|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
Note: This manual describes the legacy configuration procedure for Google Workspace. Please check the following for how to migrate to the new SSO profile. Please refer to the following manual for how to configure this with TrustLogin.
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side settings |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion is not possible) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified device compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
※ |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
※ |
Android - Native app |
|
Note: Depends on the app
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Corporate App" screen, search for and select "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)".
-
Note the "IdP URL" value under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
- Configure the "Service Provider Settings".
For "Login URL", "Entity ID", and "ACS URL for Service", enter [the primary domain name registered with Google Workspace] in the red-boxed fields, and enter the URL of the Google service to redirect to after successful IdP-Initiated SSO authentication in the blue-boxed field of "Login URL".
https://accounts.google.com/a/[your_primary_domain]/ServiceLogin?continue=[service URL]
Example configuration:
Google Account Blank Gmail https://mail.google.com Google Calendar https://calendar.google.com Google Drive https://drive.google.com Google Meet https://meet.google.com/ Google Cloud Platform https://console.cloud.google.com/
Please check your Google Workspace primary domain name in the Admin console.
- Click the "Register" button.
Google Workspace Settings
Log in to the Google Admin console.
- From the menu, open "Security > Authentication > SSO with third-party IdP > Third-party SSO profile for your organization".
- Configure each item of the "Third-party SSO profile for your organization" as follows.
Set up SSO with third-party identity provider Check the box Sign-in page URL The "IdP URL" obtained from TrustLogin Sign-out page URL https://portal.trustlogin.com/ Verification certificate The "certificate" obtained from TrustLogin Use a domain-specific issuer Check the box
- Click "Save" to finish.
TrustLogin User Settings
① When a user adds it from My Page
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds a member
- On the "Admin Page > Apps" menu, search for and click the "Google Workspace (G Suite) (SAML PC/Mobile App Compatible)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.