<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Okta Classic Engine

l380v (l380v) asked a question.

Adding an additional Google Workspace using Third party SSO IDP

So I'm trying to configure an additional Google Workspace via SSO third party IDP.

 

What should I enter for the IDP entity ID? I can't locate an URL that works... The IDP entity ID is a required field.

 

 

 

Nothing on the generated SAML setup instructions references this field / or works.

 

Also tried details in the SAML metadata page...

 

Image is not available


  • JunM.24685 (Customer)

    1. Create a SSO profile on GWS
    2. Create a SAML app in Okta, use SP Entity ID/ACS URL from GWS SSO profile.
    3. Get the new SAML application IDP metadata, you need the entityID/SSO location in it and fill them in GWS SSO profile
    4. Fill in the rest in GWS SSO profile, upload the X.509 cert.
    Expand Post
    Selected as Best
  • Marques Stewart (Achievement First)

    I'm in the same boat as Kai. Can't figure out what exactly is supposed to go into that IDP identity field.

  • l380v (l380v)

    @Paul S. (Okta, Inc.)​ Hi Paul, seems that more than one person don't understand what you are saying....

  • Paul S. (Okta, Inc.)

    @l380v (l380v)​  Thank you for the additional details. I have looked further into this and the entity ID should look something like "google.com/a/acem.com" where acme.com would be your google company domain. Please try that and let me know if that works.

    CC @Marques Stewart (Achievement First)​ 

    • l380v (l380v)

      @Paul S. (Okta, Inc.)​ I see where you are getting this format.

      @Marques Stewart (Achievement First)​ If you select the active SAML cert in the additional Google Workspace app - View IDP meta data. In the XML you can find the Entity ID Paul is suggesting we try.

       

      However, no joy for me either.

       

      Looking on the Google side, their format of the Entity ID looks like this:

      https://accounts.google.com/o/saml2?idpid=a00112233bb44

      (Admin console - Security - SSO with Google as SAML IdP)

       

      I suspect Google is expecting a URL that they can reference....

      Image is not available

      Expand Post
      • Marques Stewart (Achievement First)

        Thanks - I see now where he got that Entity ID from as well, but still no dice. Even just tried to put the URL from the metadata certificate in that slot, no change.

  • Paul S. (Okta, Inc.)

    @Marques Stewart (Achievement First)​  and @l380v (l380v)​  I have further investigated this issue and what I was able to find is that this Google Workspace option is not compatible with the OIN application and you would need to configure a Custom SAML application on Okta side.

    However to confirm this I would recommend to check this with Google Workspace Support as well.

     

    Hope this helps!

    Expand Post
    • Marques Stewart (Achievement First)

      That's not a great answer since Google is a pretty big Workspace vendor. Why isn't it compatible and what would it take to make it compatible?

       

      Is Okta working on instructions on how to use this new functionality with a Custom SAML application? What exactly would Google Workspace support say about configuring a custom SAML application within Google - i feel they would just say 'talk to Okta'.

      Expand Post
  • Paul S. (Okta, Inc.)

    Hello @Marques Stewart (Achievement First)​  In order to make the OIN compatible with this new Google Workspace, google needs to reach out to Okta to update the application.

     

    For the Custom SAML application you need to add a SAML app in Okta and after you add it you have the required information on the View Setup Instruction

    Please see our instructions on Custom SAML apps:

    https://help.okta.com/en-us/Content/Topics/Apps/Apps_App_Integration_Wizard_SAML.htm

    Expand Post
  • JunM.24685 (Customer)

    I've succeeded with a customized SAML2 application, you must use SP Entity ID/SP ACS URL from Google's SSO profile, the one from OIN will not work since SP ID/ACS are fixed in official GWS app.

This question is closed.
Loading
Adding an additional Google Workspace using Third party SSO IDP