<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00007rCXIMCA4Okta Classic EngineIntegrationsAnswered2024-04-16T10:19:24.000Z2022-07-22T23:36:57.000Z2022-12-28T22:24:01.000Z

l380v (l380v) asked a question.

Adding an additional Google Workspace using Third party SSO IDP

So I'm trying to configure an additional Google Workspace via SSO third party IDP.

 

What should I enter for the IDP entity ID? I can't locate an URL that works... The IDP entity ID is a required field.

 

 

 

Nothing on the generated SAML setup instructions references this field / or works.

 

Also tried details in the SAML metadata page...

 

Image is not available


  • JunM.24685 (Customer)

    1. Create a SSO profile on GWS
    2. Create a SAML app in Okta, use SP Entity ID/ACS URL from GWS SSO profile.
    3. Get the new SAML application IDP metadata, you need the entityID/SSO location in it and fill them in GWS SSO profile
    4. Fill in the rest in GWS SSO profile, upload the X.509 cert.
    Expand Post
    Selected as Best
  • Hello @l380v (l380v)​ Thank you for reacting out to our Community!

     

    The Entity ID would be the equivalent of Identity Provider Issuer, from the SAML Setup instructions.

    Also Sign-in page URL would be the Identity Provider Single Sign-On URL .

     

    Hope this helps and if this answered your question, please mark this as Best Answer! 

    Expand Post
  • l380v (l380v)

    Here's the generic SAML setup instructions as I sees it.... Can you help me find the Identity Provider Issuer details?

    I must be missing something... I got the same thing from Okta support...

     

    Image is not available
    Image is not available
    Image is not available

    Expand Post
  • Marques Stewart (Achievement First)

    I'm in the same boat as Kai. Can't figure out what exactly is supposed to go into that IDP identity field.

    • l380v (l380v)

      @paul.stiniguta1.508386743840768E12 (Okta, Inc.)​ I see where you are getting this format.

      @Marques Stewart (Achievement First)​ If you select the active SAML cert in the additional Google Workspace app - View IDP meta data. In the XML you can find the Entity ID Paul is suggesting we try.

       

      However, no joy for me either.

       

      Looking on the Google side, their format of the Entity ID looks like this:

      https://accounts.google.com/o/saml2?idpid=a00112233bb44

      (Admin console - Security - SSO with Google as SAML IdP)

       

      I suspect Google is expecting a URL that they can reference....

      Image is not available

      Expand Post
      • Marques Stewart (Achievement First)

        Thanks - I see now where he got that Entity ID from as well, but still no dice. Even just tried to put the URL from the metadata certificate in that slot, no change.

  • @Marques Stewart (Achievement First)​  and @l380v (l380v)​  I have further investigated this issue and what I was able to find is that this Google Workspace option is not compatible with the OIN application and you would need to configure a Custom SAML application on Okta side.

    However to confirm this I would recommend to check this with Google Workspace Support as well.

     

    Hope this helps!

    Expand Post
    • Marques Stewart (Achievement First)

      That's not a great answer since Google is a pretty big Workspace vendor. Why isn't it compatible and what would it take to make it compatible?

       

      Is Okta working on instructions on how to use this new functionality with a Custom SAML application? What exactly would Google Workspace support say about configuring a custom SAML application within Google - i feel they would just say 'talk to Okta'.

      Expand Post
10 of 19
This question is closed.
Loading
Adding an additional Google Workspace using Third party SSO IDP