Authentication & security
  1. Knowledge base
  2. Users
  3. Authentication & security

How do I set up single sign-on with Google Workspace?

For more information and configuration regarding Single sign-on (SSO) in Security Center, read this article:
How do I set up Single sign-on?

Create a single sign-on application in Google Workspace

  1. Go to the Google admin portal and navigate to Apps.
  2. Web and mobile apps.
  3. Click Add app.
  4. Provide a name and click Add.

Configure Singel sign-on in Security Center

Here, you will need both the Google Admin portal SAML Certificates and  Security center Single sign-on.

  1. Navigate to the newly created Azure application and click on Single sign-on in the left panel.
  2. Log in to Security Center > Settings Single sign-on.
  3. Uncheck Encrypt Assertion element in Security Center.
  4. Scroll down to the section IDP SAML Certificate and choose Manual.
    1. Copy the SSO URL from your SSO APP and Paste it into the IDP login URL in Security Center.
    2. Copy the Entity ID from your SSO APP and Paste it into the IDP entity ID/metadata URL in Security Center.
    3. Copy the value from Certificate 1 from your SSO APP and Paste it into the IDP Certificate in Security Center.

Configure Single sign-on Google Admin

From Holm Security, copy the Single sign-on data from within your account in the Security Center. You can find out what fields to use here: 
How do I set up Single sign-on?

Fill in the copied data in the Google Admin section named Service Provider details.

    1. Copy the Login callback URL in Security Center and Paste it into the ACS URL in the SSO APP.
    2. Copy the Metadata URL in Security Center and Paste it into the Entity ID in the SSO APP.
    3. Copy the Customer login URL in Security Center and Paste it into the Start URL in the SSO APP.
    4. Mark the Signed response in the SSO APP.

Configure the Users Name ID

In the Google Admin section named Service Provider details configure the Name ID to the following:

    1. Home ID format choose EMAIL.
    2. Name ID choose Basic information > Primary email.
    3. Click SAVE.

To test the Single sign-on

  1. Copy the Start login from the SSO APP or the Customer Login URL from the Security Center and paste it into a new Incognito window in your web browser.
  2. Fill in the login information.
  3. Done!