SSO Integrations

SSO can be enabled through various methods

Google Workspace offers SSO integrations that allow users to sign in via a third-party IdP. Google Workspace supports OIDC and SAML-based SSO protocols.

Configuring SAML SSO

Log in to the Admin Console and find SSO with third party IdP in the Security section. From there you will be prompted to set up a profile, upload a certificate, and provide SP details.

Google allows for multiple SSO profiles to be added to a single Google Workspace account.

Configuring OIDC SSO

Setting up OIDC SSO profiles follows a similar process, with the addition that the Google Workspace admin who assigns the OIDC SSO profiles must match the primary email address of the Azure AD account, and all end users must have a valid Microsoft 365 license.

Enabling SSO

Once an SSO profile has been created, SSO can be enabled for specific organizational units such as groups from within the Admin console. Groups in organizational units can also be excluded from the SSO profile.

Last updated

Was this helpful?