Google Workspace
is a set of online productivity and collaboration tools
that includes the corporate versions of Gmail, Calendar, Meet, and more.
You can use Google Workspace as an identity provider (IdP) for DoubleCloud,
so that users can use their Google Workspace credentials to log in to DoubleCloud.
In the top bar, click your organization name → Manage organization.
Select Members from the panel on the left and switch to the Federations tab.
Click Create and enter the following details in the form:
Name: Your federation name, such as Google Workspace.
Cookie lifetime: Desired cookie lifetime.
IdP Issuer:
Enter the value from the Entity ID field on the Google Workspace page.
It has the https://accounts.google.com/o/saml2?idpid=<app-id> format.
Login URL:
Enter the value from the SSO URL field on the Google Workspace page.
It has the https://accounts.google.com/o/saml2/idp?idpid=<app-id> format.
`
Under Advanced, enable Automatically create users
if you want to add users to your organization automatically when they sign in.
If you keep it disabled, you’ll need to manually add your federated users.
Click Create federation.
The Federation overview page will open.
Click Add Certificates and upload the SAML certificate you downloaded from the Google IdP information page.
Keep the Federation overview page open.
Step 3. Finish configuration in Google Workspace
On the Federation overview page in the DoubleCloud console,
copy the value from Link to federation login page.
Switch back to the Google identity provider details page in the Google Admin console and click Continue.
On the Service provider details page,
enter the federation login page URL
you just copied in the ACS URL and Entity ID fields.
This URL has the https://auth.double.cloud/federations/<id> format.
Enable Signed response.
Click Continue.
Step 4. Map user attributes
On the Attribute mapping page,
click Add mapping under Attributes and add the following mappings one by one: