Integrate with Google SSO in the Enterprise Portal (Preview)

JumpCloud’s Enterprise Portal (EP) centralizes the control and management of organizations from one place. This enables Enterprise admins to control all of their organizations efficiently, from a single, browser-based portal. EP Admins can view top-level data for all of their orgs at-a-glance. They can also securely launch full management sessions from the EP for any org they administer.

Configuring Google Workspace Single Sign-On (SSO) in the EP empowers you to centralize user access and enhance security for managed orgs. By enabling SSO, you simplify access for your end-users, allowing them to securely log in to Google Workspace using their JumpCloud credentials. This integration also allows you to enforce critical security controls, including JumpCloud's Multi-Factor Authentication (MFA) and Conditional Access Policies.

Terminology:

  • Enterprise Portal: Portal where Enterprise Admins manage settings for multiple organizations under one Enterprise Configuration. Differs from the JumpCloud Admin Portal, which is for one organization
    • Enterprise (formerly Enterprise Configuration): Centralized hub for all the organizations' objects in the Enterprise Portal. Items can be created and shared for organizations in the Enterprise Portal from this hub
  • Organizations: A division of the enterprise (for example a region or a country) that maintains its own users, devices, and resources

Prerequisites:

  • Administrative rights to access configuration in your Google Workspace account
  • Google Workspace subscription for Enterprise, Business, or Education

Considerations:

  • Non-profit or Standard (Free legacy) editions do not support SAML
  • When a Google Super Admin tries to sign in to an SSO-enabled domain via admin.google.com, they will not be redirected to JumpCloud for authentication, but rather will be prompted for their full Google email address and associated password:

Creating the Enterprise-Level Google SSO Application

To create a new Google SSO connector

  1. Log in to your EP.
  2. Go to Access > SSO Applications.
  3. Click + Add New Application (or Get Started if this is your first application) and selectme for the application.
  4. Type <Google> in the Search field and select it.
  5. Click Next.
  6. In the Display Label, type your name for the application.
  7. Optionally, customize the display label, description and how the application displays:
    • Description - add a description that users will see in their user portal
    • User Portal Image - choose Logo or Color Indicator
    • Show in User Portal - enable to show the application tile in your organization's user portal
    • If needed, customize the IdP URL:
      • Expand Advanced Settings and enter the name you want to use for the end of the SSO IdP URLhttps://sso.jumpcloud.com/saml2/<applicationname>

Warning:

The SSO IdP URL is not editable after the application is created. You will have to delete and recreate the connector if you need to edit this field at a later time.

  1. Click Save Application.
  2. If successful, click:
    • Configure Application and go to the next section
    • Close to configure your new application at a later time

To configure the SSO Integration

Note:

Users must be added before any changes can be made to the SSO configuration, like attribute mappings.

After creating the application, go to SSO with Google Workspace to complete the configuration.

Managing Access to SSO Applications

To manage organization access

Note:

Applications created at the organization level cannot be shared.

  1. Log in to your EP.
  2. Go to the Access > SSO Applications.
  3. Click on the name of the configuration and then select the Organizations tab.
  4. There are two options:
    • Select the box next to the organizations where you want the configuration to be available
    • Deselect the box next to the organizations where the configuration should no longer be available
  5. Click Save.

To manage organization group access

  1. Log in to your EP and use the Global Selector to navigate to your organization.
  2. Go to Access > SSO Applications.
  3. Find and select your SSO Application.
  4. Go to the User Groups tab.
  5. There are two options:
    • Select the checkbox next to the user groups you want to give access
    • Deselect the checkbox next to the user groups you want to remove access
  6. Click Save.
Back to Top

List IconIn this Article

Still Have Questions?

If you cannot find an answer to your question in our FAQ, you can always contact us.

Submit a Case