<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Configure a Shared Account for a Google Workspace App Integration in Okta

Single Sign-On
Okta Integration Network
Okta Classic Engine
Okta Identity Engine

Overview

A shared account for a single Google Workspace application integration requires an existing main integration in Okta. Administrators must create a separate Google Workspace application integration for each shared account and use Postman to share the x.509 certificate between the applications.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • Google Workspace App Integration

Solution

The shared application integration requires specific configuration.

Create a new Google Workspace application integration and configure the domain and sign-on settings by following these steps.

  1. Set the domain to match that of the main application integration from which the shared account originates.
  2. Select the links to display (it is possible to display more than one).

Google Workspace App Settings

  1. Click Save or Next and navigate to the Sign On tab.
  2. Scroll down to the Credentials Details section and select Custom for the Application username format.
  3. Enter the shared account name in double quotes in the text box and click Save.

Credentials Details section

 

 

How is the certificate shared with the new Google Workspace application instance?

Sharing an existing certificate between two applications requires user-based API access and the Postman Apps API collection.

In order to share the existing certificate with the new app integration, the following is needed:

 

Retrieve the application IDs and key IDs to clone the certificate using Postman by following these steps.

  1. Open Postman, navigate to the Apps collection, and use the List Apps API command to retrieve the application ID for the source application (App1).
  2. Retrieve the key ID for the source application (App1).
  3. Retrieve the application ID for the target application (App2).
  4. Navigate to the Apps collection, select Certificate Operations, and search for the Share/Clone certificate API call.
  5. Execute the API call using the following format:

 {{url}}/api/v1/apps/app1ID/credentials/keys/{{keyIdForApp1}}/clone?targetAid=app2ID

NOTE: App1 is the source application from which the certificate is shared, and App2 is the target application that receives the certificate.

The new certificate requires activation and user assignment.

Activate the shared certificate and assign users to the new Google Workspace application by following these steps.

  1. Activate the certificate in the new Google Workspace shared application.
  2. Assign users or groups to the application and test the configuration.

When a user clicks the shared Google Workspace application, a new tab opens for the Google application logged in as the shared account user.

NOTE: Using a shared account poses security risks. These steps provide a workaround, and administrators assume any security risk arising from using a shared account.

Related References

Loading
Configure a Shared Account for a Google Workspace App Integration in Okta | Okta Support