes
OU: Staff-Teachers Elementary
OU: Staff-Teachers Middle School
OU: Staff-Teachers High School
OU: Staff-Teachers SPED-EL
OU: Staff-Teachers SPED-MS
OU: Staff-Teachers SPED-HS
OU: Students-2023-12
OU: Students-2024-11
OU: Students-2025-10
OU: Students-2026-09
OU: Students-2027-08
OU: Students-2028-07
OU: Students-2029-06
OU: Students-2030-05
OU: Students-2031-04
OU: Students-2032-03
OU: Students-2033-02
OU: Students-2034-01
OU: Students-2035-K
OU: Students-2036-PK
No way do I want to have to primarily manage school district user accounts in Microsoft's flat file mess, sorted exclusively alphabetically by Common Name.
(Oh and Azure AD can't handle loading the entire user list all at once, lol. Click "Load More" a hundred times. Horrible web user interface.)
What were you thinking Microsoft, removing the ability to use Organizational Units in Azure AD / Office 365 ???