Google Workspace SSO
Configure SAML SSO between Google Workspace and platform, including domain verification, attribute mapping, Start URL, and troubleshooting steps.
This guide guides you through setting a single SAML record between Google Workspace (formerly G Suite) and the platform.
Prerequisites
Section entitled ‘Prerequisites’- Google Workspace administrator access
- the platform organization administrator access
- Your platform domain (for example,
probo.example.com) - Access to DNS settings for domain verification
Prepare the platform Information
Section entitled “Prepare the Platform Information”Before you set up Google Workspace, collect the following details about the platform’s service provider:
| Field | Value |
|---|---|
| ACS URL | https://your-probo-domain.com/api/connect/v1/saml/2.0/consume |
| Entity ID | https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata |
| Start URL | https://your-probo-domain.com (optional) |
Replace your-probo-domain.com with your actual platform domain.
Domain Verification
Section “Domain Verification”Before you set up anything else, you need to check the domain property:
- Log in to the platform as an organization administrator
- Go to Organization Settings → Authentication → SAML
- Click Verify Domain (If there are no configurations yet, this option will be available)
- Copy the provided TXT record value
- Add a TXT record to your domain’s DNS settings:
Type: TXTName: _probo-domain-verification.your-company.comValue: [Verification token from Probo]TTL: 300 (or your DNS provider's default)
- Wait for DNS propagation (usually 5-15 minutes)
- In the platform, click Complete Verification
- In case of success, the domain status will be displayed as "Verified"
Configure Google Workspace
Section entitled “Configure Google Workspace”-
Signed to Google Admin Console
-
Go to Apps → Web and mobile apps
-
Click Add app → Add custom SAML app
-
Configure the app details:
Field Value App name ProboDescription Probo Compliance Management PlatformUpload logo Discharge from the GitHub (optional) -
Click Continue
-
Save the Google Identity Provider details which will appear (these will be needed to configure the platform):
Field Example Value Notes SSO URL https://accounts.google.com/o/saml2/idp?idpid=XXXXXXXXXCopy this exact URL Entity ID https://accounts.google.com/o/saml2?idpid=XXXXXXXXXCopy this exact URL Certificate X.509 Certificate text Download the certificate or copy the X.509 certificate text -
Click Continue
-
Configure the service provider details:
Field Value ACS URL https://your-probo-domain.com/api/connect/v1/saml/2.0/consumeEntity ID https://your-probo-domain.com/api/connect/v1/saml/2.0/metadataStart URL [SAML Configuration ID](optional - see note below)Name ID format EMAILName ID Basic Information > Primary emailImportant: The Start URL is optional, but if you want to support the connection streams initiated by IdP, it must be set to your exact SAML configuration ID (not a locholder). If the setting is incorrect, SSO will not work.
-
Click Continue
-
Configure the attribute mappings:
Google Directory attributes App attributes Basic Information > Primary email emailBasic Information > First name firstNameBasic Information > Last name lastName -
Click Finish
-
In the list of applications, click on the platform app
-
Click User access
-
Select ON pentru toata lumea or configure specific organizational units
-
Click Save
Configure the platform
Section entitled “Configure the platform”-
Log in to the platform as an organization administrator
-
Go to Organization Settings → Authentication → SAML
-
Click Add SAML Configuration
-
Configure the basic settings:
Field Value Notes Email Domain your-company.comYour organization’s email domain Enforcement Policy OPTIONALRecommended for initial setup -
Configure the identity provider settings with values in Google Workspace:
Field Value Notes IdP Entity ID https://accounts.google.com/o/saml2?idpid=XXXXXXXXXCopy from Google Workspace setup IdP SSO URL https://accounts.google.com/o/saml2/idp?idpid=XXXXXXXXXCopy from Google Workspace setup IdP Certificate [X.509 Certificate text]Get a certificate from Google -
Configure the attribute mappings:
Field Value Notes Email Attribute emailMaps to user email First Name Attribute firstNameMaps to user first name Last Name Attribute lastNameMaps to user last name Role Attribute [Leave empty]Optional; map to send OWNER,ADMIN,EMPLOYEE, orVIEWER -
Configure user settings:
Field Value Notes Auto Signup EnabledAllows new users to automatically register through SSO -
Click Save Configuration (the configuration will be created, but is not yet enabled)
-
Copy the SAML Configuration ID - You will see a unique configuration ID (for example,
saml_config_1a2b3c4d) that you need to update the start URL in Google Workspace
Update Google Workspace Start URL
“Update Google Workspace Start URL” sectionNow that you have the SAML configuration ID on the platform:
- Return to Google Admin Console
- Go to Apps → Web and mobile apps → the platform
- Click SAML attribute mapping
- Update the Start URL field with the SAML configuration ID (for example,
saml_config_1a2b3c4d) - Click Save
This enables IdP-initiated connection streams, allowing users to click on the platform from their Google Workspace app launcher.
Troubleshooting
Section “Troubleshooting”“App isn’t verified” Error
“App Isn’t Verified” Error- Cause: Google Workspace app not enabled for users
- SolutionActivate the app for all users or specific organizational units in the Google Admin Console
“Access blocked” Error
“Access Blocked” Error”- Cause: User not in allowed organizational units
- SolutionCheck the user access settings of Google Workspace and make sure that users are in the correct organizational units
“Invalid SAML Response” Error
“Invalid SAML Response” Error”- Cause: Incorrect ACS URL or Entity ID configuration
- SolutionCheck the URLs that match exactly between Google Workspace and the platform:
- ACS URL:
https://your-probo-domain.com/api/connect/v1/saml/2.0/consume - Entity ID:
https://your-probo-domain.com/api/connect/v1/saml/2.0/metadata
- ACS URL:
Attributes Not Mapping
Section titled “Attributes Not Mapping”- Cause: Incorrect attribute names in the platform configuration
- Solution: Use exact attribute names:
email,firstName,lastName
Debugging Steps
Posts Tagged ‘Debugging Steps’Check Google Workspace Logs
Section entitled “Check Google Workspace Logs”- Go to Google Admin Console → Reporting → Audit and investigation → SAML apps
- Look for failed authentication attempts
- Check error messages and timestamps for debugging clues
Verify Certificate Format
Section entitled “Verify Certificate Format”Make sure that the certificate is formatted correctly without line interruptions:
-----BEGIN CERTIFICATE-----[Certificate content without line breaks]-----END CERTIFICATE-----Test Metadata URL
Section entitled “URL metadata test”If you use the metadata URL, test it in a browser to make sure it returns valid XML:
https://accounts.google.com/o/saml2/idp?idpid=XXXXXXXXXShould return valid XML metadata response.
Advanced Configuration
Section “Advanced Configuration”Custom Attributes
Posts Tagged ‘Custom Attributes’To map additional Google Workspace attributes:
- In Google Admin Console, go to Directory → Users
- Add custom attributes to user profiles
- In the SAML platform configuration, map these custom attributes
Multiple Domains
Posts Tagged ‘Multiple Domains’To support multiple email domains:
- Create separate SAML configurations for each domain
- Use the same Google Workspace IdP settings
- Verify each domain separately
Organizational Units
Section entitled “Organizational Units”Limit SSO to specific organizational units in Google Workspace:
- In the platform application settings, select Limited access
- Choose specific organizational units
- Only users on these units will be able to use SSO