Adding Google Workspace as external identity provider in Azure

HK G 516 Reputation points
2022-04-01T21:27:09.08+00:00

I am trying to setup a SAML federation partnership between Azure and Google Workspace with Workspace being the Idp.

I am looking for some good step by step guide and could not find any that I can follow. I think the high level steps are to create a Google Workspce SAML Identity providers in Azure and then create a M365\custom web\mobile app in the Workspace admin console. There are some parameters such as attribute mapping and etc which I am not sure how to configure.

Any help will be appreciated.

Thanks

Microsoft Security Microsoft Entra Microsoft Entra External ID
Microsoft Security Microsoft Entra Microsoft Entra ID
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. HK G 516 Reputation points
    2022-04-01T21:40:29.817+00:00

    I also wanted to add that this will be like B2B collaboration. User sign-in with their Workspace account to the Azure tenant and access the resource from there. The account should be added to Azure Active Directory once an invitation is sent. And there is not need to do any account synchronization or pre-creation.

    Thanks.

    0 comments No comments

  2. Takahito Iwasa 4,851 Reputation points MVP Volunteer Moderator
    2022-04-02T00:09:07.237+00:00

    Hi, @HK G

    The following may be helpful.
    The email address is specified in the SAML attribute mapping.

    https://www.misuzilla.org/Blog/2019/07/26/FederatingGSuiteWithAzureActiveDirectory

    0 comments No comments

  3. HK G 516 Reputation points
    2022-04-04T16:20:50.65+00:00

    Hi Takahitolwasa,

    Thanks for the reply. I did look at the links that you provided but it doesn't seem to provide what I need. I am actually looking at adding Google Gsuite as an Identity provider in Azure. With this, I should be able to invite guest (Microsoft accounts, Azure account from other tenants) to my tenant without needing to configure the ImmutableID and\or changing the authentication mode for the specific domain in Azure. The documentation I can find so far is for Google gmail but not for Gsuite.

    Thanks again.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.