How to Configure Google Workspace (G Suite) External IdP Integration

This page explains how to configure Google Workspace (G Suite) as a SAML Identity Provider (IdP) and
integrate it with TrustLogin.

You will need to configure settings both in the Google Admin console and in the TrustLogin Admin Page.

Prerequisites

  • You must apply for TrustLogin's External IdP Integration option.
  • You must create a TrustLogin account using the same email address as your Google Workspace (G Suite) account.
    Note: If you integrate using the login ID, the email addresses do not need to match.
     Reference: NameID Settings for External IdP (SAML) Integration
  • TrustLogin's External IdP Integration only supports SP-Initiated SSO.
  • If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
    Note: We recommend assigning password authentication to administrator users in case of emergency.
     Reference: Configuring Password Authentication - Logging In with Both the IdP and TrustLogin Passwords

Setup Steps

Google Workspace (G Suite) Settings

Note: For the latest setup instructions, please refer to the manual provided by Google.
 Reference (external site): Google Workspace Admin Help "Set up your own custom SAML app"

  1. Open the Google Admin console.
  2. Click "Apps" → "Web and mobile apps" in that order.
  3. Click "Add app", then click "Add custom SAML app".

  4. Enter an app name of your choice, and click "Continue". You may optionally set a logo.
  5. Copy the SSO URL and Entity ID to your clipboard.
    Download the certificate, then click "Next".
    step2.png
  6. On the "Service provider details" screen, enter the following information.

    Item Setting Value / Details
    ACS URL https://portal.trustlogin.com/saml/acs
    Entity ID trustlogin-saml-sp
    Start URL No configuration needed.
    Signed response Check this box.
    Name ID Specify the user attribute to send as the NameID.
    Example: To integrate using the email address, select "Basic Information - Primary Email".
    Name ID format

    Specify the format to send as the NameID.

    Please also set the value you specified here to match the "NameID Format" on the TrustLogin side.

8. Click "Finish".
mceclip8.png

This completes the setup on the Google Workspace side.
Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to TrustLogin, and
    in the "Admin Page", open "Settings > Optional Features > External IdP Integration (SAML) > Settings".

  2. Open "Add SAML IDP".

  3. On the "Create SAML Identity Provider" screen, enter the following information.

    Item Setting Value / Details
    Name Enter any name of your choice.
    Example: Google Workspace
    SSO URL Google Workspace (G Suite) Settings > The "SSO URL" value you noted in step 6
    Entity ID Google Workspace (G Suite) Settings > The "Entity ID" value you noted in step 6
    SAML IDP Certificate Google Workspace (G Suite) Settings > The certificate information you downloaded in step 6
    Note: Open the certificate in a text editor and copy and paste the text.
    NameID Format Specify the format to send as the NameID.
    Google Workspace (G Suite) Settings > Select the value that matches the format you specified in step 8.

    Note: For details, seehere
    Preferred NameID Attribute Specify the member attribute to prioritize when matching the NameID.

    Note: For details, seehere
    Case-Sensitive Matching Specify whether to distinguish between uppercase and lowercase letters when matching the NameID.
    Note: For details, seehere

    ExternalIDPSAML_01.png

  4. Click "Register".
  5. Next, assign the members who will log in using their Google Workspace (G Suite) ID and password.
    From the External IdP list, click the name of the SAML IDP you just added.
  6. Click "Add Member". (If adding by group, click "Add Group".)SKUID__10_.png
  7. Select the target members and click the "Register" button.
  8. The member has been added.skuid10.png


    This completes the setup.


Verifying the Configuration

On the TrustLogin login page, when you enter your Company ID and email address, a Google Workspace (G Suite) button will appear.

Please log in using that button.

mceclip3.png

How to Configure Google Workspace (G Suite) External IdP Integration

This page explains how to configure Google Workspace (G Suite) as a SAML Identity Provider (IdP) and
integrate it with TrustLogin.

You will need to configure settings both in the Google Admin console and in the TrustLogin Admin Page.

Prerequisites

  • You must apply for TrustLogin's External IdP Integration option.
  • You must create a TrustLogin account using the same email address as your Google Workspace (G Suite) account.
    Note: If you integrate using the login ID, the email addresses do not need to match.
     Reference: NameID Settings for External IdP (SAML) Integration
  • TrustLogin's External IdP Integration only supports SP-Initiated SSO.
  • If you want to restrict the login method to SAML authentication only, you must remove members from the password authentication assignment.
    Note: We recommend assigning password authentication to administrator users in case of emergency.
     Reference: Configuring Password Authentication - Logging In with Both the IdP and TrustLogin Passwords

Setup Steps

Google Workspace (G Suite) Settings

Note: For the latest setup instructions, please refer to the manual provided by Google.
 Reference (external site): Google Workspace Admin Help "Set up your own custom SAML app"

  1. Open the Google Admin console.
  2. Click "Apps" → "Web and mobile apps" in that order.
  3. Click "Add app", then click "Add custom SAML app".

  4. Enter an app name of your choice, and click "Continue". You may optionally set a logo.
  5. Copy the SSO URL and Entity ID to your clipboard.
    Download the certificate, then click "Next".
    step2.png
  6. On the "Service provider details" screen, enter the following information.

    Item Setting Value / Details
    ACS URL https://portal.trustlogin.com/saml/acs
    Entity ID trustlogin-saml-sp
    Start URL No configuration needed.
    Signed response Check this box.
    Name ID Specify the user attribute to send as the NameID.
    Example: To integrate using the email address, select "Basic Information - Primary Email".
    Name ID format

    Specify the format to send as the NameID.

    Please also set the value you specified here to match the "NameID Format" on the TrustLogin side.

8. Click "Finish".
mceclip8.png

This completes the setup on the Google Workspace side.
Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to TrustLogin, and
    in the "Admin Page", open "Settings > Optional Features > External IdP Integration (SAML) > Settings".

  2. Open "Add SAML IDP".

  3. On the "Create SAML Identity Provider" screen, enter the following information.

    Item Setting Value / Details
    Name Enter any name of your choice.
    Example: Google Workspace
    SSO URL Google Workspace (G Suite) Settings > The "SSO URL" value you noted in step 6
    Entity ID Google Workspace (G Suite) Settings > The "Entity ID" value you noted in step 6
    SAML IDP Certificate Google Workspace (G Suite) Settings > The certificate information you downloaded in step 6
    Note: Open the certificate in a text editor and copy and paste the text.
    NameID Format Specify the format to send as the NameID.
    Google Workspace (G Suite) Settings > Select the value that matches the format you specified in step 8.

    Note: For details, seehere
    Preferred NameID Attribute Specify the member attribute to prioritize when matching the NameID.

    Note: For details, seehere
    Case-Sensitive Matching Specify whether to distinguish between uppercase and lowercase letters when matching the NameID.
    Note: For details, seehere

    ExternalIDPSAML_01.png

  4. Click "Register".
  5. Next, assign the members who will log in using their Google Workspace (G Suite) ID and password.
    From the External IdP list, click the name of the SAML IDP you just added.
  6. Click "Add Member". (If adding by group, click "Add Group".)SKUID__10_.png
  7. Select the target members and click the "Register" button.
  8. The member has been added.skuid10.png


    This completes the setup.


Verifying the Configuration

On the TrustLogin login page, when you enter your Company ID and email address, a Google Workspace (G Suite) button will appear.

Please log in using that button.

mceclip3.png