Built by IT. Designed for Operations.
30 Day Free Trial
No Credit Card Required
Real Human Support

Google Workspace supports SAML 2.0 and OIDC for single sign-on, and the entire job comes down to four moves: create an SSO profile in the Admin console, configure your identity provider with that profile’s Entity ID, ACS URL, and certificate, assign the profile to an organizational unit or group, then verify it with an IdP-initiated and SP-initiated test. If you’re still running a legacy SAML profile, Google recommends migrating to the newer SSO profile model for better group targeting and OIDC support.


TL;DR:

  • SAML is preferred for legacy, enterprise environments, or apps that require XML assertions, while OIDC is better suited for modern web and mobile apps using JSON tokens.

  • Proper setup of SAML profiles involves verifying Entity IDs, ACS URLs, certificates, and attribute mappings to prevent common sign-in errors.

  • Assign SSO profiles at the organizational or group level, starting with pilot groups to avoid widespread issues and ensure smooth deployment.

  • Regularly rotating certificates, testing login flows, and monitoring sign-in logs help maintain SSO reliability and security over time.

  • Pair SSO with context-aware access, strong MFA, and automated provisioning to enhance security and reduce risks associated with centralized authentication.


CentriOps
Keep Access Workflows In View
CentriOps brings users, devices, software access, onboarding, offboarding, and support needs together for distributed teams.
See how CentriOps works

Table of Contents

When Should You Use SAML Instead of OIDC?

Both protocols exist in Google Workspace for a reason, and picking wrong just means more troubleshooting later.

SAML 2.0 has been the enterprise default for years because it works with a huge range of existing SaaS applications that were built around XML assertions and browser redirects. If your organization runs older line-of-business apps or an identity provider that only speaks SAML, that decision is already made for you.

OIDC, built on OAuth 2.0, tends to fit better with modern web apps, mobile clients, and API-driven services that expect JSON tokens instead of XML. It’s also generally easier to debug, since ID tokens are simpler to inspect than signed SAML assertions.

How Do You Set Up a SAML SSO Profile in Google Admin?

Configuring SAML correctly the first time saves you a week of chasing sign-in errors later.

  1. In the Admin console, go to Security > Authentication > SSO with third-party IdP.

  2. Click Add SAML SSO profile and give it a clear name (something tied to the IdP, not just β€œSSO1”).

  3. Enter your IdP’s Entity ID, Sign-in page URL, Sign-out page URL, and (optionally) a Change password URL.

  4. Copy the ACS URL and Google’s own Entity ID from the Admin console, then paste them into your IdP’s configuration.

  5. Upload your IdP’s public certificate. Google requires signed SAML assertions using the SAML 2.0 HTTP POST binding, so an unsigned or misconfigured cert is one of the most common launch blockers.

  6. Confirm the NameID format matches what your IdP sends (email address is the usual choice) and set up any attribute mapping you need.

Keep group assignments modest at first. A profile assigned to a single pilot group is far easier to unwind than one pushed to your entire domain.

Pro Tip: Stand up a dedicated test OU with two or three throwaway accounts before you touch production users. It turns a risky rollout into a boring one.

How Do You Configure an OIDC Profile for Workspace?

OIDC profiles live in the same Admin console location as SAML, under Security > Authentication > SSO with third-party IdP, but the fields look different.

OIDC tends to be a better fit if your organization is building or buying modern SaaS tools rather than maintaining legacy SAML-only systems.

How Should You Assign SSO Profiles to Users?

Google Workspace assigns SSO profiles at the OU or group level. There’s no per-user toggle, which is intentional. It forces you to think in terms of scope rather than one-off exceptions.

It’s the only way to catch a bad ACS URL before it locks out your whole company.

What Should You Check When Testing SSO?

Testing is where most SSO problems get caught, or missed.

  1. Use the Admin console’s Test SAML login feature to run an IdP-initiated test before assigning the profile broadly.

  2. Separately test an SP-initiated flow by starting from a Google sign-in page (like gmail.com) to confirm the redirect to your IdP works both directions.

  3. Inspect the SAML assertion or OIDC ID token for a correct NameID, expected attributes, a valid signature, and timestamps that haven’t expired.

  4. If login fails, check for clock skew between your IdP and Google, a certificate that doesn’t match what’s uploaded, or an ACS URL/Entity ID mismatch. Google Cloud’s architecture guidance covers this assertion flow in detail if you need to trace exactly where the handshake breaks.

  5. Confirm the test user actually exists in Workspace with matching attributes. A perfectly valid assertion still fails if there’s no provisioned account to match it to.

What Maintenance Keeps SSO Reliable Long Term?

SSO isn’t a set-it-and-forget-it configuration. A few recurring tasks keep it from breaking quietly.

Pro Tip: Put a recurring calendar reminder 30 days before every certificate expiration. Nobody remembers this until the day logins start failing.

What Security Controls Should Pair With SSO?

SSO centralizes authentication, but that only reduces risk if you back it with the right controls around it.

Migrating off legacy SAML profiles matters here too. Legacy profiles don’t support the same group-based assignment or newer provisioning options, which means a smaller, harder-to-audit attack surface than modern SSO profiles.

Why Do SSO Errors Happen, and How Do You Fix Them?

Most SSO failures trace back to a short list of causes.

How Does Operations Tooling Fit Into the SSO Lifecycle?

SSO handles authentication, while your team still needs to organize the work around employee arrivals and departures. CentriOps brings user records, devices, tasks, and checklists into one workspace to help teams track onboarding and offboarding work. Teams can outline steps such as assigning equipment and removing accounts, then carry out and verify those changes in Google Workspace or their identity provider.

β€” CentriOps Team

Manage the Access Lifecycle Around Your SSO Setup

Getting SSO configured is one part of supporting your team. You also need to organize device records, track tasks, and follow a clear process when employees join or leave. CentriOps helps small and mid sized businesses bring this operational work into one workspace, with users, devices, subscriptions, tasks, and checklists.CentriOps

Use CentriOps checklists to document onboarding and offboarding steps, and tasks to track the work your team needs to complete. Keep user and device records organized alongside that work, while making and verifying account changes directly in Google Workspace and other services. Explore the CentriOps features or start a 30 day free trial to see how it fits your team’s daily operations.

Sources

Get Ready for CentriOps Launch

Be the first to know when we go live and get early access to a simpler way to manage users, assets, tickets, and more.

By joining, you agree to our Privacy Policy. No spam. Unsubscribe anytime.

πŸš€ CentriOps Launching March 16, 2026

βœ… Design Complete
βœ… Core Features are Complete
βœ… Support/Settings Complete
βœ… Dark Mode Complete
βœ… Mobile Complete
βœ… Early Access
βœ… Finishing Touches Complete
πŸ“… Launching March 16, 2026
Updated: Mar 7, 2026
100%

πŸš€ CentriOps Launching March 16, 2026

βœ… Design Complete
βœ… Core Features are Complete
βœ… Support/Settings Complete
βœ… Dark Mode Complete
βœ… Mobile Complete
βœ… Early Access
βœ… Finishing Touches Complete
πŸ“… Launching March 16, 2026
Updated: Mar 7, 2026
100%

Download Your Free Guide from CentriOps

A quick guide for non-IT staff suddenly managing tech at work.

By submitting, you agree to our Privacy Policy. No spam. Unsubscribe anytime.

πŸš€ Launch Progress

βœ… Design Complete
βœ… Core Features are Complete
βœ… Support/Settings Complete
βœ… Dark Mode Complete
βœ… Mobile Complete
βœ… Early Access
βœ…Finishing Touches Complete
πŸ“… Launching Early March 2026
Updated: Feb 23, 2026 (updates posted weekly)
100%

πŸš€ Launch Progress

βœ… Design Complete
βœ… Core Features are Complete
βœ… Support/Settings Complete
βœ… Dark Mode Complete
βœ… Mobile Complete
βœ… Early Access
βœ…Finishing Touches Complete
πŸ“… Launching Early March 2026
Updated: Feb 23, 2026 (updates posted weekly)
100%

Coming Soon

Free trials will be available after launch.

Get Ready for CentriOps Launch

Join the list and get 50% off your first 3 months when we go live.