jump to content

Google Workspace SSO

Configure SAML SSO between Google Workspace and platform, including domain verification, attribute mapping, Start URL, and troubleshooting steps.

Show as Markdown

This guide guides you through setting a single SAML record between Google Workspace (formerly G Suite) and the platform.

  • Google Workspace administrator access
  • the platform organization administrator access
  • Your platform domain (for example, probo.example.com)
  • Access to DNS settings for domain verification

Before you set up Google Workspace, collect the following details about the platform’s service provider:

Field Value
ACS URL https://your-probo-domain.com/api/connect/v1/saml/2.0/consume
Entity ID https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata
Start URL https://your-probo-domain.com (optional)

Replace your-probo-domain.com with your actual platform domain.

Before you set up anything else, you need to check the domain property:

  1. Log in to the platform as an organization administrator
  2. Go to Organization Settings → Authentication → SAML
  3. Click Verify Domain (If there are no configurations yet, this option will be available)
  4. Copy the provided TXT record value
  5. Add a TXT record to your domain’s DNS settings:
    Type: TXT
    Name: _probo-domain-verification.your-company.com
    Value: [Verification token from Probo]
    TTL: 300 (or your DNS provider's default)
  6. Wait for DNS propagation (usually 5-15 minutes)
  7. In the platform, click Complete Verification
  8. In case of success, the domain status will be displayed as "Verified"
  1. Signed to Google Admin Console

  2. Go to Apps → Web and mobile apps

  3. Click Add app → Add custom SAML app

  4. Configure the app details:

    Field Value
    App name Probo
    Description Probo Compliance Management Platform
    Upload logo Discharge from the GitHub (optional)
  5. Click Continue

  6. Save the Google Identity Provider details which will appear (these will be needed to configure the platform):

    Field Example Value Notes
    SSO URL https://accounts.google.com/o/saml2/idp?idpid=XXXXXXXXX Copy this exact URL
    Entity ID https://accounts.google.com/o/saml2?idpid=XXXXXXXXX Copy this exact URL
    Certificate X.509 Certificate text Download the certificate or copy the X.509 certificate text
  7. Click Continue

  8. Configure the service provider details:

    Field Value
    ACS URL https://your-probo-domain.com/api/connect/v1/saml/2.0/consume
    Entity ID https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata
    Start URL [SAML Configuration ID] (optional - see note below)
    Name ID format EMAIL
    Name ID Basic Information > Primary email

    Important: The Start URL is optional, but if you want to support the connection streams initiated by IdP, it must be set to your exact SAML configuration ID (not a locholder). If the setting is incorrect, SSO will not work.

  9. Click Continue

  10. Configure the attribute mappings:

    Google Directory attributes App attributes
    Basic Information > Primary email email
    Basic Information > First name firstName
    Basic Information > Last name lastName
  11. Click Finish

  12. In the list of applications, click on the platform app

  13. Click User access

  14. Select ON pentru toata lumea or configure specific organizational units

  15. Click Save

  1. Log in to the platform as an organization administrator

  2. Go to Organization Settings → Authentication → SAML

  3. Click Add SAML Configuration

  4. Configure the basic settings:

    Field Value Notes
    Email Domain your-company.com Your organization’s email domain
    Enforcement Policy OPTIONAL Recommended for initial setup
  5. Configure the identity provider settings with values in Google Workspace:

    Field Value Notes
    IdP Entity ID https://accounts.google.com/o/saml2?idpid=XXXXXXXXX Copy from Google Workspace setup
    IdP SSO URL https://accounts.google.com/o/saml2/idp?idpid=XXXXXXXXX Copy from Google Workspace setup
    IdP Certificate [X.509 Certificate text] Get a certificate from Google
  6. Configure the attribute mappings:

    Field Value Notes
    Email Attribute email Maps to user email
    First Name Attribute firstName Maps to user first name
    Last Name Attribute lastName Maps to user last name
    Role Attribute [Leave empty] Optional; map to send OWNER, ADMIN, EMPLOYEE, or VIEWER
  7. Configure user settings:

    Field Value Notes
    Auto Signup Enabled Allows new users to automatically register through SSO
  8. Click Save Configuration (the configuration will be created, but is not yet enabled)

  9. Copy the SAML Configuration ID - You will see a unique configuration ID (for example, saml_config_1a2b3c4d) that you need to update the start URL in Google Workspace

Update Google Workspace Start URL

“Update Google Workspace Start URL” section

Now that you have the SAML configuration ID on the platform:

  1. Return to Google Admin Console
  2. Go to Apps → Web and mobile apps → the platform
  3. Click SAML attribute mapping
  4. Update the Start URL field with the SAML configuration ID (for example, saml_config_1a2b3c4d)
  5. Click Save

This enables IdP-initiated connection streams, allowing users to click on the platform from their Google Workspace app launcher.

“App isn’t verified” Error

“App Isn’t Verified” Error
  • Cause: Google Workspace app not enabled for users
  • SolutionActivate the app for all users or specific organizational units in the Google Admin Console

“Access blocked” Error

“Access Blocked” Error”
  • Cause: User not in allowed organizational units
  • SolutionCheck the user access settings of Google Workspace and make sure that users are in the correct organizational units

“Invalid SAML Response” Error

“Invalid SAML Response” Error”
  • Cause: Incorrect ACS URL or Entity ID configuration
  • SolutionCheck the URLs that match exactly between Google Workspace and the platform:
    • ACS URL: https://your-probo-domain.com/api/connect/v1/saml/2.0/consume
    • Entity ID: https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata
  • Cause: Incorrect attribute names in the platform configuration
  • Solution: Use exact attribute names: email, firstName, lastName
  1. Go to Google Admin Console → Reporting → Audit and investigation → SAML apps
  2. Look for failed authentication attempts
  3. Check error messages and timestamps for debugging clues

Make sure that the certificate is formatted correctly without line interruptions:

-----BEGIN CERTIFICATE-----
[Certificate content without line breaks]
-----END CERTIFICATE-----

If you use the metadata URL, test it in a browser to make sure it returns valid XML:

https://accounts.google.com/o/saml2/idp?idpid=XXXXXXXXX

Should return valid XML metadata response.

To map additional Google Workspace attributes:

  1. In Google Admin Console, go to Directory → Users
  2. Add custom attributes to user profiles
  3. In the SAML platform configuration, map these custom attributes

To support multiple email domains:

  1. Create separate SAML configurations for each domain
  2. Use the same Google Workspace IdP settings
  3. Verify each domain separately

Limit SSO to specific organizational units in Google Workspace:

  1. In the platform application settings, select Limited access
  2. Choose specific organizational units
  3. Only users on these units will be able to use SSO

Ultima actualizare: