Integrate Google Workspace with Zero Trust Network Access
In this topic, you will find general instructions on how to integrate Google Workspace with Portnox™ Zero Trust Network Access.
You can use this configuration, for example, if you use Entra ID for user management, and you want your users to access Google Workspace applications. Then, your users logging in to Google applications (such as Gmail, Google Docs, and more) will be authenticated using Zero Trust Network Access certificates and Entra ID credentials, not their Google passwords.
Create a Portnox Cloud application configuration
In this step, you will create a configuration in Portnox Cloud that will contain all the information necessary to integrate with Google Workspace as an application.
Open your Google Workspace SSO with third-party IdP settings
In this section, you will access your Google Workspace SSO settings page for third-party identity providers and create a new third-party SSO profile.
Copy configuration values from the Portnox tab to the Google Workspace tab
In this section, you will copy the values displayed by Portnox Cloud and paste them in the relevant fields in the Google Workspace new SAML SSO profile pane.
Copy configuration values from the Google Workspace tab to the Portnox tab
In this section, you will copy the values displayed in your Google Workspace SAML SSO profile section, and paste them in the relevant fields in Portnox Cloud.
Finalize the configuration
In this section, you will finalize the configuration in Portnox Cloud and Google Workspace.
-
Finalize the configuration in the Portnox tab.
-
Finalize the configuration in the Google Workspace tab.
Result: You have configured Google Workspace to be accessible using Portnox Zero Trust Network Access for Applications.
Note the following troubleshooting information:
-
Google Workspace does not enforce third-party IdP for users with Admin privileges, even if they belong to a group or organizational unit configured to use a third-party IdP. These users are always asked for their Google passwords.
-
When creating a new user, we recommend that you assign that user to a temporary organizational unit or group with no IdP requirement, so that the user can activate their account and create a Google password. After the user activates their account, you can assign them to the third-party IdP login unit/group. Otherwise, this may cause problems with the first login.




















