SAML with Google Workspace
This guide walks you through configuring SAML 2.0 SSO between Google Workspace and NetActuate.
Prerequisites
- Super Admin access to your Google Workspace Admin Console
- Admin access to the NetActuate portal
- A verified domain in your NetActuate account
Step 1: Add a Custom SAML Application in Google Workspace
- Log in to the Google Workspace Admin Console.
- Navigate to Apps → Web and mobile apps.
- Click Add app → Add custom SAML app.
- Enter an application name (e.g., "NetActuate") and click Continue.
Step 2: Download Google IdP Metadata
- On the Google IdP details page, you will see the SSO URL, Entity ID, and certificate.
- Click Download Metadata to save the IdP metadata XML file.
- Click Continue.
Note: Keep this metadata file available. You will upload it to the NetActuate portal in a later step.
Step 3: Configure Service Provider Details
Enter the following values:
| Field | Value |
|---|---|
| ACS URL | https://portal.netactuate.com/saml/acs |
| Entity ID | https://portal.netactuate.com/saml/metadata |
| Name ID Format | EMAIL |
| Name ID | Basic Information > Primary email |
Click Continue.
Step 4: Configure Attribute Mapping
Add the following attribute mappings:
| Google Directory Attribute | App Attribute |
|---|---|
| Primary email | email |
| First name | firstName |
| Last name | lastName |
Click Finish.
Step 5: Enable the Application
- On the application details page, click User access.
- Select ON for everyone (or configure for specific organizational units).
- Click Save.
Note: It can take up to 24 hours for changes to propagate across all Google Workspace users, though it typically takes effect within minutes.
Step 6: Configure NetActuate
- Log in to the NetActuate portal.
- Navigate to Account → Settings → SAML.
- Upload the metadata XML file you downloaded from Google Workspace.
- Click Save.
Step 7: Test the Integration
- Open a new incognito/private browser window.
- Navigate to the NetActuate portal login page.
- Select SSO Login and enter your Google Workspace email address.
- Verify that you are redirected to Google for authentication and returned to the NetActuate portal.
Troubleshooting
- "App is not configured" error: Ensure the application is enabled for the user's organizational unit in Google Workspace.
- Attribute mapping issues: Verify the attribute names match exactly (
email,firstName,lastName). - Users not seeing the app: Check that the application is turned on for the correct organizational unit and allow time for propagation.
Need Help?
If you run into issues, contact NetActuate Support.