Deeza1 Posted June 11 Posted June 11 Our school primarily uses Google workspace but we have wanted to explore the idea of getting rid of our physical servers due to the rising costs and lack of budgets. We have A3 Microsoft Licenses which we use for PowerBI mainly but are planning on enrolling devices to intune which is included. My question is has anyone sucessfully been able to setup intune to work alongside GCPW so that end users are able to login to the managed windows machines with their Google accounts? Or anyone ran into issues with this. Ideally, I'd like to not confuse staff having a seperate Microsoft login to logon to windows to etc.
BKGarry Posted June 11 Posted June 11 While not Intune, I actually have Google Workspace using Entra ID as the SSO Provider, so you log into windows, then when you go to a Google service and type in your email address it then goes hey, you have the Entra ID cookie and cert, I will log you into Google Workspace without typing in the password. 1
Planehazza Posted June 17 Posted June 17 On 11/06/2026 at 12:58, BKGarry said: While not Intune, I actually have Google Workspace using Entra ID as the SSO Provider, so you log into windows, then when you go to a Google service and type in your email address it then goes hey, you have the Entra ID cookie and cert, I will log you into Google Workspace without typing in the password. Ooh interesting. would you be able to share any more on this please? We too are Google primarily, but have an M365 footprint for PowerBI and Intune. Right now, we have no SSO, but passwords sync from AD to Google to make lives a little easier, but full on SSO between Google and AD/Entra would be great. I was originally looking to have Google as the IdP but this might make more sense?
BKGarry Posted June 17 Posted June 17 So I have AD so the sync to Google using the installed GCDS version on the server, that works just fine. I then setup the SAML stuff here - https://docs.cloud.google.com/architecture/identity/federating-gcp-with-azure-ad-configuring-provisioning-and-single-sign-on#configure_microsoft_entra_id_for_single_sign-on This way you don't need to Google IdP on workstations for logging in, as it just isn't needed. And where everyone uses outlook for email, even students, the SAML Cookie is kept on the chromebooks they use that automatically logs them into M365. That way I have full domain login here, with all the control of GPO etc while there is a SSO for Google, you just need to enter you email address and it goes, is this you and you click OK on windows machines 2
Planehazza Posted June 17 Posted June 17 1 minute ago, BKGarry said: So I have AD so the sync to Google using the installed GCDS version on the server, that works just fine. I then setup the SAML stuff here - https://docs.cloud.google.com/architecture/identity/federating-gcp-with-azure-ad-configuring-provisioning-and-single-sign-on#configure_microsoft_entra_id_for_single_sign-on This way you don't need to Google IdP on workstations for logging in, as it just isn't needed. And where everyone uses outlook for email, even students, the SAML Cookie is kept on the chromebooks they use that automatically logs them into M365. That way I have full domain login here, with all the control of GPO etc while there is a SSO for Google, you just need to enter you email address and it goes, is this you and you click OK on windows machines Thanks, will look into this! Much appreciated.
BKGarry Posted June 17 Posted June 17 oh and while you are testing it you can set it to just one OU in Google Workspace, which makes it easier. It will not do SAML SSO for Google Admins though, as a safety feature in case there is an issue
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now