Configure Google SAML for SSO
Connect a Google custom SAML app to Azion as the identity provider of your account, so users sign in to Azion Console with their Google identity.
You can make a Google custom SAML app the identity provider (IdP) of your Azion account, so users sign in to Azion Console with their Google corporate identity and no separate Azion password. The work alternates between Google Admin and Azion Console. For the Azion side alone, or for an Open ID provider, refer to Configure an identity provider for SSO.
Prerequisites
- Administrator access to the Google account.
- Access to Azion Console as an Account owner. To sign in, refer to Access Azion Console.
- Every user of the account registered in Azion. The IdP and Azion hold the same users, and a user that does not exist in Azion cannot sign in. To add users, refer to Manage users.
Create the SAML app in Google
Google Admin issues the three values that Azion needs: the SSO URL, the entity ID, and a certificate.
To create the app in Google Admin:
- Go to Google Admin Console.
- In the menu, select Apps > Web and mobile apps.
- Select Add App > Add custom SAML app.
- On the App Details page, enter a name for the app and select Continue.
- On the Identity Provider details page, copy the SSO URL and the Entity ID.
- On the same page, download the certificate.
You now hold the SSO URL, the entity ID, and the certificate file for the Azion form.
Create the identity provider in Azion Console
The Create Identity Provider form takes the Google values. Azion then generates the values that Google needs back.
To create the identity provider:
Access Azion Console and, in the account menu, select SSO Management.
Select Add Identity Provider. In Select the Identity Provider, select SAML.
In the General section, enter a Name. For example: Google IdP.
In the SAML Configuration section, enter the Google Entity ID in Identity provider’s Entity ID URI and the SSO URL in Sign-in URL.
In X-509 Certificate, paste the certificate, including the -----BEGIN CERTIFICATE----- and -----END CERTIFICATE----- lines.
In the Identity Providers list, select the identity provider. In Edit Identity Provider, copy Assertion Consumer Service URL, Service Provider’s Entity ID URI, and Sign-in URL.
The identity provider appears in the Identity Providers list. Do not set it as active until the Google app carries the Azion values.
Complete the SAML app in Google
The Service Provider Details page of the Google app takes the values you copied from Azion Console.
To finish the app in Google Admin:
- In Google Admin, open the Service Provider Details of the app.
- In ACS URL, paste the Assertion Consumer Service URL.
- In Entity ID, paste the Service Provider’s Entity ID URI.
- (Optional) In Start URL, paste the Sign-in URL.
- Select the Signed Response checkbox.
- In Name ID format, select UNSPECIFIED.
- In Name ID, select Basic Information > Primary email.
- Select Continue.
- On the Attribute mapping page, select Add Another Mapping.
- In Google Directory attributes, select Basic Information > Primary email.
- In App Attributes, enter
email. - Select Finish.
The Google app sends the primary email of each user to Azion as the email attribute.
Assign users in Google
The app is off for your organization until you change its user access.
To turn on the app for your users:
- In Google Admin Console, select Apps > Web and mobile apps.
- Select the SAML app.
- Select User access.
- Select On for everyone. To turn the app off later, select Off for everyone.
- Select Save.
Every user in your Google organization can now reach the app.
Set the identity provider as active
To activate the identity provider:
Access Azion Console and, in the account menu, select SSO Management.
In the row of the identity provider, select Set as active.
Every user of the account, except the Account owner, signs in to Azion Console through Google. While Google is the IdP, Google verifies multi-factor authentication (MFA) instead of Azion. When the account goes back to the Azion login, each user keeps the MFA status that was last active.