Google Workspace (G Suite) Integration

The "Google Workspace (G Suite) Integration" feature enables
user information synchronization to Google Workspace (G Suite) with TrustLogin as the source,
as well as SAML authentication integration.

Note: To use this feature, you need to subscribe to the TrustLogin Pro plan or the corresponding option. For pricing, click here

Setup Instructions

1. Adding a Domain

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "G Suite Integration."

    gsuite01.png

  2. Open "Set up G Suite."
    Note: If the error "This app is blocked" appears during this operation, please check here.
    gsuite02.png

  3. Log in with a Google Workspace (G Suite) administrator account.

    gsuite03.png

  4. After logging in as a Google Workspace (G Suite) administrator, a security warning screen will appear.
    Click "Advanced" → "Go to trustlogin.com (unsafe)."gsuite04.png
    gsuite05.png

  5. Five consecutive confirmation screens for "Grant permission to trustlogin.com" will appear. Click "Allow" on all of them.

    gsuite06.png

  6. Click "Allow" again.

    gsuite07.png

  7. Setup is complete when the message "Setup complete" appears. Confirm that the domains registered on the Google Workspace (G Suite) side are displayed. (Aliases are not displayed.)

    gsuite08.png

2. Assigning Members

  1. Select the domain for which you want to assign members.

    gsuite09.png

  2. Click "Add Member" or "Add Group," then select and add the target members (or group).

    gsuite10.png

Confirm that the members have been added.

gsuite11.png

When TrustLogin is integrated with Google Workspace (G Suite), member information is mapped as follows.

TrustLogin Google Workspace (G Suite)
Last Name Last Name
First Name First Name
Email Address Email Address
Phone Number Phone Number (Work)
Prefecture + City + Street Address Address (Work)
Department Department

[About Member Status After Disabling the Integration]

gsuite17.png

Please note that if you turn this setting ON (shown in green), members will be deleted on the Google Workspace (G Suite) side when the option integration is disabled or when a member is removed from assignment.
By default, this setting is OFF, and members will not be deleted on the Google Workspace (G Suite) side even if you disable the integration or remove member assignments on the TrustLogin side.

[Google Workspace (G Suite) Behavior When a Member's Status Becomes "Suspended" in TrustLogin]
On the Google Workspace (G Suite) side, the user will become "Suspended" and will no longer be able to receive email.
If "Suspend Unused Accounts" is configured under "Security Policy Settings," please note that if a member does not log in to TrustLogin for a period of time (for example, due to an extended leave), their status will become "Suspended," which may result in email not being received.

3. Enabling SSO (SAML)

After assigning members, enable automatic SSO (SAML) configuration.

About Excluding Some Users from SAML Authentication

When you enable SAML authentication for Google Workspace, all users within the Google-side domain become subject to SAML authentication.
If you want to exclude some users from SAML authentication, please refer to "If You Want to Exclude Some Users from SAML Authentication."

  1. Click the "Edit" button to the right of "G Suite Integration," and turn ON "Enable automatic SSO (SAML) configuration."

    gsuite12.png

  2. A "GSuite Integration (domain name)" icon will appear on the My Page of integrated members, allowing them to log in to GSuite via SSO authentication from there.

    gsuite13.png
    Note: If you do not want the SAML app icon to appear on My Page, you can hide it by disabling the checkbox item below.

Updating the Integration

If a domain is added or removed on the Google Workspace (G Suite) side, you can update the integration to retrieve the latest domain information.

  1. Click "Update Integration."

    gsuite16.png
  2. G Suite administrator: click "Yes" to grant approval.

    gsuite18.png

  3. Follow the same steps as step 3 onward in Adding a Domain in the setup instructions.

Resetting the Integration

This section describes how to reset the integration between Google Workspace (G Suite) and TrustLogin.

  1. Click "Reset Integration."

    gsuite14.png
  2. A confirmation message will appear. Select "OK."

    gsuite15.png

  3. Confirm that it has returned to its initial state.

    gsuite16.png



Frequently Asked Questions

Q1.
When configuring the Google Workspace (G Suite) integration, clicking "Set up G Suite"

displays the error "This app is blocked."

A1.
This may occur because Google Workspace is restricting API access via
OAuth authentication from third-party apps.
Please try obtaining an OAuth client ID using the steps below, and then configure Google Workspace to allow access for the app.

  1. On the error screen displayed after clicking "Set up G Suite," copy the URL.01.png


  2. Paste the copied URL into a text editor or similar,
    and note the value in the URL from after "client_id=" up to the ".googleusercontent.com" portion.
    This is the "Client ID" required when configuring settings on the Google Workspace side.

    02.png


  3. Configure the obtained client ID in the Google Workspace admin console.
    For detailed steps, please refer to the following document provided by Google Workspace.

    Reference steps:
    Control which third-party & internal apps can access Google Workspace data
    Note: Please refer to the "Add new app" section within Step 3.
    Note: For "App access,"
    please select "Trusted: can access all Google services."
    Note: This must be performed by a Google super administrator.


  4. After completing the configuration on the Google Workspace side,
    please redo the integration setup from the TrustLogin admin screen.

Q2.
A 500 error may occur when launching the "Google Workspace App" from My Page (IdP-Initiated).
Note: This error does not occur when accessing Google directly for SSO (SP-Initiated).

A2.

In the "Google Workspace Integration" feature, depending on the SSO profile settings on the Google side,

we have confirmed that a SAML error may occur.

■ Workaround

If the above error occurs, please make the following configuration change in the Google Workspace admin console.

"Security" > "SSO with third-party IdP" > "Domain specific service URLs"

> "Automatically redirect users to the third-party IdP included in the following SSO profile"

> Select "SSO profile for your organization" and save.

Google Workspace (G Suite) Integration

The "Google Workspace (G Suite) Integration" feature enables
user information synchronization to Google Workspace (G Suite) with TrustLogin as the source,
as well as SAML authentication integration.

Note: To use this feature, you need to subscribe to the TrustLogin Pro plan or the corresponding option. For pricing, click here

Setup Instructions

1. Adding a Domain

  1. Log in to TrustLogin, open the "Admin Page > Settings > Optional Features" menu, and click the "Settings" button for "G Suite Integration."

    gsuite01.png

  2. Open "Set up G Suite."
    Note: If the error "This app is blocked" appears during this operation, please check here.
    gsuite02.png

  3. Log in with a Google Workspace (G Suite) administrator account.

    gsuite03.png

  4. After logging in as a Google Workspace (G Suite) administrator, a security warning screen will appear.
    Click "Advanced" → "Go to trustlogin.com (unsafe)."gsuite04.png
    gsuite05.png

  5. Five consecutive confirmation screens for "Grant permission to trustlogin.com" will appear. Click "Allow" on all of them.

    gsuite06.png

  6. Click "Allow" again.

    gsuite07.png

  7. Setup is complete when the message "Setup complete" appears. Confirm that the domains registered on the Google Workspace (G Suite) side are displayed. (Aliases are not displayed.)

    gsuite08.png

2. Assigning Members

  1. Select the domain for which you want to assign members.

    gsuite09.png

  2. Click "Add Member" or "Add Group," then select and add the target members (or group).

    gsuite10.png

Confirm that the members have been added.

gsuite11.png

When TrustLogin is integrated with Google Workspace (G Suite), member information is mapped as follows.

TrustLogin Google Workspace (G Suite)
Last Name Last Name
First Name First Name
Email Address Email Address
Phone Number Phone Number (Work)
Prefecture + City + Street Address Address (Work)
Department Department

[About Member Status After Disabling the Integration]

gsuite17.png

Please note that if you turn this setting ON (shown in green), members will be deleted on the Google Workspace (G Suite) side when the option integration is disabled or when a member is removed from assignment.
By default, this setting is OFF, and members will not be deleted on the Google Workspace (G Suite) side even if you disable the integration or remove member assignments on the TrustLogin side.

[Google Workspace (G Suite) Behavior When a Member's Status Becomes "Suspended" in TrustLogin]
On the Google Workspace (G Suite) side, the user will become "Suspended" and will no longer be able to receive email.
If "Suspend Unused Accounts" is configured under "Security Policy Settings," please note that if a member does not log in to TrustLogin for a period of time (for example, due to an extended leave), their status will become "Suspended," which may result in email not being received.

3. Enabling SSO (SAML)

After assigning members, enable automatic SSO (SAML) configuration.

About Excluding Some Users from SAML Authentication

When you enable SAML authentication for Google Workspace, all users within the Google-side domain become subject to SAML authentication.
If you want to exclude some users from SAML authentication, please refer to "If You Want to Exclude Some Users from SAML Authentication."

  1. Click the "Edit" button to the right of "G Suite Integration," and turn ON "Enable automatic SSO (SAML) configuration."

    gsuite12.png

  2. A "GSuite Integration (domain name)" icon will appear on the My Page of integrated members, allowing them to log in to GSuite via SSO authentication from there.

    gsuite13.png
    Note: If you do not want the SAML app icon to appear on My Page, you can hide it by disabling the checkbox item below.

Updating the Integration

If a domain is added or removed on the Google Workspace (G Suite) side, you can update the integration to retrieve the latest domain information.

  1. Click "Update Integration."

    gsuite16.png
  2. G Suite administrator: click "Yes" to grant approval.

    gsuite18.png

  3. Follow the same steps as step 3 onward in Adding a Domain in the setup instructions.

Resetting the Integration

This section describes how to reset the integration between Google Workspace (G Suite) and TrustLogin.

  1. Click "Reset Integration."

    gsuite14.png
  2. A confirmation message will appear. Select "OK."

    gsuite15.png

  3. Confirm that it has returned to its initial state.

    gsuite16.png



Frequently Asked Questions

Q1.
When configuring the Google Workspace (G Suite) integration, clicking "Set up G Suite"

displays the error "This app is blocked."

A1.
This may occur because Google Workspace is restricting API access via
OAuth authentication from third-party apps.
Please try obtaining an OAuth client ID using the steps below, and then configure Google Workspace to allow access for the app.

  1. On the error screen displayed after clicking "Set up G Suite," copy the URL.01.png


  2. Paste the copied URL into a text editor or similar,
    and note the value in the URL from after "client_id=" up to the ".googleusercontent.com" portion.
    This is the "Client ID" required when configuring settings on the Google Workspace side.

    02.png


  3. Configure the obtained client ID in the Google Workspace admin console.
    For detailed steps, please refer to the following document provided by Google Workspace.

    Reference steps:
    Control which third-party & internal apps can access Google Workspace data
    Note: Please refer to the "Add new app" section within Step 3.
    Note: For "App access,"
    please select "Trusted: can access all Google services."
    Note: This must be performed by a Google super administrator.


  4. After completing the configuration on the Google Workspace side,
    please redo the integration setup from the TrustLogin admin screen.

Q2.
A 500 error may occur when launching the "Google Workspace App" from My Page (IdP-Initiated).
Note: This error does not occur when accessing Google directly for SSO (SP-Initiated).

A2.

In the "Google Workspace Integration" feature, depending on the SSO profile settings on the Google side,

we have confirmed that a SAML error may occur.

■ Workaround

If the above error occurs, please make the following configuration change in the Google Workspace admin console.

"Security" > "SSO with third-party IdP" > "Domain specific service URLs"

> "Automatically redirect users to the third-party IdP included in the following SSO profile"

> Select "SSO profile for your organization" and save.