Deeza1 Posted June 11 Posted June 11 Our school primarily uses Google workspace but we have wanted to explore the idea of getting rid of our physical servers due to the rising costs and lack of budgets. We have A3 Microsoft Licenses which we use for PowerBI mainly but are planning on enrolling devices to intune which is included. My question is has anyone sucessfully been able to setup intune to work alongside GCPW so that end users are able to login to the managed windows machines with their Google accounts? Or anyone ran into issues with this. Ideally, I'd like to not confuse staff having a seperate Microsoft login to logon to windows to etc.
BKGarry Posted June 11 Posted June 11 While not Intune, I actually have Google Workspace using Entra ID as the SSO Provider, so you log into windows, then when you go to a Google service and type in your email address it then goes hey, you have the Entra ID cookie and cert, I will log you into Google Workspace without typing in the password. 1
Planehazza Posted June 17 Posted June 17 On 11/06/2026 at 12:58, BKGarry said: While not Intune, I actually have Google Workspace using Entra ID as the SSO Provider, so you log into windows, then when you go to a Google service and type in your email address it then goes hey, you have the Entra ID cookie and cert, I will log you into Google Workspace without typing in the password. Ooh interesting. would you be able to share any more on this please? We too are Google primarily, but have an M365 footprint for PowerBI and Intune. Right now, we have no SSO, but passwords sync from AD to Google to make lives a little easier, but full on SSO between Google and AD/Entra would be great. I was originally looking to have Google as the IdP but this might make more sense?
BKGarry Posted June 17 Posted June 17 So I have AD so the sync to Google using the installed GCDS version on the server, that works just fine. I then setup the SAML stuff here - https://docs.cloud.google.com/architecture/identity/federating-gcp-with-azure-ad-configuring-provisioning-and-single-sign-on#configure_microsoft_entra_id_for_single_sign-on This way you don't need to Google IdP on workstations for logging in, as it just isn't needed. And where everyone uses outlook for email, even students, the SAML Cookie is kept on the chromebooks they use that automatically logs them into M365. That way I have full domain login here, with all the control of GPO etc while there is a SSO for Google, you just need to enter you email address and it goes, is this you and you click OK on windows machines 3
Planehazza Posted June 17 Posted June 17 1 minute ago, BKGarry said: So I have AD so the sync to Google using the installed GCDS version on the server, that works just fine. I then setup the SAML stuff here - https://docs.cloud.google.com/architecture/identity/federating-gcp-with-azure-ad-configuring-provisioning-and-single-sign-on#configure_microsoft_entra_id_for_single_sign-on This way you don't need to Google IdP on workstations for logging in, as it just isn't needed. And where everyone uses outlook for email, even students, the SAML Cookie is kept on the chromebooks they use that automatically logs them into M365. That way I have full domain login here, with all the control of GPO etc while there is a SSO for Google, you just need to enter you email address and it goes, is this you and you click OK on windows machines Thanks, will look into this! Much appreciated.
BKGarry Posted June 17 Posted June 17 oh and while you are testing it you can set it to just one OU in Google Workspace, which makes it easier. It will not do SAML SSO for Google Admins though, as a safety feature in case there is an issue 1
Deeza1 Posted 22 hours ago Author Posted 22 hours ago On 17/06/2026 at 10:59, BKGarry said: oh and while you are testing it you can set it to just one OU in Google Workspace, which makes it easier. It will not do SAML SSO for Google Admins though, as a safety feature in case there is an issue Thanks for the help bud. Sorry for the late reply but was a good wormhole to go down! It did work but we ended up not doing it anyway as it would confuse staff. cheers 1
BKGarry Posted 10 hours ago Posted 10 hours ago 11 hours ago, Deeza1 said: Thanks for the help bud. Sorry for the late reply but was a good wormhole to go down! It did work but we ended up not doing it anyway as it would confuse staff. cheers Sorry to hear that, but at least you seem to have enjoyed it.
Rogueleeder Posted 10 hours ago Posted 10 hours ago I've done it the other way round. I had Google Provisioning Entra ID, then used Web Sign In via Intune after federating Microsoft to Google. User signs in and a Google Login Box appears. I did have to use Intune Shared PC Mode on our student and shared PCs to stop Windows Hello Setup, and because its Web Sign In, I'm snookered if the Internet ever goes out. For Assigned Machines I've had issues with MFA just giving me a blank box or saying the person doesn't exist in Entra so I use TAP Codes to setup Windows Hello for people so they can use their device offline. Ironically, we're going to be doing Wonde MyLogin soon so both Microsoft and Google will point to that going forward, though the same is process will apply.
Rogueleeder Posted 10 hours ago Posted 10 hours ago 3 minutes ago, 6Foot3 said: Chromeflex? That only works when all the software across the school is ChromeOS compatible, my IT suite won't ever move to ChromeOS due to the programmes used in the curriculum, the Maths Department staff are the same as they use resources which break in Google Sheets/Docs etc so need MS Apps so have full on desktops.
TwistedHelixis Posted 8 hours ago Posted 8 hours ago (edited) All our schools are logging into their Windows devices using their Google accounts with GCPW (Google credential provider). It very very simple to install and setup. Just download the installer from Workspace and make a few settings changes, run the installer on a windows device, then 30 seconds later instead of the Windows login they get a Google login on their Windows device. Also saves the need to manage a separate system (Microsoft) It also support GPO polices and things like Bitlocker if needed. It also now fully supports 2 step authentication, inducing Yubi keys Google offer a free version and a very cheap licensed version, which is about £4 per year. If you need any info, ask 🙂 EDITED Edited 7 hours ago by TwistedHelixis
Rogueleeder Posted 8 hours ago Posted 8 hours ago Just now, TwistedHelixis said: All our schools are logging into their Windows devices using their Google accounts with GCPW (Google credential provider). It very very simple to install and setup, then instead of the Windows login they get a Google login. It does also support GPO polices and things like Bitlocker if needed. My only complaint with GCPW is I could never get it working on InTune Devices, the login box would never load properly. Google Device Management for Windows isn't quite there for me yet, I need the ability to deploy apps easily 1
TwistedHelixis Posted 7 hours ago Posted 7 hours ago Quote I need the ability to deploy apps easily How many devices do you have?
TwistedHelixis Posted 7 hours ago Posted 7 hours ago (edited) Quote the login box would never load properly Not tested it on InTune devices, as the reason for us using GCPWwas so we didn't need anything Microsoft, but Make sure Chrome is installed first, otherwise the login box will not work and make sure to set a domain. Edited 7 hours ago by TwistedHelixis
Rogueleeder Posted 7 hours ago Posted 7 hours ago 5 minutes ago, TwistedHelixis said: How many devices do you have? Around 60 Windows Laptops and Desktops all in all 3 minutes ago, TwistedHelixis said: Not tested it on InTune devices, as the reason for us using GCPWwas so we didn't need anything Microsoft, but Make sure Chrome is installed first, otherwise the login box will not work and make sure to set a domain. Yep made sure that was the case, Chrome installed with the domain set, I assumed it was a conflict with InTune. Spent most of the summer trying to get it working, the only time it worked was if I had the PC completely unmanaged
TwistedHelixis Posted 7 hours ago Posted 7 hours ago (edited) Quote Around 60 Windows Laptops and Desktops all in all Have you looked at Action1? https://www.action1.com/ Its free for 200 devices, patching works for Windows updates and also software. Once its setup I never need to do anything apart from check all the devices and servers have updated. I have it set to delay updates on teachers laptops by 1 week and delay servers for 2 weeks, so if there are any patch issues I can remove those before they deploy. A1 also lets you deploy any software very easily and then keep that software updated. It also has built in remote access if needed, so you can help end users and it also comes with Vulnerability detection and remediation. As its not Microsoft it actually works and is simple to setup. For free its amazing 👍 Quote I assumed it was a conflict with InTune. 👍 Edited 6 hours ago by TwistedHelixis
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now