KOP Integrations - Google Workspace - Rafay Product Documentation

Google Workspace

Follow the steps documented below to integrate your Org and Google Workspace for Single Sign On (SSO).

Important

Only users with "Organization Admin" privileges can configure SSO in the Web Console.


Step 1: Create IdP

Important

Within an org, the domain of an IdP cannot be used for another IdP. A domain existing in an org can be used in multiple orgs (for one IdP in each org)

Important

Encrypting SAML assertions is optional because privacy is already provided at the transport layer using HTTPS. Encrypted assertions provide an additional layer of security on top ensuring that only the SP (Org) can decrypt the SAML assertion.


Step 2: View SP Details

The IdP configuration wizard will display critical information that you need to copy/paste into your Google Workspace. Provide the following information to your Google Workspace administrator.


Step 3: Create App in Google Workspace


Step 4: General Settings


Step 5: Configure SAML


Step 6: Create Group in Google Workspace


Step 7: Assign User to Group in Google Workspace


Step 8: Enable SSO in Google Workspace


Step 9: Configure SSO Attribute Mapping for SSO SAML Configuration

The SSO Attribute Mapping configuration step for Groups is critical because it will ensure that Google Workspace will send the groups the user belongs to as part of the SSO process. The group information is used to transparently map users to the correct group/role. In the illustrative example below, we are using Rafay as the name of the group attribute statement.


Step 10: Add Group Name to user in Google googleworkspace


Step 11: Specify IdP Metadata File


Step 12: Create group in Console

An identical named group needs to be created as was created in Step 6. Ensure that this group is mapped to the appropriate Projects with the correct privileges. In the example below, the Group rafay-org-admins is configured as an "Organization Admin" with access to all Projects.


Recap

Congratulations! You have successfully enabled SSO using Google Workspace. You should be able to login to the Web Console using your Google Workspace credentials.