How to Configure SAML Authentication for Google Workspace (Legacy Procedure)

Item

Details

Prerequisites

Note: This manual describes the legacy configuration procedure for Google Workspace. Please check the following for how to migrate to the new SSO profile.
Migrating from a legacy SSO to an SSO profile

Please refer to the following manual for how to configure this with TrustLogin.
How to Configure SAML Authentication for Google Workspace

  • Prior configuration in Google Workspace is required.

  • You must create an account in Google Workspace using the same email address as your TrustLogin account.

  • This manual covers the case where users within your organization perform SSO using the same IdP (TrustLogin).
  • Enabling the SSO profile for your organization makes all users in the domain subject to SAML SSO.
    If you want to exclude some users from SAML SSO, please refer to the following manual.
    How to Exclude Some Users from SAML Authentication in Google Workspace

  • If another IdP has already been configured as your organization's SSO profile on the Google side and you want to configure TrustLogin as an additional SSO profile, or if you want to configure multiple IdPs, please refer to the following manual.
    How to Configure SAML Authentication for Google Workspace (Multiple IdP Support)
  • If you use multiple services linked to Google, please also refer to the following manual after completing the SAML configuration described in this manual.
    How to Use a Single SAML Authentication Configuration for Multiple Apps
  • For the latest configuration procedure, please check the manual provided by Google.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion is not possible)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: Depends on the app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)".
    02.png

  3. Note the "IdP URL" value under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Configure the "Service Provider Settings".

    For "Login URL", "Entity ID", and "ACS URL for Service", enter [the primary domain name registered with Google Workspace] in the red-boxed fields, and enter the URL of the Google service to redirect to after successful IdP-Initiated SSO authentication in the blue-boxed field of "Login URL".

    https://accounts.google.com/a/[your_primary_domain]/ServiceLogin?continue=[service URL]

    Example configuration:

    Google Account Blank
    Gmail https://mail.google.com
    Google Calendar https://calendar.google.com
    Google Drive https://drive.google.com
    Google Meet https://meet.google.com/
    Google Cloud Platform https://console.cloud.google.com/

    Please check your Google Workspace primary domain name in the Admin console.

    2019-08-01_1_58.png

  5. Click the "Register" button.

Google Workspace Settings

Log in to the Google Admin console.

  1. From the menu, open "Security > Authentication > SSO with third-party IdP > Third-party SSO profile for your organization".
    05.png

  2. Configure each item of the "Third-party SSO profile for your organization" as follows.
    Set up SSO with third-party identity provider Check the box
    Sign-in page URL The "IdP URL" obtained from TrustLogin
    Sign-out page URL https://portal.trustlogin.com/
    Verification certificate The "certificate" obtained from TrustLogin
    Use a domain-specific issuer Check the box

    06 (1).png

  3. Click "Save" to finish.

TrustLogin User Settings

① When a user adds it from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. On the "Admin Page > Apps" menu, search for and click the "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Google Workspace (Legacy Procedure)

Item

Details

Prerequisites

Note: This manual describes the legacy configuration procedure for Google Workspace. Please check the following for how to migrate to the new SSO profile.
Migrating from a legacy SSO to an SSO profile

Please refer to the following manual for how to configure this with TrustLogin.
How to Configure SAML Authentication for Google Workspace

  • Prior configuration in Google Workspace is required.

  • You must create an account in Google Workspace using the same email address as your TrustLogin account.

  • This manual covers the case where users within your organization perform SSO using the same IdP (TrustLogin).
  • Enabling the SSO profile for your organization makes all users in the domain subject to SAML SSO.
    If you want to exclude some users from SAML SSO, please refer to the following manual.
    How to Exclude Some Users from SAML Authentication in Google Workspace

  • If another IdP has already been configured as your organization's SSO profile on the Google side and you want to configure TrustLogin as an additional SSO profile, or if you want to configure multiple IdPs, please refer to the following manual.
    How to Configure SAML Authentication for Google Workspace (Multiple IdP Support)
  • If you use multiple services linked to Google, please also refer to the following manual after completing the SAML configuration described in this manual.
    How to Use a Single SAML Authentication Configuration for Multiple Apps
  • For the latest configuration procedure, please check the manual provided by Google.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion is not possible)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified device compatibility

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: Depends on the app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)".
    02.png

  3. Note the "IdP URL" value under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Configure the "Service Provider Settings".

    For "Login URL", "Entity ID", and "ACS URL for Service", enter [the primary domain name registered with Google Workspace] in the red-boxed fields, and enter the URL of the Google service to redirect to after successful IdP-Initiated SSO authentication in the blue-boxed field of "Login URL".

    https://accounts.google.com/a/[your_primary_domain]/ServiceLogin?continue=[service URL]

    Example configuration:

    Google Account Blank
    Gmail https://mail.google.com
    Google Calendar https://calendar.google.com
    Google Drive https://drive.google.com
    Google Meet https://meet.google.com/
    Google Cloud Platform https://console.cloud.google.com/

    Please check your Google Workspace primary domain name in the Admin console.

    2019-08-01_1_58.png

  5. Click the "Register" button.

Google Workspace Settings

Log in to the Google Admin console.

  1. From the menu, open "Security > Authentication > SSO with third-party IdP > Third-party SSO profile for your organization".
    05.png

  2. Configure each item of the "Third-party SSO profile for your organization" as follows.
    Set up SSO with third-party identity provider Check the box
    Sign-in page URL The "IdP URL" obtained from TrustLogin
    Sign-out page URL https://portal.trustlogin.com/
    Verification certificate The "certificate" obtained from TrustLogin
    Use a domain-specific issuer Check the box

    06 (1).png

  3. Click "Save" to finish.

TrustLogin User Settings

① When a user adds it from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. On the "Admin Page > Apps" menu, search for and click the "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.