> ## Documentation Index
> Fetch the complete documentation index at: https://docs.blinkops.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring a SAML application on Google Workspace

> Instructions on how to configure a SAML SSO application with Google Workspace.

<Steps>
  <Step title="Add a Custom SAML App in Google Admin">
    Log in to Google Admin account, press "Apps" on left sidebar, and under it "Web and mobile apps", then press in main window "Add app" and choose "Add custom SAML app":

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-1.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=1303671bc00e83dea39cd88a916c44d1" width="2042" height="728" data-path="img/IdentityProviders/gw-1.png" />
    </Frame>
  </Step>

  <Step title="Name Your Custom SAML App">
    In "Add custom SAML app", give App name, and press continue:

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-2.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=6485129f1d03b70c0deaeb9c9997caf2" width="2040" height="1044" data-path="img/IdentityProviders/gw-2.png" />
    </Frame>
  </Step>

  <Step title="Download IdP Metadata">
    In the IdP page, click on the 'download metadata' button.

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-3.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=c7481e4e497c4c5f19d538b32dc4435d" width="3286" height="2070" data-path="img/IdentityProviders/gw-3.png" />
    </Frame>
  </Step>

  <Step title="Upload Metadata File in Blink Platform">
    Once the file is downloaded, navigate to the Metadata File section found within the SAML tab in the Account Management Settings. Paste the **downloaded metadata** values into the designated text field labeled Metadata File.

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/VXKzhvwYkcutAgt0/img/IdentityProviders/saml-metadata.png?fit=max&auto=format&n=VXKzhvwYkcutAgt0&q=85&s=ebe23d3464469cd3d4a950770adc771d" width="1725" height="1075" data-path="img/IdentityProviders/saml-metadata.png" />
    </Frame>

    <Note>
      **NOTE**

      Please note that the Identifier (Entity ID) value, along with the Single Sign-On URL, can be located within the SAML tab under the Account Management Settings section within the Blink Platform. The **ACS URL** is not available under the SAML tab, therefore you can find it below:

      **The Entity ID** : `urn:amazon:cognito:sp:eu-west-1_NEemCMO1L`\
      **The ACS URL** : `https://cognito.blinkops.com/saml2/idpresponse`\
      **Single Sign-On URL** : Please look in the Account Management Settings section within the Blink Platform to find your unique **Single Sign-On URL**.

      <Frame>
        <img src="https://mintcdn.com/blinkops-2/VXKzhvwYkcutAgt0/img/IdentityProviders/saml.png?fit=max&auto=format&n=VXKzhvwYkcutAgt0&q=85&s=278df00dec265b8a2c9c63742b79d17d" width="1372" height="458" data-path="img/IdentityProviders/saml.png" />
      </Frame>
    </Note>
  </Step>

  <Step title="Enter SAML Configuration Details">
    Using the **ACS URL**, as well as the **Identifier (Entity ID)** value and the **Single Sign-On URL** available in the SAML tab under the Account Management Settings section within the Blink Platform, proceed to copy and insert these values into the designated text fields below.

    <Note>**Note**: Paste the **Single Sign-On URL value** in the **START URL** text field.</Note>

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-4.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=1616555d356bed0fda197c6b206a53e6" width="2649" height="1837" data-path="img/IdentityProviders/gw-4.png" />
    </Frame>
  </Step>

  <Step title="Continue to Next Step">
    Press continue
  </Step>

  <Step title="Configure Attribute Mapping">
    In the **Attribute mapping** page, map **"First name"** to **"given\_name"**, **Last name** to **family\_name**, and **"Primary email"** to **"email"**.

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-5.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=1cb2973ccd3b762f1a3d73cfafd0b394" width="2652" height="1332" data-path="img/IdentityProviders/gw-5.png" />
    </Frame>
  </Step>

  <Step title="Set Up Group Mapping and Role Mapping in Blink">
    Next, scroll to the **Group Membership** section, select your **Google Groups**, and set the App attribute value as **group** and click 'FINISH'. Then head to the SAML tab under the Account Management Settings section within the Blink Platform and click the **Role Mapping** section and select the applicable values.

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-8.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=5725beefcf4ea4a0eeab659c6b638ed7" width="2049" height="548" data-path="img/IdentityProviders/gw-8.png" />
    </Frame>

    When a user belongs to multiple Google groups, Blink resolves role assignment in SAML SSO using a **top-down priority order** based on the `Group:Role` mapping table. The first matching group in the list determines the assigned role.

    <Warning>**IMPORTANT** Please note that in the **Mapping** section, at least one mapping role must be designated as an **admin** with administrative privileges. Additionally, the user configuring the group must be a part of the group mapped to the **Admin** role. Otherwise you won't be able to operate as an administrator in your account or access and edit the role mapping again.</Warning>

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/okta-12.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=b5669312112cb3942744339938dfa0d9" width="1247" height="805" data-path="img/IdentityProviders/okta-12.png" />
    </Frame>
  </Step>

  <Step title="Enable User Access for Organizational Units">
    After you finish SAML app creation, you can set up User access by changing the status to **ON** for all organizational units:

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-6.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=e097624b8f15fc45bcb7e681e596b59e" width="2042" height="764" data-path="img/IdentityProviders/gw-6.png" />
    </Frame>

    <Frame>
      <img src="https://mintcdn.com/blinkops-2/ZeD68GD0apWa12JT/img/IdentityProviders/gw-7.png?fit=max&auto=format&n=ZeD68GD0apWa12JT&q=85&s=3e4bd6b2adc3f3d6c78f7361332bae4c" width="2036" height="806" data-path="img/IdentityProviders/gw-7.png" />
    </Frame>
  </Step>
</Steps>
