About Google Workspace SAML Integration
Google Workspace SAML integration in Iru Endpoint lets you set up SAML-based SSO integration with Google Workspace for users accessing Iru Endpoint through their Google Workspace credentials.How It Works
When users attempt to access Iru Endpoint, they’re redirected to Google Workspace for authentication. After successful authentication, Google Workspace sends a SAML assertion back to Iru Endpoint, which validates the user’s identity and grants access to the platform.- Iru Endpoint Configuration
- Google Workspace Configuration
Setting Up the SAML Connection
You’ll need to complete the initial setup in Iru Endpoint first to get the configuration information required for Google Workspace. After copying the Entity ID and ACS URL, switch to the Google Workspace Configuration tab to continue.
1
Navigate to the Account Menu Button
In Iru Endpoint, in the sidebar, click the Account Menu Button.
2
Access Authentication Settings
Click the Access option in the menu.
3
Add New Connection
Select the Admin and Authentication tab (selected by default) and scroll down to Authentication methods.
4
Add Authentication Method
Click + Authentication Method, then enter a display name for the SSO Connection and select SAML.
5
Create Connection
Click Create.
6
Configuration Information
Click Configuration information if that section is not already expanded.
7
Copy Service Provider Entity ID
Copy the Service provider entity ID into a text document for later use. You’ll need this for the Google Workspace configuration.
8
Copy ACS URL
Copy the Assertion consumer service (ACS) URL into a text document for later use. You’ll need this for the Google Workspace configuration.
9
Keep Tab Open
Keep the Iru Endpoint configuration modal open, then switch to the Google Workspace Configuration tab to continue.
Configuring Iru Endpoint SAML Connection
After completing the Google Workspace configuration, return here to finish setting up the SAML connection in Iru Endpoint. You’ll need the SSO URL, Entity ID, and certificate from Google Workspace.
1
Return to Iru Endpoint
Go back to the SAML connection configuration modal in Iru Endpoint.
2
Name the Connection
Give the connection a Name.
3
Add Sign-in URL
Paste in the Sign-in URL you copied from Google Workspace.
4
Add IdP Entity ID
Paste the Entity ID you copied from Google Workspace into the IdP Entity ID field.
5
Upload Certificate
Upload the certificate you downloaded from Google Workspace.
6
Set User ID Attribute
Ensure that the User ID Attribute is set to the default value of:
7
Enable Sign Request
Ensure that Sign Request is set to Yes.
8
Set Request Algorithm
Ensure that the Request Algorithm is set to RSA-SHA256.
9
Set Digest Algorithm
Ensure that Sign Request Algorithm Digest is set to SHA 256.
10
Set Protocol Binding
Set the Protocol Binding to HTTP-POST.
11
Save Configuration
Click Save and then click Cancel to exit the configuration.
Allow for Tenant Authentication
Once you have configured the SAML connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the Allowing Tenant Authentication and Managing Connections section in our Single Sign-on support article.Enforcing Single Sign-On
Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our Single Sign-on support article for step-by-step instructions.Testing the Integration
1
Add User to Admin Team
Add a user to the Admin Team in Iru Endpoint by clicking New User.
2
Fill User Information
Fill in all of the corresponding user information. This user must exist in Google Workspace and must be assigned to the Iru Endpoint SSO app in your Google Workspace tenant.
3
Submit User
Click Submit.
4
Close Invite Window
Once the invite is submitted, close the Invite User window.
5
Refresh Access Page
Refresh the Access page in Iru Endpoint. You should see the user you just added.
6
Test SSO Login
Check the user’s email to accept the invitation and log into Iru Endpoint with the new SAML SSO connection.