Managed Studio

Single Sign-On (SSO) SAML: Integrating with Google

Requirements

  • Admin access to create the app in your Identity Provider's Admin Console

Setup instructions

Start the integration within Managed Studio

  1. Navigate to the Settings page
  2. Click Single sign-on (SAML)
  3. Click the New provider button Screenshot
  4. Make a note of the following two fields from the Single sign-on configuration modal to populate your IdP Admin Console with in the next step:
    • Service Provider Consumer URL
    • Service Provider entity ID Screenshot

Create the Managed Studio app within the Google Workspace Admin Console

  1. Sign in to the Google Workspace Admin Console
  2. In the left navigation bar, click Apps
  3. Click Web and mobile apps from the list Screenshot
  4. Click the Add app button
  5. Choose Add custom SAML app from the menu Screenshot
  6. Enter a Name for your application
  7. Click Continue Screenshot
  8. Copy the values from the following two fields. You will need to paste them into the Managed Studio SSO Integration modal in the next step:
    • SSO URL
    • Entity ID
  9. Click the Download button for the Certificate
  10. Click Continue Screenshot
  11. Enter the following values from earlier:
    • ASC URL: Service Provider Consumer URL value from Managed Studio SSO Integration tab
    • Entity ID: Service Provider entity ID value from Managed Studio SSO Integration tab
  12. Click Continue Screenshot
  13. Click the Add mapping button
  14. Configure the following mapping:
    • Google Directory attributes: Primary email
    • App attributes: email
  15. Click Finish Screenshot

Finish the integration within the Managed Studio SSO Integration modal

  1. Enter the two fields from the Google Workspace Admin Console into the Managed Studio SSO Integration modal:
    • Single Sign-On URL: SSO URL from the Google Workspace Admin Console
    • Identity Provider entity ID: Entity ID from the Google Workspace Admin Console
  2. Upload the Identity provider certificate
  3. Click Save Screenshot

Enable user access to your app within the Google Workspace Admin Console

You will need to make the managed app available to all users, specific groups or organizational units before the users can authenticate within Managed Studio.

Screenshot

Finding your Single sign-on URL

  1. Navigate to the Settings page
  2. Click Single sign-on (SAML)
  3. Your Single sign-on URL is shown at the top of the page

Screenshot