In some scenarios, after setting up SAML SSO for the Google Workspace app, users on ChromeOS/Chromebook are not redirected to Okta for authentication when trying to access Google Workspace apps. Instead, they can authenticate directly with their Google Workspace credentials.
- Bypassing SSO for Google Workspace
- Security Assertion Markup Language (SAML)
- Single Sign-On (SSO)
This could be caused by "SAML-based single sign-on for Chrome devices" being disabled on the Google Workspace side. SAML SSO support for ChromeOS devices is enabled separately, even if the Okta SSO profile was already set up.
In order to enable "SAML-based single sign-on for Chrome devices":
- In the Admin console, go to Menu > Devices > Chrome > Settings. The User & browser settings page opens by default.
- Scroll down to Security.
- Click Single sign-on.
- Select Enable SAML-based single sign-on for Chrome devices.
- Click Save.
