Administrator

How do I set up Google SSO for my domain?

Follow
Ryan Richins
  • Agilix team member
  • Updated:
    info_outline
    Created:

This article explains how to configure a custom SAML application in Google so that your users can authenticate into Buzz with their Google credentials.

Many of the following steps are modified from the provided Google directions found at Set up your own custom SAML application. If any of them are out of date, you may refer to the Google article.

Requirements:

  • Your institution must have a G Suite account.
  • For a Buzz user to authenticate using Google SSO, their Buzz username must match their G Suite email address.

Set up your own custom SAML app for Buzz

  1. Sign in to your Google Admin console.
  2. From the Admin console Home page, go to Apps > SAML Apps.
  1. Click the plus (+) icon in the bottom corner.
  1. Click Setup my own custom app.
  1. Download the IDP metadata. This will be used later for configuring Buzz.
  1. Click Next.
  2. In the Basic Application Information window, add an application name (e.g., Buzz) and description.
  3. (Optional) Click Choose file next to the Upload Logo field to upload a PNG or GIF file to serve as an icon. The file size should be 256 pixels square.
  1. Click Next.
  2. In the Service Provider Details window, add an ACS URL, an Entity ID, and a Start URL. The ACS URL, the Entity ID and other information can be found at https://api.agilixbuzz.com/SAML/USERSPACE/metadata.xml, but can be found below for easier configuration.
    1. ACS (AssertionConsumerService) URL: https://api.agilixbuzz.com/SAML/USERSPACE/Consumer
    2. Entity ID: https://api.agilixbuzz.com/SAML/USERSPACE
    3. Start URL: https://USERSPACE.agilixbuzz.com/home

Note

  • Replace “USERSPACE” with your domain’s userspace wherever it appears.
  • If you have a custom URL for Buzz, then your Start URL would be https://USERSPACE.CUSTOM_URL.com/home, replacing “CUSTOM_URL” with your custom URL.
  1. Leave Signed Response unchecked.
  2. Click Next.
  3. Click Finish.

Turn on SSO to your new SAML app

  1. Sign in to your Google Admin console.
  2. From the Admin console Home page, go to Apps > SAML Apps.
  3. Click your new SAML app.
  1. At the top right of the gray box, click Edit Service.
  1. At the left, the top-level organization and any organizational units appear. Ensure that your user account email IDs match those in the domain for your Google service.
  2. Select ON for everyone to enable SSO for the listed organizations.
  1. Click Save.

Note

Once enabled, some users will be able to attempt to authenticated into Buzz with their Google credentials. However, they will not successfully be able to do so until you have configured Buzz to use the Google SSO in the following section.

Configure Buzz to use the new Google SSO

  1. Go to the Admin app in Buzz for the USERSPACE you configured in Google.
  2. Open the vertical menu in the toolbar of Domain Details and select Domain Settings.
  1. On the Authentication card, select SAML as your authentication Type.
  1. Locate the previously downloaded IPD metadata file (see step 5 of the Set up your own custom SAML app for Buzz section).
  2. Rename the file to idp-meta.xml.
  3. Click the upload icon for the idp-meta.xml field.
  1. Click Choose File, locate and select the “idp-meta.xml” file provided from Google, which you renamed in step 6 and click Open.
  2. Click Upload.
  3. Select the Open login in a new window checkbox.
  4. Save.

Note

This option is required as Google does not allow their sign-on screen to be displayed within another website.

Verify SSO between your Google service and Buzz

  1. Go to your Buzz login page.
  2. Click Login to launch the Google SSO.
  1. Enter your G Suite credentials.
  2. After your G Suite credentials are authenticated you will be automatically redirected back to your Buzz home page.

Comments

Please sign in to leave a comment.