Google IDM SSO

Set up SAML SSO with Google Workspace to streamline authentication for your organization.

In this article

Requirements

Set up AppStore SAML Profile

Assign SAML Profile to OUs

Share Entity ID and ACS URL with SchoolDay team

Google IDM lets SchoolDay users access Google Workspace applications through Single Sign-On (SSO) without entering their credentials. It uses the SAML protocol and requires configuration in each Google Workspace to be activated.

To configure SAML SSO in Google Workspace, first set up a SAML profile in AppStore, then assign it to the desired Organizational Units (OUs) and share the entity ID and ACS URL with SchoolDay.

Requirements

Set up SAML Profile 

  1. Sign in to the Google Admin console as an administrator.
  2. Go to Security > Authentication > SSO with third-party IdP.
  3. Click Add SAML profile.
  4. Under the Third-party SSO profiles, enter AppStore SAML metadata.

    • SSO Profile Name: sso.gg4l.com
    • IDP entity ID: https://sso.gg4l.com/idp
    • Sign-in page URL: https://sso.gg 4l.com/saml2/Redirect/SSO
    • Sign-out page URL: https://sso.gg4l.com/auth/logout
  5. Click Upload Certificate, then import the AppStore SAML certificate into the SAML profile.
  6. Click Save.

Assign SAML Profile to OUs

  1. Under the Manage SSO profile assignments section, click Manage.
  2. Select Another SSO Profile and choose your AppStore SAML profile.

  3. Choose the option Have Google prompt for their username, then redirect them to this profile's IDP sign-in page.
  4. Click Save.

Share Entity ID and ACS URL with SchoolDay team

  1. Navigate to Security > Authentication > SSO with third party IdP.
  2. Open your SAML Profile.
  3. Find and copy values for Entity ID and ACS URL.
  4. Provide these values to the SchoolDay team at support@schoolday.com.