There are two ways you can connect Google Workspace to ̽»¨´óÉñ; our Google Workspace Integration or our Google Workspace SSO Connector.
Read this article to learn more about the benefits and use cases for each and how they can be used together.
Key Differences
The following are key differences between integrating Google Workspace and implementing Google Workspace SSO:
Google Workspace Integration
- Is an OAuth2-based integration.
- Gives you the option to manage users from ̽»¨´óÉñ. You can provision users, manage their attributes, and suspend them in ̽»¨´óÉñ or Google.
- Allows users to log into Google Workspace directly.
- Requires you to configure Multi-factor Authentication (MFA) in Google.
- Once users login through the ̽»¨´óÉñ User Portal, ̽»¨´óÉñ is established as the password authority; whenever the user password or attributes change in ̽»¨´óÉñ, ̽»¨´óÉñ then updates Google Workspace.
Google Workspace SSO
- Is a SAML 2.0-based integration.
- Requires users to be managed in ̽»¨´óÉñ. Every Google Workspace user must also be a ̽»¨´óÉñ user to log in to Google Workspace.
- Directs users to log in to Google from the ̽»¨´óÉñ User Portal. Even if they attempt to log in to Google directly, they will be redirected to sso.jumpcloud.com.
- Requires you to configure MFA in ̽»¨´óÉñ.
- Users are always forced to authenticate against ̽»¨´óÉñ.
​â¶Ä‹â¶Ä‹â¶Ä‹About Our Google Workspace Integration
̽»¨´óÉñ’s Google Workspace Integration uses OAuth to create a secure, persistent connection between Google Workspace and ̽»¨´óÉñ. ̽»¨´óÉñ becomes the authoritative source of identity, which lets you:
- Import existing Google Workspace users.
- Export new ̽»¨´óÉñ users to Google Workspace.
- Sync user attributes and passwords between ̽»¨´óÉñ and Google Workspace.
- Centralize user provisioning and deprovisioning.
- Give users one set of credentials to access ̽»¨´óÉñ, Google Workspace, and other resources you’ve integrated with ̽»¨´óÉñ, like systems, RADIUS, and LDAP.
We recommend our Google Workspace Integration if you want to centralize user identity and lifecycle management in ̽»¨´óÉñ while still having the flexibility of creating users in either ̽»¨´óÉñ or Google Workspace. You can provision, update, and deprovision users in Google Workspace from ̽»¨´óÉñ. You can also provision users in Google Workspace and import them into ̽»¨´óÉñ. Accounts and user profiles remain in sync. Users only need to remember one password to access all their ̽»¨´óÉñ and Google resources.
About Our Google Workspace SSO Connector
The Google Workspace SSO Connector uses the Security Assertion Markup Language (SAML 2.0) to authenticate ̽»¨´óÉñ users to Google Workspace. Connect the Google Workspace SSO connector to ̽»¨´óÉñ to:
- Manage user access to Google Workspace.
- You can authorize user access to Google Workspace, and you can suspend or delete user access to Google Workspace.
- Learn more about authorizing user access to SAML applications.
- Learn more about suspending a user account or deleting a user account.
- You can’t import or export user accounts with our SAML connectors.
- You can authorize user access to Google Workspace, and you can suspend or delete user access to Google Workspace.
- Map user attributes between ̽»¨´óÉñ and Google Workspace so that you can customize user permissions and roles.
- Give users one set of credentials to access ̽»¨´óÉñ, Google Workspace, and other resources you’ve integrated with ̽»¨´óÉñ, like systems, RADIUS, and LDAP.
We recommend our Google Workspace SSO connector for controlling access to Google Workspace from ̽»¨´óÉñ. This allows you to centralize access management from ̽»¨´óÉñ. Users benefit by having a consistent experience for accessing all ̽»¨´óÉñ managed resources and all Google resources.
Benefits of Using Both
We recommend our Google Workspace Integration if you want to centralize user identity and lifecycle management in ̽»¨´óÉñ while still having the flexibility of creating users in either ̽»¨´óÉñ or Google Workspace. You can provision, update, and deprovision users in Google Workspace from ̽»¨´óÉñ. You can also provision users in Google Workspace and import them into ̽»¨´óÉñ. Accounts and user profiles remain in sync. Users only need to remember one password to access all their ̽»¨´óÉñ and Google resources.