Learn how to configure Single Sign-On using SAML protocol in Google Workspace to authenticate users to your Staffbase platform.
In this article, you will learn how to set up
SSO is optional for user management. You can choose an option based on your business requirements. Learn more about other options.
For creating an app integration in Google Workspace, you need to receive the following from Staffbase Support:
You need to create a Custom SAML App in Google Workspace to set up SSO.
Staffbase recommends creating a dedicated application to maintain users for your Staffbase platform.
You need to provide the metadata you downloaded to Staffbase.
The Name ID value and the identifier in your Staffbase platform must match for each user using SSO.
If you want to use a different identifier value than the one already in place for your users in the Staffbase platform, you must first update the user identifiers in your Staffbase platform. In such a case, ensure that you also use these new identifiers for all future user management.
Google Directory attribute: Basic Information > First Name
->
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
Google Directory attribute: Basic Information > Last Name
->
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname
Google Directory attribute: Basic Information > Primary email
->
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
Provide Staffbase the IdP Metadata for the app you created.
You can download the Idp Metadata in step 5 of the Creating a Custom SAML App section. Alternatively, you can find it in the overview of the app you created.
After creating the app, you can decide which Google Workspace users need access to the Staffbase platform using SSO.
Staffbase recommends adding a few users initially to test that everything works as expected.
The Settings for users opens.
On the left side, you can turn ON the service only for specific groups or organizational units.
Search for the user or group you want to add and click Assign.
You have assigned users or groups to the app integration.
After you have provided Staffbase Support with the Metadata, you will be informed when SSO was added to your Staffbase instance and is ready for testing.
After testing the SSO authentication works as expected, you can add all users and/or groups in Google Workspace to the app.
You have configured and enable SSO for your Staffbase platform.