Configuring SSO for Google
The Clumio service can integrate with Google for seamless user authentication. Please follow the steps below to configure Google IDP as a Single Sign On service for Clumio.
Ensure that you have the following before you start configuring Google as an IDP
Google account with admin privileges
Clumio account with Super Admin Role
Steps to enable Google Integration with Clumio
Steps in Google
- Open Google Admin Console > Apps > Web and Mobile Apps.
- Add custom SAML App.
- Enter the App Name and hit continue.
- Download Metadata and hit continue.
- You should see this screen.
- Go to the Clumio side setup and get information from Step 4.
- Copy the Audience URI to Entity ID and the ACS URL to ACS URL.
- Make sure "Signed Response" is checked.
- Click on Continue and leave everything else default.
- Turn the app for appropriate users or organizational units.
- Hit Save and return back to the app.
- Within SAML Attribute Mapping, make sure that the Primary email maps to: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
- Finish setup in Clumio before proceeding.
- Log in to Clumio.
- Navigate to Settings > Access Management > Authentication (SSO/MFA)
- Click on "Configure SSO" under Strategy.
- Copy the Audience Restriction, Assertion Customer Service (ACS) URL, and the Sign-On URL. This will be needed for the IdP side setup.
- Scroll down and upload the metadata retrieved from the IdP. You can either use the URL, upload the metadata XML file, or configure it manually.
- Now click on Save Configuration.
- Click on Test with my Account - This should open a new tab to test the SSO connection.
- Once the above step is successful, click on Activate SSO. Please note that this step is important for SSO enablement.
- Check the box to send emails if you wish to notify all users of the SSO enablement, or else click enable.
- For any user to utilize Clumio login through Google SSO, the user needs to be explicitly added in Clumio UI > Settings > Access Management > Users.
Please contact firstname.lastname@example.org in case of any clarifications or questions.