Initial Steps

⚠️

Remember to replace the REALM_ID with your actual realm information

Add App

Go to Google Workspace Admin Console (https://admin.google.com)

Apps → Web and mobile apps → Add app → Add custom SAML app

Type application name → Continue → Continue

Enter the following details:

  • ACS URL:https://login.umbrellacost.io/auth/realms/{{REALM_ID}}/broker/google-saml/endpoint
  • Entity ID: https://login.umbrellacost.io/auth/realms/{{REALM_ID}}
  • Name ID format: EMAIL
  • Name ID: Basic information > Primary email

Click Continue.

Add Mapping

Enter:

  • Google Directory attributes: Primary Email → App attributes: email

Click Continue,

Get the metadata file

  • Select the app
  • Set the User Access for everyone, groups or organizational units → Save
  • Apps → Web and mobile apps → your_app →Download metadata →Download metadata

Provide the information to Umbrella

  • The SAML file (the metadata file)
  • List of all email domains