Google Workspace - SAML Relying Party Configuration - RSA Ready Implementation Guide
Originally Published: 2021-10-30
This article describes how to integrate RSA with Google Workspace (formerly G Suite) using SAML Relying Party.
Configure RSA Cloud Authentication Service
Perform these steps to configure RSA Cloud Authentication Service as Relying Party to Google Workspace.
Procedure
- Sign in to RSA Cloud Administration Console.
- Click Authentication Clients > Relying Parties.
- On the My Relying Parties page, click Add a Relying Party.
- On the Relying Party Catalog page, click Add for Service Provider SAML.
- On the Basic Information page, enter a name for the Service Provider in the Name field.
- Click Next Step.
- On the Authentication page, choose SecurID Access manages all authentication.
- In the Primary Authentication Method list, select your desired login method as either Password or SecurID.
- In the Access Policy for Additional Authentication list, select a policy that was previously configured.
- Select Next Step.
- On the Connection Profile page, click Enter Manually.
- In the Service Provider section, provide the following details:
- In the Assertion Consumer Service (ACS) URL field, enter https://www.google.com/a/%DOMAIN%/acs where %DOMAIN% is the domain name of your Google Workspace connected domain.
- In the Service Provider Entity ID field, enter google.com.
- In the Message Protection section, click Download Certificate to download the IDP signing certificate used by Cloud Authentication Service to sign the assertion. This is required during the Workspace configuration.
- In the Identity Provider section, make a note of the Entity ID text field value. This is required during the Workspace configuration.
- Click Save and Finish.
- Click Publish Changes and wait for the operation to complete.
Configure Google Workspace
Perform these steps to configure Google Workspace.Procedure
- Sign in to the Workspace administrator console at https://admin.google.com.
- Go to Security > Authentication > SSO with third-party IdP.
- On the SSO with third-party IdP page, do the following:
- Select the Set up SSO with third-party identity provider check box.
- In the Sign-in page URL field, enter the Identity Provider URL obtained from of RSA Cloud Authentication Service configuration.
- In the Sign-out page URL field, enter https://google.com.
- Verification certificate: Upload the public certificate extracted from RSA Cloud Authentication Service configuration.
- Select the Set up SSO with third-party identity provider check box.
- Click Save.
The configuration is complete.
Return to Google Workspace - RSA Ready Implementation Guide.
Related Articles
Google Workspace - SAML IDR SSO Configuration - RSA Ready Implementation Guide 30Number of Views Google Workspace - RSA Ready Implementation Guide 58Number of Views Google Workspace - SAML My Page SSO Configuration - RSA Ready Implementation Guide 27Number of Views AWS Workspaces - RSA Ready Implementation Guide 37Number of Views AWS Workspaces - SAML My Page SSO Configuration - RSA Ready Implementation Guide 27Number of Views
Trending Articles
Passwordless Authentication in Windows MFA Agent for Active Directory – Quick Setup Guide RSA Authentication Manager 8.9 Release Notes (January 2026) RSA Authentication Manager Upgrade Process RSA Authentication Manager 8.7 SP2 Setup and Configuration Guide An example of SSO using SAML and ADFS with RSA Identity Management and Governance 6.9.x
Don't see what you're looking for?