Identity provider (IdP): performs authentication and passes the user’s identity to the service provider. Google Workspace is the IdP here. Service provider (SP): trusts the IdP and authorizes the user. Zenskar is the SP.
Step 1: Domain verification
Step 1: Domain verification
- Click the account menu at the bottom of the sidebar, and select Settings.
- Open the SAML tab.
- In the Connection section, enter a Name for this configuration and the Domain to verify, for example
acme.com. - Click GET TXT RECORDS.
- Add the resulting TXT record to the domain’s DNS.
- Click VERIFY DOMAIN once the record has propagated. The domain’s status changes from Pending to Verified.
- Under Identity Provider, select Google Workspace from the dropdown. This is the default selection.
Step 2: Configure single sign-on in Google Workspace
Step 2: Configure single sign-on in Google Workspace
- Open the Admin Console, and log in as a super admin.
- In the menu, click Show more, and go to Security > Authentication > SSO with third party IdP.
- Click Add SSO profile.
- Set Setup SSO with third party identity provider to enabled.
- Fill in the sign-in and sign-out URLs using the values shown in Zenskar’s Zenskar SAML Configuration Values section:
Zenskar’s Entity ID is the same fixed value for every organization. Copy it exactly as shown on the SAML tab.
- Leave Use a domain specific issuer cleared.
- Under Verification certificate, click Upload certificate, and upload a certificate exported from your Google Workspace SSO profile (see Step 3).
- Click Save, then sign out of the Admin Console.
Step 3: Identity provider configuration in Zenskar
Step 3: Identity provider configuration in Zenskar
- Back in Google Workspace’s SSO profile screen, copy the Entity ID and Sign-in page URL it generated for this SSO profile.
- In Zenskar’s Identity Provider Configuration section, paste these into Identity Provider Entity ID and Single Sign-On Service URL.
- Paste the SSO profile’s certificate into the Certificate field.
Step 4: Attribute mapping
Step 4: Attribute mapping
In Zenskar’s Attribute Mapping section, map each Zenskar field to the Google Workspace attribute that carries it:
Adjust these if your Google Workspace SSO profile sends custom attribute names.
Step 5: Finish and test
Step 5: Finish and test
- In Zenskar, turn on SAML Status, and click Save Configuration.
- Choose a Zenskar user whose email address matches the primary email address of an existing Google Workspace user, and who does not have Google super-admin privileges. Super-admin accounts always sign in with Google credentials directly and are not suitable for testing SSO.
- Sign out, and go to the Zenskar sign-in screen.
- Sign in using that user’s email address. With a verified domain and an enabled configuration, the sign-in should route through Google.
- On success, the sign-in returns to the Zenskar dashboard.
If sign-in does not work as expected, Google super-admin accounts can always sign in directly with Google credentials, bypassing SSO, so you can still reach the Google Admin Console to review or change settings.