This guide explains how to configure Group-Based SSO Authorization using Google Workspace as the Identity Provider (IdP) for Valimail products.
This integration streamlines user access management by:
Automatically assigning users to the correct Team during login
Reducing manual user administration
Supporting centralized access control through Entra ID groups
Working together with Just-in-Time (JIT) provisioning to automatically create user accounts as needed
Prerequisites
Before configuring Group-Based SSO Authorization, ensure the following requirements are met:
SSO is already configured in Valimail following the appropriate Google Workspace SSO setup documentation (instructions).
The required Groups have been created in Google Workspace (instructions).
Just-in-Time (JIT) provisioning is enabled in Valimail (instructions).
The corresponding Teams have already been created in Valimail Enforce (instructions).
Configure Group-Based Authorization in Google Workspace
Step 1: Open the Google Admin Console
Sign in to the Google Admin Console.
Navigate to: Apps β Web and mobile apps
Select the Valimail application that was previously configured for SSO.
Step 2: Enable Access for a Google Group
Open the User access section.
Expand the Groups section in the left navigation pane.
Search for and select the Google Group you want to authorize for Valimail access.
Set Service status to ON.
Click Save.
This grants members of the selected Google Group access to the Valimail application through Single Sign-on.
Step 3: Configure SAML Group Attribute Mapping
Return to the application overview page.
Open SAML attribute mapping.
In the Group membership (optional) field:
In the App attribute field, enter:
GroupsClick Save.
Map the Google Group to a Valimail Team
Step 1: Sign In to Valimail
Go to:
Sign in using an Owner account.
Step 2: Open Team Settings
Click Account Settings in the top-right corner.
Select Teams from the left navigation menu.
Open the Team you want to map (Click on its name).
Click Edit below the Team name.
In the OID for Active Directory SSO field:
-Enter the Google Group name
-Do not enter the group email addressClick UPDATE to save the configuration.
Validation
Once the Group OID has been added to the appropriate Team in Valimail and the SAML Group Attribute Mapping has been configured in Google Workspace:
Users can authenticate to Valimail using SSO.
User accounts are automatically provisioned through JIT provisioning.
Users are automatically assigned to the correct Team based on the Group OID included in the SAML assertion.
Users who already have a Valimail account and belong to a Google Group linked to a Valimail Team will be automatically added to that Team the next time they log in through SSO.









