Skip to main content

Configure G Suite for Custom SAML App

To configure devices using G Suite credentials with SSO, follow the steps below:

  1. Log in to https://admin.google.com with G Suite credentials.

  2. Under Home, click Apps.

  3. Click Web and Mobile Apps.

  4. Select Add App and click Add Custom SAML App from the drop-down list.

  5. On the Add Custom SAML App page, enter the App details and click Continue.

  6. On the following screen, under Google IdP Details, click Continue without making any changes.

  7. In the next 'Service Provider Details' screen, configure Single Sign-on, input Service Provider details, including ACS URL and entity ID, and then click Continue.

note

An example of an ACS URL and Entity ID is given below:

  • Add your SureMDM DNS name and Account ID as:
https://<DNS Name>/console/sharedsaml?id=<account id>

For example: https://suremdm.42gears.com/sharedsaml?id=xxxx

  • Entity Id as: urn:42gears:suremdm:SAML2ServiceProvider
  1. In the 'Attribute Mapping' page, click Add Mapping and provide the following details:
  • Employee Details: Select a parameter from the 'Google directory attributes' list.
  • App Attributes: User-defined meta tag, then click Finish.
note

App Attributes will be your meta tag value.

Reference screenshots: Steps 1–8

Configure G Suite for Custom SAML App - Part 1
1 / 6
  1. Go to the Web and Mobile Apps screen and click on the created SAML App.

  2. In the App Details screen, the 'User Access' option is initially set to 'OFF for everyone' by default. Change it to 'On for everyone' and click Save.

  3. Click DOWNLOAD METADATA in App details.

  4. Copy SSO URL, Entity ID. Click Download to download the certificate, and then click Close.

note

SSO URL, Entity ID, and Certificate details are required while configuring SSO in SureMDM.

Reference screenshots: Steps 9–12

Configure G Suite for Custom SAML App - Part 2
1 / 6

Once the existing user is available, tap on the user

  1. Click User Information.

  2. Enter the required fields in User Information (the same details can be used at the time of profile creation while configuring SureLock settings) and click Save.

note

Attribute Statements:

Attribute statements are used to send user-specific attributes to the service provider during SAML authentication.

Reference screenshots: Steps 13–14 and Attribute Statements

Configure G Suite for Custom SAML App - Part 3
1 / 4

💬 Help us improve this documentation

Was this information useful?

Your feedback helps us keep our documentation accurate, up to date, and useful.