How to Configure SAML Authentication for Google Workspace

Item

Details

Pre-check

  • Prior configuration is required in Google Workspace.
  • If you are migrating from an organization-wide SSO profile (legacy procedure) to a new SSO profile, please also refer to the following page.
    Migrating from previous SSO to SSO profiles
  • You must create an account in Google Workspace using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by Google.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App (possible depending on the app)

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App (possible depending on the app)

SAML Authentication Scope

Enabled for everyone (SAML authentication only)

Other:
Enabled only for groups to which SAML authentication is applied on the SP side
Administrators (password authentication only)

Remarks

If you are using multiple services linked to Google, after completing the SAML configuration in this manual, please also refer to the following manual.
How to use one SAML authentication configuration for multiple apps

Table of Contents:

TrustLogin Admin Page Configuration

Google Workspace Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration


TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Enterprise App Registration" screen, search and select "Google Workspace (SAML)".
    google01.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", then download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to the configuration on the Google side.
Do not click the "Register" button yet — open the Google Workspace Admin console in a separate window.

Google Workspace Configuration

  1. From the menu, click "Add SAML profile" under "Security > Authentication > SSO with third-party IdP > Third-party SSO profiles".
    04.png

  2. Configure each item under "SAML SSO Profile" as follows, then click "Save" to save the settings.
    SSO Profile Name Any name of your choice (e.g., IdP name, name of the organizational unit to assign)
    IdP Entity ID The "Issuer/Entity ID" obtained from TrustLogin

    Sign-in Page URL

    The "IdP URL" obtained from TrustLogin
    Sign-out Page URL https://portal.trustlogin.com/
    Verification Certificate The "Certificate" obtained from TrustLogin

    05.png

  3. Copy and note down the "Entity ID" and "ACS URL" from the "SP Details" of the SSO profile you created.
    08.png

  4. Return to "SSO with third-party IdP" and click "Manage" under "Manage SSO profile assignments".
    (If you are configuring this item for the first time, click "Get Started" instead.)
    06.png

  5. Select the organizational unit or group to assign, and select the SSO profile you configured under "Select SSO profile".
    Select "Ask for Google username first, then redirect to this profile's IdP sign-in page" and click "Save" to save the settings.
    Google.png
    Note: By selecting "None" as the sign-in method, you can exclude the target organizational unit or group from SSO. This allows you to configure SSO on/off in detail for the entire organization, or for individual organizational units or groups.
    (Example) If you configure an SSO profile at the organizational-unit level and select "None" as the sign-in method for a group, users belonging to that group will not have SSO applied, even though SSO is enabled for the organizational unit.
    Note: If you want to allow SP-initiated sign-in with a password, select "Ask users to enter their Google username and password to sign in".

  6. Click the edit icon next to "Domain-specific service URL".
    10.png

  7. This controls the behavior when a user clicks an app from TrustLogin, or accesses a domain-specific service URL (e.g., https://mail.google.com/a/example.com).

    Automatically redirect users to the third-party IdP included in the following SSO profile
    Redirects to the IdP of the selected SSO profile. If a user clicks an app from TrustLogin, they can be taken directly to the service. However, do not select this setting if there are organizational units or groups to which SSO should not be applied.

    Ask users to enter their username on the Google sign-in page first
    Redirects to the Google sign-in page. After entering their email address, users subject to SSO are redirected to the IdP, while users not subject to SSO proceed to password entry.
    11.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL

    The URL of the service

    https://[subdomain of each service].google.com/a/[your primary domain]

    Example:
    https://mail.google.com/a/example.com
    https://calendar.google.com/a/example.com

    Note: If left blank, after SSO, users will be taken to the Google Account page.

    Entity ID The "Entity ID" obtained from Google Workspace
    ACS URL for the Service The "ACS URL" obtained from Google Workspace

    09.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "Google Workspace (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an administrator adds members

  1. From the "Admin Page > Apps" menu, search for and click the "Google Workspace (SAML)" app.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Google Workspace

Item

Details

Pre-check

  • Prior configuration is required in Google Workspace.
  • If you are migrating from an organization-wide SSO profile (legacy procedure) to a new SSO profile, please also refer to the following page.
    Migrating from previous SSO to SSO profiles
  • You must create an account in Google Workspace using the same email address as your TrustLogin account.
  • For the latest setup instructions, please refer to the manual provided by Google.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App (possible depending on the app)

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App (possible depending on the app)

SAML Authentication Scope

Enabled for everyone (SAML authentication only)

Other:
Enabled only for groups to which SAML authentication is applied on the SP side
Administrators (password authentication only)

Remarks

If you are using multiple services linked to Google, after completing the SAML configuration in this manual, please also refer to the following manual.
How to use one SAML authentication configuration for multiple apps

Table of Contents:

TrustLogin Admin Page Configuration

Google Workspace Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration


TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Enterprise App Registration" screen, search and select "Google Workspace (SAML)".
    google01.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", then download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to the configuration on the Google side.
Do not click the "Register" button yet — open the Google Workspace Admin console in a separate window.

Google Workspace Configuration

  1. From the menu, click "Add SAML profile" under "Security > Authentication > SSO with third-party IdP > Third-party SSO profiles".
    04.png

  2. Configure each item under "SAML SSO Profile" as follows, then click "Save" to save the settings.
    SSO Profile Name Any name of your choice (e.g., IdP name, name of the organizational unit to assign)
    IdP Entity ID The "Issuer/Entity ID" obtained from TrustLogin

    Sign-in Page URL

    The "IdP URL" obtained from TrustLogin
    Sign-out Page URL https://portal.trustlogin.com/
    Verification Certificate The "Certificate" obtained from TrustLogin

    05.png

  3. Copy and note down the "Entity ID" and "ACS URL" from the "SP Details" of the SSO profile you created.
    08.png

  4. Return to "SSO with third-party IdP" and click "Manage" under "Manage SSO profile assignments".
    (If you are configuring this item for the first time, click "Get Started" instead.)
    06.png

  5. Select the organizational unit or group to assign, and select the SSO profile you configured under "Select SSO profile".
    Select "Ask for Google username first, then redirect to this profile's IdP sign-in page" and click "Save" to save the settings.
    Google.png
    Note: By selecting "None" as the sign-in method, you can exclude the target organizational unit or group from SSO. This allows you to configure SSO on/off in detail for the entire organization, or for individual organizational units or groups.
    (Example) If you configure an SSO profile at the organizational-unit level and select "None" as the sign-in method for a group, users belonging to that group will not have SSO applied, even though SSO is enabled for the organizational unit.
    Note: If you want to allow SP-initiated sign-in with a password, select "Ask users to enter their Google username and password to sign in".

  6. Click the edit icon next to "Domain-specific service URL".
    10.png

  7. This controls the behavior when a user clicks an app from TrustLogin, or accesses a domain-specific service URL (e.g., https://mail.google.com/a/example.com).

    Automatically redirect users to the third-party IdP included in the following SSO profile
    Redirects to the IdP of the selected SSO profile. If a user clicks an app from TrustLogin, they can be taken directly to the service. However, do not select this setting if there are organizational units or groups to which SSO should not be applied.

    Ask users to enter their username on the Google sign-in page first
    Redirects to the Google sign-in page. After entering their email address, users subject to SSO are redirected to the IdP, while users not subject to SSO proceed to password entry.
    11.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL

    The URL of the service

    https://[subdomain of each service].google.com/a/[your primary domain]

    Example:
    https://mail.google.com/a/example.com
    https://calendar.google.com/a/example.com

    Note: If left blank, after SSO, users will be taken to the Google Account page.

    Entity ID The "Entity ID" obtained from Google Workspace
    ACS URL for the Service The "ACS URL" obtained from Google Workspace

    09.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "Google Workspace (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an administrator adds members

  1. From the "Admin Page > Apps" menu, search for and click the "Google Workspace (SAML)" app.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.