Initial Setup Steps for Identity Provisioning with Google

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Google Workspace.

Note: For detailed instructions on operating Google Workspace , please refer to the manual provided by Google .

Item

Details

Pre-check

Table of Contents

Note: After connecting TrustLogin and Google Workspace using the steps on this page,
 please proceed to configuring user synchronization.

Provisioning Target

Supports user provisioning

Supports group provisioning

SAML Authentication Setup Manual

How to Configure SAML Authentication for Google Workspace

  • You can link the Identity Provisioning configuration created in this procedure with an existing SAML app.
    For details on SAML app configuration, please checkhere.

Notes

  • None in particular

Setup Steps

Google Settings

  1. Log in to Google Cloud APIs (external site: https://console.cloud.google.com/apis) with administrator privileges,
    and click "Admin SDK API" from the "Enabled APIs & services" tab.
    google_IDProv_01.png

  2. Click "Enable". 
    google_IDProv_02.png
  3. Open the "Credentials" tab, and select "OAuth client ID" from the "Create Credentials" button.
    google_IDProv_03.png
  4. On the "Create OAuth client ID" screen, configure the following settings, and click the "Create" button.

    Application type Select "Web application"
    Name Set any name of your choice
    Authorized redirect URIs

    Enter the following value:

    https://portal.trustlogin.com/id_prov_callback

    google_IDProv_04.png

  5. From the window that is displayed, copy the following values.

    • Client ID
    • Client secret

    google_IDProv_05.png

This completes the preliminary preparation on the Google side. Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png

  2. Click "Add Service".
    IDProvServiceCommon02.png

  3. Search for "Google", select it, and click the "Add" button.
    google_IDProv_06.png
  4. You will be redirected to the "Identity Provisioning > Google" page.
    Click the "Edit" button.
    google_IDProv_07.png
  5. Open "Access Settings", enter the following values for each setting item, and click "Save".

    Connection URL The verified Google Workspace domain name
    Client ID Issued and copied in Google Settings > Step 5
    Client secret Issued and copied in Google Settings > Step 5

    google_IDProv_12.png

  6. Click the "Connect" button.
    google_IDProv_08.png
  7. Click "Yes".
    google_IDProv_09.png
  8. You will be redirected to the Google page.
    Click "Allow". (Super administrator privileges are required.)
    google_IDProv_10.png
  9. Once the button status updates to "Connected", the initial setup is complete.
    google_IDProv_11.png

Next step: The manual for configuring user synchronization is available here

Values You Can Configure in Attribute Mapping

The values that can be specified as Google's default functions are as follows.

Value Description
Full name The full name with the last name first.
Full name with first name first The full name with the first name first.
Username from email Retrieves the portion of the email address before the "@" symbol, limited to a maximum of 21 characters.

Note: For an overview of the attribute mapping feature and how to configure it, please see here.


Initial Setup Steps for Identity Provisioning with Google

This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Google Workspace.

Note: For detailed instructions on operating Google Workspace , please refer to the manual provided by Google .

Item

Details

Pre-check

Table of Contents

Note: After connecting TrustLogin and Google Workspace using the steps on this page,
 please proceed to configuring user synchronization.

Provisioning Target

Supports user provisioning

Supports group provisioning

SAML Authentication Setup Manual

How to Configure SAML Authentication for Google Workspace

  • You can link the Identity Provisioning configuration created in this procedure with an existing SAML app.
    For details on SAML app configuration, please checkhere.

Notes

  • None in particular

Setup Steps

Google Settings

  1. Log in to Google Cloud APIs (external site: https://console.cloud.google.com/apis) with administrator privileges,
    and click "Admin SDK API" from the "Enabled APIs & services" tab.
    google_IDProv_01.png

  2. Click "Enable". 
    google_IDProv_02.png
  3. Open the "Credentials" tab, and select "OAuth client ID" from the "Create Credentials" button.
    google_IDProv_03.png
  4. On the "Create OAuth client ID" screen, configure the following settings, and click the "Create" button.

    Application type Select "Web application"
    Name Set any name of your choice
    Authorized redirect URIs

    Enter the following value:

    https://portal.trustlogin.com/id_prov_callback

    google_IDProv_04.png

  5. From the window that is displayed, copy the following values.

    • Client ID
    • Client secret

    google_IDProv_05.png

This completes the preliminary preparation on the Google side. Next, configure the settings on the TrustLogin side.

TrustLogin Settings

  1. Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
    open "Settings" next to "Identity Provisioning".
    IDProvServiceCommon01.png

  2. Click "Add Service".
    IDProvServiceCommon02.png

  3. Search for "Google", select it, and click the "Add" button.
    google_IDProv_06.png
  4. You will be redirected to the "Identity Provisioning > Google" page.
    Click the "Edit" button.
    google_IDProv_07.png
  5. Open "Access Settings", enter the following values for each setting item, and click "Save".

    Connection URL The verified Google Workspace domain name
    Client ID Issued and copied in Google Settings > Step 5
    Client secret Issued and copied in Google Settings > Step 5

    google_IDProv_12.png

  6. Click the "Connect" button.
    google_IDProv_08.png
  7. Click "Yes".
    google_IDProv_09.png
  8. You will be redirected to the Google page.
    Click "Allow". (Super administrator privileges are required.)
    google_IDProv_10.png
  9. Once the button status updates to "Connected", the initial setup is complete.
    google_IDProv_11.png

Next step: The manual for configuring user synchronization is available here

Values You Can Configure in Attribute Mapping

The values that can be specified as Google's default functions are as follows.

Value Description
Full name The full name with the last name first.
Full name with first name first The full name with the first name first.
Username from email Retrieves the portion of the email address before the "@" symbol, limited to a maximum of 21 characters.

Note: For an overview of the attribute mapping feature and how to configure it, please see here.