This page describes the initial setup steps for using TrustLogin as the source of identity
to perform Identity Provisioning to Google Workspace.
Note: For detailed instructions on operating Google Workspace , please refer to the manual provided by Google .
Item |
Details |
|
Pre-check |
|
|
Table of Contents |
Note: After connecting TrustLogin and Google Workspace using the steps on this page, |
|
Provisioning Target |
〇 |
Supports user provisioning |
〇 |
Supports group provisioning | |
SAML Authentication Setup Manual |
How to Configure SAML Authentication for Google Workspace
|
|
Notes |
|
|
Setup Steps
Google Settings
Log in to Google Cloud APIs (external site: https://console.cloud.google.com/apis) with administrator privileges,
and click "Admin SDK API" from the "Enabled APIs & services" tab.
- Click "Enable".
- Open the "Credentials" tab, and select "OAuth client ID" from the "Create Credentials" button.
-
On the "Create OAuth client ID" screen, configure the following settings, and click the "Create" button.
Application type Select "Web application" Name Set any name of your choice Authorized redirect URIs Enter the following value:
https://portal.trustlogin.com/id_prov_callback
-
From the window that is displayed, copy the following values.
- Client ID
- Client secret
This completes the preliminary preparation on the Google side. Next, configure the settings on the TrustLogin side.
TrustLogin Settings
Log in to the TrustLogin Admin Page, and from the "Admin Page > Settings > Optional Features" menu,
open "Settings" next to "Identity Provisioning".
- Click "Add Service".
- Search for "Google", select it, and click the "Add" button.
- You will be redirected to the "Identity Provisioning > Google" page.
Click the "Edit" button.
-
Open "Access Settings", enter the following values for each setting item, and click "Save".
Connection URL The verified Google Workspace domain name Client ID Issued and copied in Google Settings > Step 5 Client secret Issued and copied in Google Settings > Step 5
- Click the "Connect" button.
- Click "Yes".
- You will be redirected to the Google page.
Click "Allow". (Super administrator privileges are required.)
Once the button status updates to "Connected", the initial setup is complete.
Next step: The manual for configuring user synchronization is available here
Values You Can Configure in Attribute Mapping
The values that can be specified as Google's default functions are as follows.
| Value | Description |
| Full name | The full name with the last name first. |
| Full name with first name first | The full name with the first name first. |
| Username from email | Retrieves the portion of the email address before the "@" symbol, limited to a maximum of 21 characters. |
Note: For an overview of the attribute mapping feature and how to configure it, please see here.