About Google Workspace SAML Integration
Google Workspace SAML integration in Iru Endpoint allows you to set up SAML-based SSO integration with Google Workspace, providing secure authentication for users accessing Iru Endpoint through their Google Workspace credentials.How It Works
When users attempt to access Iru Endpoint, they’re redirected to Google Workspace for authentication. After successful authentication, Google Workspace sends a SAML assertion back to Iru Endpoint, which validates the user’s identity and grants access to the platform.Setting Up the SAML Connection
Navigate to Settings
Access Authentication Settings
Add New Connection
Select SAML Connection
Continue Setup
Show Advanced Details
Copy ACS URL
Copy Entity ID
Keep Tab Open
Configuring Google Workspace Application
Access Google Admin Console
Open Menu
Navigate to Apps
Select Web and Mobile Apps
Add New App
Select Custom SAML App
Configure App Details
- Set an App name.
- Optionally, add a Description.
- Upload an optional App icon.
- Click Continue.
Copy Google Identity Provider Details
- Copy the SSO URL and save it to a text document for later use.
- Download the Certificate and save it.
- Click Continue.
Configure Service Provider Details
- In the ACS URL field, paste the Iru Endpoint Assertion Consumer Service URL you copied earlier.
- Paste the Iru Endpoint Entity ID you copied earlier in the Entity ID field.
- Make sure that the Signed response option is checked.
- Set the Name ID Format to UNSPECIFIED.
- For NameID, make sure that Basic Information > Primary email is selected.
- Click CONTINUE.
Configure Attribute Mapping
- Click on Add Mapping twice so that you can add the following two mappings:
-
Find the First name attribute in the dropdown menu and paste the following string:
-
Find the Last name attribute in the dropdown menu and paste the following string:
- Click Finish.
Configure User Access
- If it displays OFF for everyone, click on the disclosure triangle in the user access panel to assign a user group or organizational unit to the app.
- Optionally, please select a group or organizational unit to enable the service (by default, it will display all organizational units).
- Set service status to ON for everyone.
- Click Save.
Configuring Iru Endpoint SAML Connection
Return to Iru Endpoint
Name the Connection
Add Sign-in URL
Upload Certificate
Verify User ID Attribute
Enable Sign Request
Set Request Algorithm
Set Digest Algorithm
Set Protocol Binding
Save Configuration
Enabling the Connection
Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can enable it. For step-by-step instructions, please refer to the Enable and Manage a Connection section of our Single Sign-on support article.Enforcing Single Sign-On
Once you have configured at least one Single Sign-on connection, you can disable the standard authentication connection. Disabling Iru Endpoint standard authentication will disable the ability for Iru Endpoint administrators in your tenant to authenticate via email/password, Google Sign-in, or Office 365 Sign-in. Please refer to our Single Sign-on support article for step-by-step instructions.Testing the Integration
Add User to Admin Team
Fill User Information
Submit User
Close Invite Window
Refresh Access Page
Test SSO Login