Configure Google Workspace for SAML
Prerequisites
- Review SAML (SaaS).
- Configure Sysdig Monitor or Sysdig Secure, or both as a SAML application using Google Workspace’s documentation: Set up your own custom SAML application.
The notes below call out specific steps that require additional action.
Sysdig-Specific Configuration
Configure User access
Set up user access permissions according to your organization’s requirements.
Specify Service Provider Details
Enter the values shown in the table below. If you wish to configure IdP-initiated login flow, replace CUSTOMER-ID-NUMBER
with the number retrieved as described in Find Your Customer Number.
See SaaS Regions and IP Ranges and identify the correct URLs associated with your Sysdig application and region. For example, in US East, the endpoints are:
Setting | Value for Sysdig Monitor | Value for Sysdig Secure |
---|---|---|
ACS URL | <REGION_URL>/api/saml/auth | <REGION_URL>/api/saml/secureAuth |
Entity ID | <REGION_URL> | <REGION_URL> |
Start URL | #/&customer=<CUSTOMER_ID> | #/&customer=<CUSTOMER_ID> |
Replace <REGION_URL>
with the region URL where your Sysidig application is hosted. For example, for Sysdig Monitor in the EU, you use https://eu1.app.sysdig.com
.
Specify SAML Attribute Mapping
Configure the following:
Google Directory attributes | App attributes |
---|---|
Primary email | email |
First name | first name |
Last name | last name |
Note that the attributes are case sensitive, so use caution when entering them.
Only email
is required. However, including first and last names is recommended since these values will now be included in the records created in the Sysdig platform’s database when new users successfully log in via SAML for the first time.
Specify SAML Metadata in Sysdig
Do the following:
- Download the SAML metadata file.
- Open the metadata file using a text editor of choice.
- Copy to the clipboard contents of the metadata file.
- Log in to your Sysdig application.
- In Settings, open Authentication(SSO) > SAML.
- Copy the URL and paste it into the Metadata entry on the SAML Configuration page in the SAML connection settings.
(Optional) Test SAML Login
To ensure the IdP flow works, you can perform a test login from your browser. Ensure the selected user has access to the Sysdig application you have configured.
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.