How to Configure Google Workspace to Exclude Some Users from SAML Authentication

Note: This setup assumes that SAML authentication has already been configured for Google Workspace.
How to Configure SAML Authentication for Google Workspace (G Suite) (For Organizations)
Google Workspace (G Suite) Integration

When you enable SAML authentication for Google Workspace, all users within your Google-side domain become subject to SAML authentication.

This article explains how to exclude some users who belong to a domain where SAML authentication is enabled
from SAML authentication (so they log in using their Google credentials instead).


Note: Please refer to the manual provided by Google for the latest setup instructions.

How to Assign SSO Profiles to Organizational Units or Groups

Create a User Group for SAML Management

  1. Open "Directory > Groups."
    image03.png

  2. Open "Create group."
    image04.png

  3. Set the group’s "Name" and "Email address," then click "Next."
    image05.png

  4. Click "Create group."
    image06.png

  5. Click "Add members to (the group name you set)."
    image07.png

  6. Open "Add members" and add the target members.
    image08.png
    image09.png

    Note:
    If you do not check the security checkbox in the group label when creating the group, you will not be able to specify this group when assigning an SSO profile, so please be careful.

Assign an SSO Profile to an Organizational Unit or Group

  1. From the menu, select "Security > Authentication > SSO with Third-Party IdP > Manage SSO Profile Assignments for Organizational Units or Groups," then click [Try it out].
    Note: [Try it out] only appears if a third-party SSO profile has already been enabled.

    __________SSO_____________1.png

  2. From the items on the left, select the organizational unit or group to which you want to assign the SSO profile.

    __________SSO_____________2.png

  3. Select the SSO profile to assign, then click "Save."

    Third-party SSO profile for the organization The third-party SSO profile settings are assigned to the organizational unit or group
    None The organizational unit or group is excluded from the third-party SSO profile settings
    Note: A user’s group settings always take precedence over organizational unit settings.
    If the same user is assigned a setting where the organizational unit’s SSO profile is enabled but the group’s SSO profile is disabled, the group’s setting takes precedence.

    __________SSO_____________3.png
  4. Setup complete

    __________SSO_____________4.png

How to Configure Google Workspace to Exclude Some Users from SAML Authentication

Note: This setup assumes that SAML authentication has already been configured for Google Workspace.
How to Configure SAML Authentication for Google Workspace (G Suite) (For Organizations)
Google Workspace (G Suite) Integration

When you enable SAML authentication for Google Workspace, all users within your Google-side domain become subject to SAML authentication.

This article explains how to exclude some users who belong to a domain where SAML authentication is enabled
from SAML authentication (so they log in using their Google credentials instead).


Note: Please refer to the manual provided by Google for the latest setup instructions.

How to Assign SSO Profiles to Organizational Units or Groups

Create a User Group for SAML Management

  1. Open "Directory > Groups."
    image03.png

  2. Open "Create group."
    image04.png

  3. Set the group’s "Name" and "Email address," then click "Next."
    image05.png

  4. Click "Create group."
    image06.png

  5. Click "Add members to (the group name you set)."
    image07.png

  6. Open "Add members" and add the target members.
    image08.png
    image09.png

    Note:
    If you do not check the security checkbox in the group label when creating the group, you will not be able to specify this group when assigning an SSO profile, so please be careful.

Assign an SSO Profile to an Organizational Unit or Group

  1. From the menu, select "Security > Authentication > SSO with Third-Party IdP > Manage SSO Profile Assignments for Organizational Units or Groups," then click [Try it out].
    Note: [Try it out] only appears if a third-party SSO profile has already been enabled.

    __________SSO_____________1.png

  2. From the items on the left, select the organizational unit or group to which you want to assign the SSO profile.

    __________SSO_____________2.png

  3. Select the SSO profile to assign, then click "Save."

    Third-party SSO profile for the organization The third-party SSO profile settings are assigned to the organizational unit or group
    None The organizational unit or group is excluded from the third-party SSO profile settings
    Note: A user’s group settings always take precedence over organizational unit settings.
    If the same user is assigned a setting where the organizational unit’s SSO profile is enabled but the group’s SSO profile is disabled, the group’s setting takes precedence.

    __________SSO_____________3.png
  4. Setup complete

    __________SSO_____________4.png