Google Single Sign-On integration with SAML
Google offers a Single Sign-On service as part of its Cloud Identity product. The service provides single-click access to applications. For additional information, refer to the Google support documentation.
This document explains how to configure Google and Invicti Platform for Single Sign-On.
Configure Google Single Sign-On integration with SAML
- In Google Administrator console, select Apps > Web and mobile apps.
- From the Web and mobile apps page, select Add app > Add custom SAML app.
- On the Add custom SAML app page, enter a name for your app. (For this document, Invicti is used.)
- Click Continue.
- The IdP Information: SSO URL, Entity ID, and Certificate are needed in a later step.
- Click Continue.
- Open a new browser tab and from the Invicti's menu, select Settings > Security & access control > SSO & Provisioning.
- Turn on the Enable SSO toggle.
- Select Google from the SSO Provider drop-down list.

- Copy the SAML 2.0 Service URL from Invicti and paste it into the ACS URL field in the Service provider details section.
- Copy the Identifier from Invicti and paste it into the Entity ID field in the Service provider details section.

-
Click Continue in the administrator console to open Attribute mapping.
-
Click Add Mapping and configure the Attribute Mapping as follows:
- Assign to the First name field the value user.firstName.

- Click Finish in your Google Admin console.
- In your Google Invicti settings page, change the User access to ON for everyone.

- Click DOWNLOAD METADATA to access the IdP information.

- Copy the Entity ID field and switch to Invicti browser tab to paste the URL into the IdP Identifier field.
- Switch to Google browser tab to copy the URL from the SSO URL field and paste it into the SAML 2.0 Endpoint field in Invicti.
- Switch to Google browser tab to copy the content from the X.509 Certificate field and paste it into the X.509 Certificate field in Invicti.

- Select the checkboxes for signed assertions, encrypted assertions, or sign requests as needed.
- If you enable any assertions or requests, a new section appears where you can Generate a new certificate or upload an existing one.
- Use the SSO Exemptions drop-down to select users who can log in to Invicti via password.

- Click Save to complete the integration.
- Open Google Invicti's setting page and click TEST SAML LOGIN to test the connection.

info
To learn more about the Single Sign-On fields, refer to the Single Sign-On configuration document.
Need help?
Invicti Support team is ready to provide you with technical help. Go to Help Center
Was this page useful?