Skip to content
  • There are no suggestions because the search field is empty.

Single Sign-on for Google Workspace

Step-by-step guide to setting up Google Workspace as your SAML SSO provider for Security Journey.

Google Workspace SSO Setup

Prerequisites 

Security Journey

  • An account with Admin privileges

Google Workspace

  • Google Admin access with super administrator privileges

Configuration Steps

Step 1: Add the Custom SAML App 
  1. Sign in to your Google Admin console.
    1. Sign in using an account with super administrator privileges
  2. In the Admin console, go to Menu > Apps > Web and mobile apps.
  3. Click Add App > Add custom SAML app.Enter the app name (Security Journey) and, optionally, upload an icon for your app. The app icon appears on the Web and mobile apps list, on the app settings page, and in the app launcher. If you don't upload an icon, an icon is created using the first two letters of the app name.
  4. Click Continue.
  5. On the Google Identity Provider details page, get the setup information needed by the service provider using one of these options:
    1. Download the IDP metadata.
    2. Copy the SSO URL
  6. Click Continue.
  7. In the Service Provider Details window, enter:
    1. ACS URLhttps://auth.hackedu.com/saml2/idpresponse
    2. Entity IDurn:amazon:cognito:sp:us-east-1_CHi5tsM8X
    3. Start URL—(Optional)

      https://my.securityjourney.com/login/?domain=company.com

      [You will need to add your company domain to the end of the Start URL]
  8. Set Name ID format and Name ID value for your custom SAML app. The default Name ID is the primary email.
  9. Click Continue.
  10. If needed, click Add mapping to map user attributes based on the service provider’s requirements. Security Journey only requires Name ID but additional attributes can be added to enrich your learner's profile, Platform reports or to create targeted training assignments. To learn more, check out Learner Attributes
  11. (Optional) To enter group names that are relevant for this app:
    1. For Group membership (optional), click Search for a group, enter one or more letters of the group name, and select the group name.
    2. Add additional groups as needed (maximum of 75 groups).
    3. For App attribute, enter the service provider’s corresponding groups attribute name.
  12. Click Finish  

Once app is created, you will need to upload the applications metadata to Security Journey's SSO Settings.

Step 2: Enable Your SAML Application
  1. Sign in to the Google Admin Console as a Super Administrator.
  2. Navigate to MenuAppsWeb and mobile apps.
  3. Select your Security Journey SAML application.
  4. Click User access.
Enable the application for your organization
  • To enable the application for all users, select On for everyone and click Save.
  • To disable the application, select Off for everyone and click Save.
(Optional) Enable the application for specific organizational units
  1. Select the desired Organizational Unit (OU) from the left navigation.
  2. Set the Service status to On or Off.
  3. If prompted:
    • Select Override to apply a different setting than the parent organizational unit.
    • Select Inherit to use the same setting as the parent organizational unit.
  4. Click Save.
(Optional) Enable the application for an access group

If you use Google Access Groups, you can enable the application for a specific group of users instead of an entire organizational unit. Select the appropriate access group and configure access as needed.

Important: Ensure that the email address users will use to sign in to Security Journey matches the email address associated with their Google Workspace account.

Note: Changes may take up to 24 hours to propagate throughout Google Workspace, although they are typically applied much sooner.


Troubleshooting

If you are seeing the following error, you are probably trying to login from the Google App Menu (IdP-initiated sign-on flow):

Invalid samlResponse or relayState from identity provider

Security Journey only supports SP-initiated sign-in. You can simulate this workflow by: 

  • Making a custom bookmark (or Google Workspace “shortcut” app) that points to the Security Journey's login URL instead of using Google’s app tile.

  • Label it with our app's name so users still get a “Google Apps-style” entry point.