{"id":89910,"date":"2023-06-07T15:38:39","date_gmt":"2023-06-07T19:38:39","guid":{"rendered":"https:\/\/jumpcloud.com\/?post_type=support&p=89910"},"modified":"2024-07-23T02:08:04","modified_gmt":"2024-07-23T06:08:04","slug":"sso-with-google-workspace","status":"publish","type":"support","link":"https:\/\/jumpcloud.com\/support\/sso-with-google-workspace","title":{"rendered":"SSO with Google Workspace"},"content":{"rendered":"\n
In addition to the JumpCloud Google Workspace Cloud Directory Integration<\/a> (which enables the provisioning and synchronization of your Google Workspace users from JumpCloud), you can also choose to configure the Google Workspace SAML SSO Connector. <\/p>\n\n\n\n <\/p><\/div> Learn more about the difference between JumpCloud’s Google Workspace Integration and Google Workspace SSO connector<\/a>. <\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n The Google Workspace connector provides users with single sign on (SSO) capabilities. They are redirected to the JumpCloud login screen enabling them to log into Google Workspace with their JumpCloud credentials. Using JumpCloud SSO with Google Workspace not only passes user authentication responsibilities to JumpCloud, it also allows the option to enforce JumpCloud MFA<\/a> for authentication and the ability to enforce Conditional Access Policies<\/a>. <\/p>\n\n\n\n Read this article to learn how to set up Google Workspace SSO.<\/p>\n\n\n\n <\/p><\/div> Read the SAML Configuration Notes<\/a> before you start configuring this connector.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Prerequisites<\/strong><\/p>\n\n\n\n Important Considerations<\/strong><\/p>\n\n\n\n <\/p><\/div> The SSO IdP URL<\/strong> is not editable after the application is created. You will have to delete and recreate the connector if you need to edit this field at a later time.<\/p>\n <\/div><\/div><\/div><\/div>\n\n\n\n Google Workspace allows mixed SSO policies through the use of SSO profiles. This is also called Partial SSO<\/em> and gives you the flexibility to specify the authentication authority (JumpCloud or Google) for subsets of users in your organization, like vendors or contractors. <\/p>\n\n\n\n Google’s SSO profiles provide flexibility to include or exclude specific user groups or organizational units (OUs) from SSO through assignments <\/em>within your Google Workspace environment. There are two types of SSO profiles; <\/p>\n\n\n\n\n
\n
\n
Creating a new JumpCloud Application Integration<\/strong><\/h2>\n\n\n\n
\n
\n
\n
Configuring the SSO Integration<\/strong><\/h2>\n\n\n\n
To configure Google SSO Profile<\/strong>(s)<\/h3>\n\n\n\n