You need super administrator access in Google Workspace and Organization Admin permissions in Plerion.
Steps to configure Google SSO
1
Log in to Google Admin console
Sign in to admin.google.com with a super administrator account.
2
Create a custom SAML app
- Go to Menu > Apps > Web and mobile apps.
- Click
Add app>Add custom SAML app. - Enter a name (e.g., “Plerion”) and click
Continue.
3
Download Google IdP metadata
On the Google Identity Provider details page, copy the SSO URL and Entity ID, and download the Certificate. Click
Continue.4
Configure the service provider details
- In Plerion, go to
Admin>Single sign-onand copy the SSO URL. - In Google, paste the URL as both ACS URL and Entity ID.
- Click
Continue.
5
Map attributes
On the Attribute mapping page, add the following mapping:
- Primary email →
email
6
Configure group membership for role mapping
- Under Group membership, click
Search for a groupand add the Google Groups that correspond to your Plerion roles. - In the App attribute field, enter the attribute name Plerion expects for role mapping (e.g.,
role). - Click
Finish.
7
Enable the app for your users
- On the app details page, click
User access. - Set the service status to ON for everyone and click
Save.
8
Configure trust in Plerion
- In Plerion, go to
Admin>Single sign-on>Edit>Trust.- Paste SSO URL into Single Sign-On URL
- Paste Entity ID into Identity Provider Entity ID
- Paste the contents of the Certificate file into x.509 Certificate
- Click
Configureto save.
9
Map attributes and roles
- In
Attribute mapping:- For Email, select Use SAML Name ID.
- For Roles, set the SAML attribute to the group membership attribute from Google (e.g.,
role).
- Map each Google Group to the corresponding Plerion role.
10
Test your Google SSO connection
- Open a new browser session and sign in with a Google account that has access to the Plerion SAML app.
- Verify that you can log in to Plerion using Google SSO.