This article goes over how to set up SAML SSO on Google Workspace
Step 1. Create new App & Integrate to Creative Force
Login to https://admin.google.com/.
Expand “Apps” then select “Web and mobile apps”.
Select Add App → Add custom SAML app.
Input your app name then “Continue”.
Click DOWNLOAD METADATA to save the file to set up on Gamma then click Continue.
Input values for ASC URL, Entity ID & RelayState then Continue.
ASC URL: See “SP Assertion Consumer Service Url” in the How to set up Single Sign-On within Creative Force article
Entity ID: See “SP Entity ID” in the How to set up Single Sign-On within Creative Force article
Start URL: To configure the StartURL, use the following format
<SP Assertion Consumer Service Url>?relaystate=<URL encoded RelayState value>
Example:
In the above example:
https://sso.creativeforce.io/saml2/idpresponse is the ACS URL
The RelayState value is URL encoded and appended after ‘relaystate=’
The example RelayState value is ‘response_type%3Dtoken%26identity…’
Add mapping attributes then Finish.
Primary email | |
First name | |
Last name |
Step 2. Assign user to integration App
Navigate to Directory → Users to manager users
Navigate to Directory → Groups to manager groups