Search knowledge base

Google SAML setup guide

Features

The Google/Folderit SAML integration currently supports the following features:

  • SP-initiated SSO
  • IdP-initiated SSO

Requirements

  • None

Configuration Steps

Folderit: Create initial SAML configuration

  1. Go to Manage accounts.
  2. Open the settings menu (cog wheel) of an account and click Identity providers.
  3. Click Set up custom SAML connector.
  4. Click Save.

Google: Create custom SAML app

  1. Sign in to your Google Admin console.
  2. In the Admin console, go to Menu > Apps > Web and mobile apps.
  3. Click Add App > Add custom SAML app.
    Enter the app name and, optionally, upload an icon for your app. The app icon appears on the Web and mobile apps list, on the app settings page, and in the app launcher. If you don’t upload an icon, an icon is created using the first two letters of the app name.
  4. Click Continue.
  5. On the Google Identity Provider details page, download the IDP metadata file.
  6. click Continue.
  7. In the Service Provider Details window, enter:
    1. ACS URLSP SSO URL value.
    2. Entity IDSP Entity ID value.
    3. Name ID format — EMAIL
    4. Name ID format — Primary email
  8. Click Continue.
  9. Click Add mapping
    1. Basic Information -> First name — firstName
    2. Basic Information -> Last name — lastName
  10. Click Finish.

Folderit: Update SAML configuration

  1. Click SAML in the toolbar.
  2. Click Metadata file.
  3. Select the previously downloaded IDP metadata file.
  4. Click Save.

Google: Turn on your SAML app

  1. Click User access.
  2. To turn a service on or off for everyone in your organization, click On for everyone or Off for everyone, and then click Save.
  3. (Optional) To turn a service on or off for an organizational unit:
    1. At the left, select the organizational unit.
    2. To change the Service status, select On or Off.
    3. Choose one:
      • If the Service status is set to Inherited and you want to keep the updated setting, even if the parent setting changes, click Override.
      • If the Service status is set to Overridden, either click Inherit to revert to the same setting as its parent, or click Save to keep the new setting, even if the parent setting changes.
        Note: Learn more about organizational structure.
  4. To turn on a service for a set of users across or within organizational units, select an access group. For details, go to Use groups to customize service access.
  5. Ensure that the email addresses your users use to sign in to the SAML app match the email addresses they use to sign in to your Google domain.

Verify that SSO is working with your custom app

You can test for both identity provider (IdP) initiated SSO and service provider (SP) initiated SSO.

IdP-initiated

  1. Sign in to your Google Admin console.
  2. In the Admin console, go to Menu > Apps > Web and mobile apps.
  3. Select your custom SAML app.
  4. At the top left, click Test SAML login.
    Your app should open in a separate tab. If it doesn’t, use the information in the resulting SAML app error messages to update your IdP and SP settings as needed, then re-test SAML login.

SP-initiated

  1. Open the SSO URL for your new SAML app. You should be automatically redirected to the Google sign-in page.
  2. Enter your username and password.
    After your sign-in credentials are authenticated, you’re redirected back to your new SAML app.