How do I Configure SAML2 Single Sign-on (Authentication) to use Google Workspace SSO?

Modified on Thu, 2 Feb, 2023 at 1:43 PM

Follow the steps below to configure single sign-on with Google Workspace.

 

  1. Log in to Google Workspace admin account (https://admin.google.com)

  2. Go to Apps > Web and mobile apps

     


  3. Click on Add app, then select Add custom SAML app

     


  4. Name the app "Fortinet Security Awareness and Training Service" then click Continue

  5. Click Continue again

  6. In your Fortinet app, copy the ACS URL, then paste the value in the ACS URL field in Google



  7. Then copy the SP Entity ID URL from Fortinet, and paste the value in the ‘Entity ID’ field in Google



  8. Start URL is not required

  9. Select the Name ID format dropdown and select Email

  10. Ensure that the Name ID field is displaying Basic Information > Primary email



  11. Click Continue

  12. Add attribute mappings and edit them as shown in the screenshot below



  13. Click Finish

  14. On the home page for the new custom app, click on Download Metadata



  15. Under Option 1, click on Download Metadata. This will now download an XML metadata file

  16. In your Fortinet Authentication settings, under Step 3, click the radio button for XML File
  17. Drag and drop the downloaded ‘GoogleIDPMetadata.xml’ file

  18. Click on Save Changes

 

NOTE: In Google, you may need to enable user access to the new app. This can be done by going to “User access” and enabling access for all users.


Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article