<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D51Y00005vTdXmSAKOkta Classic EngineSingle Sign-OnAnswered2024-07-08T09:00:27.000Z2019-01-30T18:45:10.000Z2019-02-01T06:45:41.000Z

zazo5 (zazo5) asked a question.

Okta to Gsuite SAML and shared accounts

We have a number of shared accounts that we utilize in Gsuite between a large number of people. Once we flip google to be using SAML logins from okta, is there any way that we can still utilize these shared accounts or are we going to have to look at a different solution?

 

Suggestions appreciated!


  • 7fhli (7fhli)

    Yes, you just create a new G Suite app instance for each shared account. The SAML certificate remains the same across each app instance.

  • zazo5 (zazo5)

    And then would I just have to give everyone individually the shared username in their app assignment? Looks like you can't do that by group for google saml

  • zazo5 (zazo5)

    Or can I do this through profile mappings?

  • GabrielL.85945 (Customer)

    Hello Ryan. Matt's suggest will technically work, but I wouldn't suggest it. There's a few potential issues.

     

    1. It is correct the certificate is the same. However, this is something that could change in the future. Okta migrated from SHA1 to SHA256 certs a couple years back. Existing apps would keep the SHA1 certs, but newly created apps would be SHA256. So if something like this happened again, you'd need to update the certs.
    2. IdP-initiated logins would work, but SP-initiated logins would only be directed to one app.
    3. It's just not considered best practice to allow users to assume the identity of another use account. It's not good for leaving an audit trail.

     

    My understanding is G Suite has existing tools on their end to share mailboxes and other data with other users. Does G Suite not have the functionality you need for this on their end?

    Expand Post
This question is closed.
Loading
Okta to Gsuite SAML and shared accounts