> ## Documentation Index
> Fetch the complete documentation index at: https://macstadiuminc-fix-cloud-provider-accuracy-di570.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Enable SAML SSO with Google Workspace Federation

> Configure SAML SSO for MacStadium Portal via Google Workspace. Create a custom SAML app in Google Admin, download metadata, and send it to MacStadium.

<Note>SAML SSO is a paid offering. Contact your account team through the [Customer Portal](https://portal.macstadium.com) for more information.</Note>

<Warning>MacStadium does not support IdP-initiated logins. After SSO is configured, all users must log in at [portal.macstadium.com/sso](https://portal.macstadium.com/sso) using the ID provided by the MacStadium team.</Warning>

1. Go to [Google Admin Console](https://admin.google.com/)

2. Navigate to “Web and mobile apps” (Apps → Web and mobile apps in the left menu or use [this link](https://admin.google.com/ac/apps/unified))\\
   <img src="https://mintcdn.com/macstadiuminc-fix-cloud-provider-accuracy-di570/tQr824J5XYFUhvV9/images/attachments/28262749454747.png?fit=max&auto=format&n=tQr824J5XYFUhvV9&q=85&s=8dc7c0c78d04284c32141dac4f027fe3" alt="Google Admin Console left menu with Web and mobile apps option highlighted" width="2354" height="1466" data-path="images/attachments/28262749454747.png" />

3. Create a new “Custom SAML App” (click Add app)\\
   <img src="https://mintcdn.com/macstadiuminc-fix-cloud-provider-accuracy-di570/tQr824J5XYFUhvV9/images/attachments/28262749456027.png?fit=max&auto=format&n=tQr824J5XYFUhvV9&q=85&s=c5bcbbc04c4af90e6d9888be83e52345" alt="Google Admin Web and mobile apps page with Add app dropdown showing Custom SAML app" width="974" height="566" data-path="images/attachments/28262749456027.png" />

4. Enter “App name” (e.g. MacStadium Portal)

5. Download the metadata by clicking Download Metadata - Keep this file for sharing with our support team later.\\
   <img src="https://mintcdn.com/macstadiuminc-fix-cloud-provider-accuracy-di570/tQr824J5XYFUhvV9/images/attachments/28262763978523.png?fit=max&auto=format&n=tQr824J5XYFUhvV9&q=85&s=7eb75e945066f73a7fd3f62db7d766ff" alt="Google SAML app setup with Download Metadata button" width="2560" height="1740" data-path="images/attachments/28262763978523.png" />

6. Configure
   * **ACS URL:** `https://idp.macstadium.com/saml2/idpresponse`
   * **Entity ID:** `urn:amazon:cognito:sp:us-east-1_pusi8jHs1`
   * Configure email mapping with the "Show Advanced Settings" menu
   * Select EMAIL for the Name ID Format field
   * Select Primary Email for the Name ID field\\
     <img src="https://mintcdn.com/macstadiuminc-fix-cloud-provider-accuracy-di570/tQr824J5XYFUhvV9/images/attachments/28262763979675.png?fit=max&auto=format&n=tQr824J5XYFUhvV9&q=85&s=f896465df534d418c9f283a83c6c7168" alt="Google SAML app Service Provider Details with ACS URL, Entity ID, and Name ID fields" width="2560" height="1740" data-path="images/attachments/28262763979675.png" />

7. Map Primary email to email\\
   <img src="https://mintcdn.com/macstadiuminc-fix-cloud-provider-accuracy-di570/tQr824J5XYFUhvV9/images/attachments/28262749462171.png?fit=max&auto=format&n=tQr824J5XYFUhvV9&q=85&s=9b8353a79520e8e5d1377dd1e14ad438" alt="Google SAML app Attribute mapping with Primary Email mapped to email" width="2416" height="1642" data-path="images/attachments/28262749462171.png" />

8. Click Finish to complete the setup

9. Provide our support team with the metadata file from step 5
