Configure Google Workspace as a SAML 2.0 Identity Provider (IdP) for Acquia Single Sign-On (SSO). After you configure Google Workspace, users with your corporate email domain authenticate through Google Workspace to access Acquia products.
Prerequisites
To configure Google Workspace as an IdP, you must have the following prerequisites:
- Active Cloud Platform subscription with SSO entitlement.
- Organization administrator access in Acquia.
- Google Workspace administrator access.
- Verified domain in Acquia SSO console.
The following table explains the steps to Configure Google Workspace as an Identity Provider:
| S.No. | Step | Description |
|---|
| 1 | Add and verify your domain in Acquia | Add your domain to the Acquia SSO console and verify its ownership. |
| 2 | Create custom SAML app in Google Workspace | Create a custom SAML app in Google to generate the initial identity provider metadata. |
| 3 | Add the Identity Provider in Acquia | To create the provider and generate Acquia metadata, enter Google metadata, such as entity ID, SSO URL, and certificate, in Acquia. |
| 4 | Complete the SAML app configuration in Google Workspace | Paste Acquia metadata into Google Workspace to finalize the application configuration. |
| 5 | Configure SAML attribute mappings | Map the exact first name, last name, and email attributes between Google and Acquia. |
| 6 | Enable user access | Turn on the custom SAML application in Google Workspace to grant access to users. |
Add and verify your domain in Acquia
Before configuring your Identity Provider, ensure that you add and verify your domain in the Acquia SSO management console. You cannot assign an Identity Provider without a verified domain. For detailed information, refer to Adding a domain.
Create custom SAML app in Google Workspace
To get the required details from Google Workspace:
- Sign in to the Google Admin console.
- Go to Apps > Web and mobile apps.
- Click Add App > Add custom SAML app.
- Enter a name for the application, for example, Acquia SSO, and click Continue.
- Copy the SSO URL and Entity ID, and download the Certificate.
- Keep the browser session open.
Add the Identity Provider in Acquia
For detailed information, refer to Adding an Identity Provider.
- In Acquia SSO, click Add identity provider.
- Enter a Label, select your verified Domain from the list, and paste the Google Entity ID and SSO URL.
- Open the downloaded Google Certificate in a text editor, copy its contents, and paste it into the Public certificate field.
Click Add identity provider.
The system displays the Service Provider details.
- Under Service provider details, copy Acquia Entity ID and ACS URL.
Complete the SAML app configuration in Google Workspace
To complete the configuration in Google Workspace:
- Return to your open Google Admin console browser session and select Continue.
- Paste Acquia ACS URL and Entity ID into the respective fields.
- Select EMAIL for the Name ID format.
- Select Basic Information > Primary email for the Name ID.
- Select Continue.
To map these Google directory attributes to the SAML app:
- On the Attribute mapping, click Add mapping.
- Map the Google directory fields to the following App attributes exactly as written:
- Basic Information > First name maps to
firstName. - Basic Information > Last name maps to
lastName. - Basic Information > Primary email maps to
email.
- Click Finish.
Enable user access
To grant users access to the Acquia SSO app:
- Go to Apps > Web and mobile apps > Your SAML App.
- Click User access.
- Select ON for everyone or apply it to specific organizational units.
- Click Save.