---
name: azion-configure-google-saml-for-sso
description: >-
  Connect a Google custom SAML app to Azion as the identity provider of your account, so users sign in to Azion Console with their Google identity.
---

# Configure Google SAML for SSO

You can make a Google custom SAML app the identity provider (IdP) of your Azion account, so users sign in to Azion Console with their Google corporate identity and no separate Azion password. The work alternates between Google Admin and Azion Console. For the Azion side alone, or for an Open ID provider, refer to [Configure an identity provider for SSO](/en/documentation/guides/platform/account-and-billing/sso/).

---

## Prerequisites

- Administrator access to the Google account.
- Access to Azion Console as an **Account owner**. To sign in, refer to [Access Azion Console](/en/documentation/guides/platform/account-and-billing/how-to-access-azion-console/).
- Every user of the account registered in Azion. The IdP and Azion hold the same users, and a user that does not exist in Azion cannot sign in. To add users, refer to [Manage users](/en/documentation/guides/platform/account-and-billing/users-management/).

---

## Create the SAML app in Google

Google Admin issues the three values that Azion needs: the SSO URL, the entity ID, and a certificate.

To create the app in Google Admin:

1. Go to [Google Admin Console](https://admin.google.com).
2. In the menu, select **Apps** > **Web and mobile apps**.
3. Select **Add App** > **Add custom SAML app**.
4. On the App Details page, enter a name for the app and select **Continue**.
5. On the *Identity Provider details* page, copy the *SSO URL* and the *Entity ID*.
6. On the same page, download the certificate.

You now hold the SSO URL, the entity ID, and the certificate file for the Azion form.

---

## Create the identity provider in Azion Console

The **Create Identity Provider** form takes the Google values. Azion then generates the values that Google needs back.

To create the identity provider:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**.

2. **Open the create form**

   Select **Add Identity Provider**. In **Select the Identity Provider**, select *SAML*.

3. **Name the identity provider**

   In the **General** section, enter a **Name**. For example: `Google IdP`.

4. **Enter the Google values**

   In the **SAML Configuration** section, enter the Google *Entity ID* in **Identity provider's Entity ID URI** and the *SSO URL* in **Sign-in URL**.

5. **Add the certificate**

   In **X-509 Certificate**, paste the certificate, including the `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` lines.

6. **Select Save**

7. **Copy the Azion values**

   In the **Identity Providers** list, select the identity provider. In **Edit Identity Provider**, copy **Assertion Consumer Service URL**, **Service Provider's Entity ID URI**, and **Sign-in URL**.

The identity provider appears in the **Identity Providers** list. Do not set it as active until the Google app carries the Azion values.

---

## Complete the SAML app in Google

The *Service Provider Details* page of the Google app takes the values you copied from Azion Console.

To finish the app in Google Admin:

1. In Google Admin, open the **Service Provider Details** of the app.
2. In **ACS URL**, paste the **Assertion Consumer Service URL**.
3. In **Entity ID**, paste the **Service Provider's Entity ID URI**.
4. (Optional) In **Start URL**, paste the **Sign-in URL**.
5. Select the *Signed Response* checkbox.
6. In **Name ID format**, select *UNSPECIFIED*.
7. In **Name ID**, select *Basic Information > Primary email*.
8. Select **Continue**.
9. On the Attribute mapping page, select **Add Another Mapping**.
10. In **Google Directory attributes**, select *Basic Information > Primary email*.
11. In **App Attributes**, enter `email`.
12. Select **Finish**.

The Google app sends the primary email of each user to Azion as the `email` attribute.

---

## Assign users in Google

The app is off for your organization until you change its user access.

To turn on the app for your users:

1. In [Google Admin Console](https://admin.google.com), select **Apps** > **Web and mobile apps**.
2. Select the SAML app.
3. Select **User access**.
4. Select **On for everyone**. To turn the app off later, select **Off for everyone**.
5. Select **Save**.

Every user in your Google organization can now reach the app.

---

## Set the identity provider as active

To activate the identity provider:

1. **Open SSO Management**

   Access [Azion Console](https://console.azion.com/) and, in the account menu, select **SSO Management**.

2. **Set the identity provider as active**

   In the row of the identity provider, select **Set as active**.

3. **Select Confirm**

Every user of the account, except the Account owner, signs in to Azion Console through Google. While Google is the IdP, Google verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.

---

## Next steps

- [Configure Microsoft Entra SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-microsoft-entra-saml.md): Use a Microsoft Entra enterprise application as the IdP instead.
- [Configure Okta SAML for SSO](/en/documentation/guides/application-security/access-and-compliance/sso-okta-saml.md): Use an Okta SAML 2.0 app integration as the IdP instead.
- [Configure an identity provider for SSO](/en/documentation/guides/platform/account-and-billing/sso.md): Add any SAML or Open ID provider in SSO Management.
- [Manage users](/en/documentation/guides/platform/account-and-billing/users-management.md): Register every user who signs in through the IdP.
