JumpCloud’s Enterprise Portal (EP) centralizes the control and management of organizations from one place. This enables Enterprise admins to control all of their organizations efficiently, from a single, browser-based portal. EP Admins can view top-level data for all of their orgs at-a-glance. They can also securely launch full management sessions from the EP for any org they administer.
Configuring Google Workspace Single Sign-On (SSO) in the EP empowers you to centralize user access and enhance security for managed orgs. By enabling SSO, you simplify access for your end-users, allowing them to securely log in to Google Workspace using their JumpCloud credentials. This integration also allows you to enforce critical security controls, including JumpCloud's Multi-Factor Authentication (MFA) and Conditional Access Policies.
Prerequisites
- A JumpCloud user account with Admin with Billing permissions
- JumpCloud SSO Package or higher or SSO à la carte option
- In order to successfully complete the integration between JumpCloud and Google, you must have administrative rights to access configuration in your Google Workspace account
- Google Workspace subscription for Enterprise, Business, or Education
Considerations
- Non-profit or Standard (Free legacy) editions do not support SAML
- When a Google Super Admin tries to sign in to an SSO-enabled domain via admin.google.com, they will not be redirected to JumpCloud for authentication, but rather will be prompted for their full Google email address and associated password:
- Read Google’s full documentation on SSO-enabled domain redirects for Super Admins
Terminology:
- Global Configuration: The primary organization. This is where you manage the settings for all the organizations.
- Organizations: These are the managed sub-organizations.
Creating the Enterprise-Level SSO Application
To create a new Google SSO connector
- Log in to your EP.
- Click the Enterprise Configuration button.
- In the Left Nav, go to Access > SSO Applications.
- Click + Add New Application (or Get Started if this is your first application).
- Type Google Workspace in the Search field and select it.
- Click Next.
- In the Display Label, type your name for the application. Optionally:
- Enter a Description, and choose to hide or Show in User Portal
- Expand Advanced Settings to specify a value for the SSO IdP URL. If no value is entered, it will default to https://sso.jumpcloud.com/saml2/<application display label>.
The SSO IdP URL is not editable after the application is created. You will have to delete and recreate the connector if you need to edit this field at a later time.
- Click Save Application.
- If successful, click:
- Configure Application and go to the next section
- Close to configure your new application at a later time
To configure the SSO Integration
After creating the application, go to SSO with Google Workspace to complete the configuration.
Sharing Enterprise-Level Applications
- Log in to your EP.
- Go to Access > SSO Applications.
- Click on the name of the application and select the Organizations tab.
- Select the Organization(s) you would like to share the application with.
- Click Save.
Managing Access to SSO Applications
To manage organization access
Applications created at the organization level cannot be shared.
- Log in to your EP.
- Go to the Access > SSO Applications.
- Click on the name of the configuration and then select the Organizations tab.
- There are two options:
- Select the box next to the organizations where you want the configuration to be available
- Deselect the box next to the organizations where the configuration should no longer be available
- Click Save.
To manage organization group access
- Log in to your EP and use the Global Selector to navigate to your organization.
- Go to Access > SSO Applications.
- Find and select your SSO Application.
- Go to the User Groups tab.
- There are two options:
- Select the checkbox next to the user groups you want to give access
- Deselect the checkbox next to the user groups you want to remove access
- Click Save.