Platform Secure Firewall Threat Defense Virtual
Activity Manage

Integrating Google Identity with Security Cloud Sign On

This guide explains how to integrate a Google Identity SAML application with Security Cloud Sign On.

Before you begin

Before you begin, read the Integrating Identity Providers to understand the overall process. These instructions supplement that guide with details specific to Google Identity integrations, specifically Step 2: Provide Security Cloud SAML metadata to your identity provider and Step 3: Provide SAML metadata from your IdP to Security Cloud.

Procedure

1

Sign in to Security Cloud Control with the organization you want to integrate with Google.

  1. Create a new identity provider and decide whether to opt out of Duo MFA, as explained in Step 1: Initial setup.

  2. On Step 2: Provide Security Cloud SAML metadata to your identity provider, download the Public certificate, and copy the values for Entity ID and Single Sign-On Service URL for use in the next steps.

2

In a new browser tab, sign in to your Google Admin console using an account with super administrator privileges. Keep the Security Cloud Control tab open.

  1. In the Admin console, go to Menu > Apps > Web and mobile apps.

  2. Click Add App > Add custom SAML app.

  3. On the App Details page:

    • Enter Secure Cloud Sign On or other value for the application name.

    • Optionally, upload an icon to associate with the application.

  4. Click Continue to go to the Google Identity Provider details page.

  5. Click Download Metadata to download the Google SAML metadata file for later use.

  6. Click Continue to go to the Service provider details page.

  7. In the ACS URL field, enter the Single Sign-On Service URL provided by Security Cloud Control.

  8. In the Entity ID field, enter the Entity IDURL provided by Security Cloud Control.

  9. Check the Signed Response option.

  10. For Name ID Format, select either UNSPECIFIED or EMAIL.

  11. For Name ID, select Basic Information > Primary Email.

  12. Click Continue to advance to the Attribute mapping page.

  13. Add the following mappings of Google Directory attributes to App attribute:

    Google Directory attributes

    App attributes

    First name

    firstName

    Last name

    lastName

    Primary email

    email

  14. Click Finish.

3

Return to Security Cloud Control and click Next. You should be on Step 3: Provide SAML metadata from your IdP to Security Cloud.

  1. Select the XML file upload option.

  2. Upload the SAML metadata file that you previously downloaded from Google.

  3. Click Next to advance to the Testing page.

What to do next

Next, follow the instructions in Step 4: Test your SAML integration and Step 5: Activate the integration to test and activate your integration.