Google Workspace Integration

This guide walks you through how to configure SAML-based Single Sign-On (SSO) between Google Workspace and Fixiam using the pre-integrated Google Workspace app available in IAM.



✅ Prerequisites

  1. You have admin access to both Google Workspace and Fixiam.
  2. The domain used in Google Workspace must be verified.

Step 1: Start from Fixiam

  1. Log into Fixiam
  2. Go to Applications > Apps
  3. Click Add New Application
  4. From the app list, find Google Workspace (pre-integrated)
  5. Click on it to open the application page

Step 2: Export Metadata from Fixiam

Once the Google Workspace application is open:

  1. Go to the Configuration page
  2. Click Export Metadata
  3. This will open the XML metadata in a new browser tab
    1. From the metadata:
      1. Locate entityID="..." → Copy this as the IDP Entity ID
      2. Locate <md:SingleSignOnService Location="..." → Copy the Sign-In Page URL
      3. Locate the value inside <ds:X509Certificate> → This is your certificate

Step 3: Configure SAML in Google Workspace

  1. Go to Google Workspace Dashboard
  2. Click your profile photo → Select Admin Console

  1. In the Admin Console, locate the search bar at the top, type SSO
  2. Select SSO with third-party IDP

Step 4: Add a New SAML Profile

On the SSO with third-party IDP page, click on Add SAML Profile.

  1. Fill out the form with the following details:
    1. SSO Profile Name: Fixiam IDP Entity ID: obtain this from the Fixiam metadata exported as completed in step 2 Sign-in Page URLobtain this from the Fixiam metadata exported as completed in step 2 Sign-out Page URL: Leave this blank Change Password URL: Leave this blank Upload the Certificate File:
      • Use the copied X.509 Certificate value from Fixiam
      • Create a text file (e.g., cert.pem) and paste the certificate inside
      • Upload this file here
  2. Click Save

Step 5: Retrieve Google Entity ID and ACS URL

  1. After saving, you’ll be redirected to a new page
  2. From that page, copy the following:
    1. Entity ID
    2. ACS URL (Assertion Consumer Service URL)

📌 You will use these to complete the configuration in Fixiam


Step 6: Complete Configuration in Fixiam

  1. Go back to the Google Workspace app configuration page in Fixiam
  2. Enter the following:
FieldWhat to Enter
SP Entity IDPaste the Entity ID from Google
ACS URLPaste the ACS URL from Google
Audience URL(Optional) Leave blank or reuse SP
Sign Assertion✅ Enable this checkbox
  1. Click Next or Save to complete configuration

Step 6: Create Group in Google Workspace

  1. Go to Directory > Groups > Create Group
  2. Enter:
    1. Group Name:Fixiam SSO Users
    2. Group Email:Use admin or service email
  3. Click Save

Step 7: Add Users to Group

  1. Open the newly created group
  2. Add users who should log in via Fixiam as members

Step 8: Assign SSO Profile to the Group

  1. Go back to SSO with third-party IDP in Google Admin Console
  2. Click Manage under SSO Profile Assignments
  3. Set the following:
    1. Group :Fixiam SSO Users
    2. SSO Profile: Fixiam
    3. Login Option: Allow users to enter Google username and be redirected to Fixiam
  4. Click Save

Step 9: Test the SSO Login

  1. Go to a Google Workspace service (e.g., Gmail, Docs)
  2. Try logging in with a user that belongs to the assigned group
  3. If successful:
    1. User is redirected to Fixiam
    2. After login, they are redirected back to Google Workspace

🎉 All Done!

You’ve successfully integrated Google Workspace with Fixiam using SAML SSO. Users can now enjoy secure, IAM-managed access across Google tools.