Connecting Okta with Google Workspace
- Authors
- Name
- Michael Bui
Overview
Okta is acting as our universal directory store. However, we want to use services from Google. This requires users to exist within the Google Workspace environment.
We also want to keep 1 set of credentials and use SSO with Okta.
To configure this we will be connecting Google Workspace with Okta to replicate users into Google Workspace and maintain the same credentials for SSO.
Prerequisites
- An Okta & Google Workspace environment
- An Okta admin account
- A Google Workspace account with user admin permissions to create/update users
Connecting to Google Workspace
- Search for
Google Workspace
in Okta's app catalog and clickadd integration
- Give the application a label
- Enter your domain associated with the Google Workspace
- Choose number of seats (licenses) - Here we put 6 to not go over our trial limit in Google Workspace
- Disable browser plugin auto-submit - This is a password vaulting technique. We'll configure SSO after
- Choose Sign on method - We'll be going with SAML and setting it up in the next step
Provisioning
- Click on the Google Workspace App and select the provisioning tab
- Scroll down to configure API Integration to allow okta to automate Google Workspace user CRUD operations
- Authenticate with your Google admin account that has user admin priviledges
- Save the configuration and go back to provisioning
- Configure settings for
To App
. We'll be using Okta as the master directory and replicating to Google Workspace. - Select Enable for creating, updating, deactivating users
- Under Assignments - Assign the application to a group of users
- Select which organizational unit to send these users to & what licenses to apply
Verifying
- In my Okta directory I have a group of users named
Google Workspace
with 2 users - Since we assigned the
Google Workspace
application to this group, they should be replicated to Google - In our Google audit logs we see that 2 users were created using the Okta service account