fiza Posted March 14, 2017 Posted March 14, 2017 I have checked and there are a few old threads on SSO for G Suite but nothing I could find that is up to date. Is it possible to configure things so when users sign in to their computers with AD credentials then these auto sign them into G Suite? I know nothing about AD FS so would appreciate some pointers if it is at all possible to do.
jmak Posted March 14, 2017 Posted March 14, 2017 (edited) I have checked and there are a few old threads on SSO for G Suite but nothing I could find that is up to date. Is it possible to configure things so when users sign in to their computers with AD credentials then these auto sign them into G Suite? I know nothing about AD FS so would appreciate some pointers if it is at all possible to do. Edit: I was wrong and am therefore happy 😀 Please see @FN-GM's answer below. I can't see a way of doing true SSO without using a 3rd party identity provider. You can use Google cloud directory sync (part of G Suite) to provision accounts and match you AD structure with OUs syncing and then your users will be able to sign in to Google Suite with their AD credentials. See here: https://support.google.com/a/answer/106368?hl=enhttps://support.google.com/a/answer/106368?hl=en A client sits on your DC and G Suite makes a call to it when a user tries to login. However they will be presented with an extra login dialogue. There are various options for avoiding that. The most straightforward one looks to me to be to use Azure AD. Essentially you set up ADFS between your onsite AD and Azure AD and then set up SSO between Azure AD and G Suite. https://docs.microsoft.com/en-us/azure/active-directory/active-directory-saas-google-apps-tutorialAzure AD G Suite SSO Happy to be corrected as it seems a bit of a pain and also not free.... Edited March 14, 2017 by jmak 1
FN-GM Posted March 14, 2017 Posted March 14, 2017 I have checked and there are a few old threads on SSO for G Suite but nothing I could find that is up to date. Is it possible to configure things so when users sign in to their computers with AD credentials then these auto sign them into G Suite? I know nothing about AD FS so would appreciate some pointers if it is at all possible to do. It is possible to do with ADFS. We have it setup here. I used this guide - Google Apps and Active Directory Federation Services – 1
mowgli82 Posted April 19, 2017 Posted April 19, 2017 Sorry to jump on this, im in the process of migrating services to a new DC, I've just installed Google Cloud Directory Sync and imported the config file from my other DC. I've run a simulate sync and have a load o f messages about "change stored non address primary key" is this normal?
FN-GM Posted April 19, 2017 Posted April 19, 2017 Sorry to jump on this, im in the process of migrating services to a new DC, I've just installed Google Cloud Directory Sync and imported the config file from my other DC. I've run a simulate sync and have a load o f messages about "change stored non address primary key" is this normal? I would open a new thread. This is not related to the rest of the topic. Thanks 1
enjay Posted April 19, 2017 Posted April 19, 2017 As @FN-GM has already said, it is possible to use ADFS for SSO (we do it here). A word of caution though, as some things won't work if you do. The "password-less" sign-on from a school computer is nice, and isn't a huge problem through a browser from home as you just have to re-enter your email address, BUT if you use SSO in this way, you cannot use the "sign in with your Google account" function which a number of websites offer. You also can't register Android or ChromeOS devices to the school Google account - this makes Chromebooks a fiddle to use, as you have to create a personal Google account and then add your school one as a linked account. I keep toying the idea of removing SSO and instead using password sync, except it would be an absolute pain to make this switch.
FN-GM Posted April 19, 2017 Posted April 19, 2017 . You also can't register Android or ChromeOS devices to the school Google account - this makes Chromebooks a fiddle to use, as you have to create a personal Google account and then add your school one as a linked account. We use both just fine. We have a hundreds of Chrome Devices. I do remember having to turn a setting on though.
enjay Posted April 19, 2017 Posted April 19, 2017 We use both just fine. We have a hundreds of Chrome Devices. I do remember having to turn a setting on though. I'd be VERY interested to know where that setting is. You don't happen to recall, do you?
FN-GM Posted April 19, 2017 Posted April 19, 2017 Ah, I see what you're after. If nothing better presents itself, could you use email filtering rules to deny students the ability to email outside their own (sub)domain? I remember doing that to make Primary students at my last school "internal only" email accounts. I think its this setting
enjay Posted April 20, 2017 Posted April 20, 2017 I don't have that setting in my Google Admin dashboard, possibly because we don't have any managed devices. The Chromebooks we're trying to use are personally-owned BYOD machines. Some users want to create a second user login on their Chromebook for their school account to keep them separate. Also, for those people who want to use a Chromebook for school but don't have a Google account of their own, it seems strange to have to create one just so you can link your school one to it (plus it brings the risk of using the "wrong" Google account).
FN-GM Posted April 20, 2017 Posted April 20, 2017 I don't have that setting in my Google Admin dashboard, possibly because we don't have any managed devices. The Chromebooks we're trying to use are personally-owned BYOD machines. Some users want to create a second user login on their Chromebook for their school account to keep them separate. Also, for those people who want to use a Chromebook for school but don't have a Google account of their own, it seems strange to have to create one just so you can link your school one to it (plus it brings the risk of using the "wrong" Google account). It should be there as its a user setting
enjay Posted April 20, 2017 Posted April 20, 2017 I really can't see it - could you talk me through the full route, from the main Admin Console homepage.
FN-GM Posted April 20, 2017 Posted April 20, 2017 Admin Console > Device Management > Chrome Management (on the left hand side) > User Settings > Search for saml and the results will be filtered. Cheers.
enjay Posted April 20, 2017 Posted April 20, 2017 Admin Console > Device Management > Chrome Management (on the left hand side) > User Settings > Search for saml and the results will be filtered. Definitely not there. How strange.
drappleyea Posted October 31, 2018 Posted October 31, 2018 I am curious what you mean by "password-less" SSO. Are you able to log into Windows and not be prompted for credentials when browsing Google resources? If so, how do you accomplish this with ADFS? I followed the guide referenced on this page and still am required to login at the ADFS login URL when launching Chrome or Windows prompt when loading IE. Thank you.
howartp Posted October 31, 2018 Posted October 31, 2018 Yes, if you’re logged onto Windows domain and have it setup right (!) you won’t need password to get into Google. If you’re at home accessing remotely you’ll still get promoted as you’re not on domain. It can take a bit of trial and error!
enjay Posted November 1, 2018 Posted November 1, 2018 I am curious what you mean by "password-less" SSO. Are you able to log into Windows and not be prompted for credentials when browsing Google resources? If so, how do you accomplish this with ADFS? I followed the guide referenced on this page and still am required to login at the ADFS login URL when launching Chrome or Windows prompt when loading IE. Thank you. Yes, I do mean Google resources log in automatically once you've authenticated to Windows. As for how, I don't actually know, it was set up for us. Sorry!
howartp Posted November 1, 2018 Posted November 1, 2018 Make sure you've added your ADFS url (eg sso.yourdomain.com) to the Intranet zone in IE. Peter
drappleyea Posted November 1, 2018 Posted November 1, 2018 Thanks Peter. It should already be in that Zone since we use a wild card URL. Any chance you can provide a guide that explains how to properly configure it? I have found many and followed them exactly and still get the ADFS login page.
drappleyea Posted November 1, 2018 Posted November 1, 2018 NVM - That worked. The wildcard for some reason does not. Thanks!
Simcfc73 Posted November 1, 2018 Posted November 1, 2018 I can't get this working, I click on the tile and it takes me to the google sign in page.
enjay Posted November 1, 2018 Posted November 1, 2018 I can't get this working, I click on the tile and it takes me to the google sign in page. What link are you following? Try using https://mail.google.com/a/your-domain-name.org.uk rather than just gmail.com
simpsonj Posted December 19, 2018 Posted December 19, 2018 We've got this setup at one of the schools in our MAT, but they've also added governors to the system, who can't change their password through their google account as it redirects them to change their AD password instead, which is obviously an issue as governors rarely log into school computers! Is there a way to set an exception to SSO for certain users, other than making them Super admins?
free780 Posted December 19, 2018 Posted December 19, 2018 Don't think so. Can they not just register for AzureAD Self Service Password Reset? 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now