# Google Workspace

## Overview

[Google Workspace](https://workspace.google.com), formerly known as G Suite, is a collection of cloud services and software products developed by Google. This article describes how to set up Google Workspace as an SSO provider in order to access [VGS Dashboard](https://dashboard.verygoodsecurity.com).

## Setup

1. Sign in to your [Google Admin console](https://admin.google.com/) and navigate to **Apps** > **SAML apps**.

<figure><img src="https://1773866054-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzbOVGj5YTirkppRKlOP9%2Fuploads%2F028pzI31QN3laQETKTCV%2Fgw1.png?alt=media&#x26;token=6e8b9f1c-a8c7-498b-a75e-45e19d216167" alt=""><figcaption></figcaption></figure>

2. Select **Add custom SAML app** from the **Add App** dropdown list in the upper left corner of the screen.
3. Give the app a name and click **Continue**.

<figure><img src="https://1773866054-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzbOVGj5YTirkppRKlOP9%2Fuploads%2FwnU4LoqF9Eo61cJ6QFA3%2Fgw5.png?alt=media&#x26;token=83dc144f-57dd-4aad-8e8e-89ae0650b8d9" alt=""><figcaption></figcaption></figure>

4. On the **Google Identity Provider details** page, download the **IDP metadata** file and send it to [support@vgs.io](mailto:support@verygoodsecurity.com).

> You will be able to use your IDP to login and [verify SSO](https://docs.verygoodsecurity.com/enterprise-platform/access-management/enterprise-identity-providers/saml-2.0-configuration) *only* after [VGS Support](mailto:support@verygoodsecurity.com) will process your **IDP metadata**.

5. On the **Service provider details**,
   * enter **ACS URL** and **ENTITY ID** as provided by VGS,
   * check **Signed response**,
   * and set **Name ID format** to `EMAIL`.

> You can find **ACS URL** and **ENTITY ID** values on **Organization Settings** page on [Dashboard](https://dashboard.verygoodsecurity.com).\
> \
> To make Login via the Google App Launcher available, please add to the ACS url `/clients/dashboard` for POST binding.

6. Lastly, on the **Attribute mapping** page, add the following mapping: Google Directory attribute **Primary email** to `email`.

<figure><img src="https://1773866054-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzbOVGj5YTirkppRKlOP9%2Fuploads%2FBEmUqCzsKa3ozt69MXC9%2Fgw7.png?alt=media&#x26;token=5b91dae2-91c5-4c83-9381-60219dc2b013" alt=""><figcaption></figcaption></figure>

## Turn On the App

Navigate to **Apps** > **SAML apps** and select your app from the list. Then, go to **User access** and turn it on for everyone.

<figure><img src="https://1773866054-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FzbOVGj5YTirkppRKlOP9%2Fuploads%2FDiSPCYOwBt1Alo3KHphX%2Fgw8.png?alt=media&#x26;token=a989aa86-2cab-4b69-a9f9-b7af6de08bc7" alt=""><figcaption></figcaption></figure>
