Jump to content

Recommended Posts

Posted

Our school primarily uses Google workspace but we have wanted to explore the idea of getting rid of our physical servers due to the rising costs and lack of budgets. We have A3 Microsoft Licenses which we use for PowerBI mainly but are planning on enrolling devices to intune which is included.

 

My question is has anyone sucessfully been able to setup intune to work alongside GCPW so that end users are able to login to the managed windows machines with their Google accounts? Or anyone ran into issues with this. Ideally, I'd like to not confuse staff having a seperate Microsoft login to logon to windows to etc.

Posted

While not Intune, I actually have Google Workspace using Entra ID as the SSO Provider, so you log into windows, then when you go to a Google service and type in your email address it then goes hey, you have the Entra ID cookie and cert, I will log you into Google Workspace without typing in the password.

  • Like 1
Posted
On 11/06/2026 at 12:58, BKGarry said:

While not Intune, I actually have Google Workspace using Entra ID as the SSO Provider, so you log into windows, then when you go to a Google service and type in your email address it then goes hey, you have the Entra ID cookie and cert, I will log you into Google Workspace without typing in the password.

 

Ooh interesting. would you be able to share any more on this please? We too are Google primarily, but have an M365 footprint for PowerBI and Intune.

 

Right now, we have no SSO, but passwords sync from AD to Google to make lives a little easier, but full on SSO between Google and AD/Entra would be great. I was originally looking to have Google as the IdP but this might make more sense?

Posted

So I have AD so the sync to Google using the installed GCDS version on the server, that works just fine.

 

I then setup the SAML stuff here - 

 
This way you don't need to Google IdP on workstations for logging in, as it just isn't needed. And where everyone uses outlook for email, even students, the SAML Cookie is kept on the chromebooks they use that automatically logs them into M365.
 
That way I have full domain login here, with all the control of GPO etc while there is a SSO for Google, you just need to enter you email address and it goes, is this you and you click OK on windows machines
  • Thanks 2
Posted
1 minute ago, BKGarry said:

So I have AD so the sync to Google using the installed GCDS version on the server, that works just fine.

 

I then setup the SAML stuff here - 

 
This way you don't need to Google IdP on workstations for logging in, as it just isn't needed. And where everyone uses outlook for email, even students, the SAML Cookie is kept on the chromebooks they use that automatically logs them into M365.
 
That way I have full domain login here, with all the control of GPO etc while there is a SSO for Google, you just need to enter you email address and it goes, is this you and you click OK on windows machines

Thanks, will look into this! Much appreciated.

Posted

oh and while you are testing it you can set it to just one OU in Google Workspace, which makes it easier.

 

It will not do SAML SSO for Google Admins though, as a safety feature in case there is an issue

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...