Skip to main content

Setting Up Group-Based SSO Authorization with Google Workspace IdP

This guide explains how to configure Group-Based SSO Authorization using Google Workspace as the Identity Provider (IdP) for Valimail products.

This integration streamlines user access management by:

  • Automatically assigning users to the correct Team during login

  • Reducing manual user administration

  • Supporting centralized access control through Entra ID groups

  • Working together with Just-in-Time (JIT) provisioning to automatically create user accounts as needed

Prerequisites

Before configuring Group-Based SSO Authorization, ensure the following requirements are met:

  1. SSO is already configured in Valimail following the appropriate Google Workspace SSO setup documentation (instructions).

  2. The required Groups have been created in Google Workspace (instructions).

  3. Just-in-Time (JIT) provisioning is enabled in Valimail (instructions).

  4. The corresponding Teams have already been created in Valimail Enforce (instructions).

Configure Group-Based Authorization in Google Workspace

Step 1: Open the Google Admin Console

  1. Sign in to the Google Admin Console.

  2. Navigate to: Apps β†’ Web and mobile apps

  3. Select the Valimail application that was previously configured for SSO.

Step 2: Enable Access for a Google Group

  1. Open the User access section.

  2. Expand the Groups section in the left navigation pane.

  3. Search for and select the Google Group you want to authorize for Valimail access.

  4. Set Service status to ON.

  5. Click Save.

This grants members of the selected Google Group access to the Valimail application through Single Sign-on.

Step 3: Configure SAML Group Attribute Mapping

  1. Return to the application overview page.

  2. Open SAML attribute mapping.

  3. In the Group membership (optional) field:

    • Search for and select the Google Group.

  4. In the App attribute field, enter: Groups

  5. Click Save.

Map the Google Group to a Valimail Team

Step 1: Sign In to Valimail

  1. Go to:

  2. Sign in using an Owner account.

Step 2: Open Team Settings

  1. Click Account Settings in the top-right corner.

  2. Select Teams from the left navigation menu.

  3. Open the Team you want to map (Click on its name).

  4. Click Edit below the Team name.

  5. In the OID for Active Directory SSO field:
    -Enter the Google Group name
    -Do not enter the group email address

  6. Click UPDATE to save the configuration.

Validation

Once the Group OID has been added to the appropriate Team in Valimail and the SAML Group Attribute Mapping has been configured in Google Workspace:

  • Users can authenticate to Valimail using SSO.

  • User accounts are automatically provisioned through JIT provisioning.

  • Users are automatically assigned to the correct Team based on the Group OID included in the SAML assertion.

  • Users who already have a Valimail account and belong to a Google Group linked to a Valimail Team will be automatically added to that Team the next time they log in through SSO.

Did this answer your question?