Sign in with Google Workspace through Microsoft Entra
On this page
Use a Google Workspace custom SAML app to authenticate managed Workspace users through Entra. Microsoft’s built-in Google federation is intended for Gmail users; Workspace domains use SAML federation.
Review the shared prerequisites and SAML values.
Configure Google Workspace
- As a super administrator, open Apps > Web and mobile apps > Add app > Add custom SAML app.
- Name the app and download the Google IdP metadata or collect its SSO URL, Entity ID, and certificate.
- In Service Provider Details, set ACS URL to the shared ACS and Entity ID to the shared audience.
- Select PERSISTENT for the Name ID format and map its value to an administrator-controlled stable user attribute. The default primary email can change; plan identity continuity if using it.
- Add an attribute mapping from the user’s primary email to the shared email claim.
- Finish and turn on User access for the pilot user’s organizational unit or access group.
Confirm the assertion’s NameID stays consistent and that its email matches the invited guest.
Connect Entra and CluedIn
Complete Entra federation, guest onboarding, and CluedIn role assignment. Use the resource tenant associated with your CluedIn SSO connection.
Start the pilot sign-in from CluedIn, verify the correct user and role, then test role changes and logout. Provider roles or groups require an explicit authorization design; forwarding them in SAML does not automatically assign CluedIn roles.
Validate this pattern in your deployment before rollout. The provider application authenticates to Entra; its ACS points to Entra rather than CluedIn.
Troubleshooting
If Google denies access, check the app’s User access setting and allow time for changes to propagate. Test from CluedIn even if Google’s Test SAML login succeeds: the complete Entra guest flow still needs verification.
Google group attributes do not create Entra group membership automatically.