This document offers examples of Google Workspace and Identity Center single sign-on (SSO login).
Preparations
Before configuring SSO login, you need to complete user creation: create a same-name user in Identity Center. Upon creation, the username in Identity Center must be consistent with that in Google Workspace. For detailed operations, please refer to User Management. Note:
Google Workspace does not support synchronizing users to Identity Center through SCIM.
Configuration in Identity Center
Step 1: Enable SSO Login
2. In the left sidebar, choose User Management > Settings.
3. In the SSO Login section, click , then click Enable in the popup window to enable SSO login. Step 2: Copy the Service Provider (SP) Info
In the Service Provider (SP) Info section, view and copy the ACS URL and Entity ID, and use them directly for manual configuration of the external IdP.
Configuring Google Workspace
Step 1: Set Up Single Sign-On in Google Workspace
1. The admin enters Google Workspace, in the left sidebar, select Apps > Web and mobile apps, click Add app on the page, and select Add custom SAML app.
2. Configure App name, then click CONTINUE.
3. Click DOWNLOAD METADATA to download the metadata XML document, then click CONTINUE.
4. At ACS URL, fill in the ACS URL obtained from the identity center in step 2. At Entity ID, fill in the Entity ID obtained from the identity center, then click CONTINUE. 5. Click FINISH to complete the creation.
6. Click User access module View details.
7. In the Service status module, select ON for everyone, then click SAVE.
Step 2: Upload Federation Metadata XML in Identity Center
1. In the Organization Account Management > Identity Center Management > Settings > SSO Login Identity Provider (IDP) Information section, click Configure Identity Provider Information. 2. Click Select File to upload the Federation Metadata XML document downloaded from Google Workspace.
Result Verification
After completing the SSO login configuration, you can initiate SSO login from Tencent Cloud.
Premise: In the identity center, it is necessary to create a user with the same name as in the Google Workspace application. Enter Organization Account Management > Identity Center Management > User page creation. Login Process:
1. The Identity Center administrator enters Organization Account Management > Identity Center Management > Identity Center Overview page on the right to view and copy the User Login URL. 2. Click to access the User Login URL, then click Login.
3. Redirect to the Google Login page, select an account, then enter the password to sign in.
4. Login successful, enter the Identity Center account list page.