---
title: Google SAML
slug: google-saml
description: Configure Google SAML single sign-on to authenticate users with their Google accounts.
image: https://archbee-image-uploads.s3.amazonaws.com/oAyFj2GHlBeBVWF5OAir2/e_qHb1m7hHbasnTc0QETS_1.png
docTags: 
createdAt: 2025-02-10T14:58:51.047Z
---

:::hint{type="info"}
This feature is available to Enterprise customers.
:::

The following manual configuration creates an SAML SSO configuration for your Enterprise organization.

## Prerequisites

- `Owner` role in an Enterprise organization
- Google Admin console account

## Supported features

This configuration supports the following:

- Service Provider initiated SSO
- Single Log Out \[optional]

## Configuration Steps

Before configuring SSO, you need to assign a namespace and download your service provider certificate in Make. These steps provide information you need to enter later.

### Create your namespace in Make

::::WorkflowBlock
:::WorkflowBlockItem
Click **Organization** in the left sidebar.
:::

:::WorkflowBlockItem
Click the **SSO** tab.
:::

:::WorkflowBlockItem
Under **Namespace**, enter the namespace you want for your organization. For example, `acmecorp`. Your organization members enter this namespace when they log in via SSO.
:::

:::WorkflowBlockItem
Under **SSO type**, select **SAML 2.0**.
:::

:::WorkflowBlockItem
Copy the **Redirect URL** and save it in a safe place. You will use this later when you create your SAML integration in the Google admin portal.
:::
::::

### Create an SAML application in the Google admin portal

::::WorkflowBlock
:::WorkflowBlockItem
Login to the Google admin console.
:::

:::WorkflowBlockItem
From the dashboard's left menu, click **Apps > Web and mobile apps**.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-Q3Q4KT-Rqx_XNYlyLrd5I-20250228-142929.png" size="80" width="960" height="494" position="flex-start" alt="Google admin console" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Add app** and select **Add custom SAML app**.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-MgIH94jUfHazZZ-TCL8kZ-20250228-143141.png" size="80" width="1001" height="422" position="flex-start" alt="Add custom SAML app" showCaption="false"}
:::

:::WorkflowBlockItem
Enter an **App name** and **Description**.
:::

:::WorkflowBlockItem
Copy the **SSO URL** and save it in a safe place. You will use this later.
:::

:::WorkflowBlockItem
On the same screen, download the certificate and save it in a safe place.
:::

:::WorkflowBlockItem
Click **Continue**.
:::

:::WorkflowBlockItem
Enter the **Service provider details**. You can find thise information in the Make SSO configuration tab.

**ACS URL:&#x20;**`https://www.make.com/sso/saml/{namespace}`

**Entity ID: &#x20;**`https://www.make.com/sso/saml/{namespace}/metadata.xml`

Replace \{namespace} with your [namespace](docId\:c2tfQhgM9UQannl5dWZhk).

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-2Q3hdFJhG4C4IhTAMIMv8-20250228-140928.png" size="60" width="601" height="217" position="flex-start" alt="Service provider details" showCaption="false"}
:::

:::WorkflowBlockItem
Click **Continue**.
:::

:::WorkflowBlockItem
Enter the App attributes.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-MoEzoFAaBw8TV8byrIIQA-20250228-140414.png" size="80" width="1000" height="574" position="flex-start" alt="App attributes" showCaption="false"}
:::

:::WorkflowBlockItem
Update the **User access** to On for everyone.

::Image[]{src="https://api.archbee.com/api/optimize/yAufeXqD1oGWOPBNi5MAm-xd-cn2h216HDWl1q8dJ_0-20250228-140758.png" size="80" width="1224" height="589" position="flex-start" alt="User access" showCaption="false"}
:::
::::

### Update the SSO in Make

::::WorkflowBlock
:::WorkflowBlockItem
Click **Org** in the left sidebar.
:::

:::WorkflowBlockItem
Switch to the **SSO** tab.
:::

:::WorkflowBlockItem
Activate the **Service Provider Certificate** and download it.
:::

:::WorkflowBlockItem
In the **Identity Provider Certificate** section, click **Extract**. In the **P12, PFX or PEM file** field, upload the certificate downloaded from step 6 of [Create an SAML application in the Google admin portal](docId\:c2tfQhgM9UQannl5dWZhk) above. Then click **Save**.&#x20;

![](https://api.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/3jW3Sv4rWQmjvIyWI09I7-20251015-093508.png)
:::

:::WorkflowBlockItem
Enter the SSO URL from step 5 of [Create an SAML application in the Google admin portal](docId\:c2tfQhgM9UQannl5dWZhk) above and paste it into the **IDP Login URL** field in Make.
:::

:::WorkflowBlockItem
Enter the **Login IML resolve**.

```javascript
{
    "email": "{{get(user.attributes.email, 1)}}",
    "name": "{{get(user.attributes.firstName, 1)}}{{get(user.attributes.lastName, 1)}}",
    "id": "{{get(user.attributes.email, 1)}}"
}
```

Optional: It is a good practice to validate the JSON string in IML Resolve to ensure it is correct. You can use the [JSONLint](https://jsonlint.com/) website to perform this validation.
:::

:::WorkflowBlockItem
Enter the following additional information:

**Allows Unencrypted Assertions**: No

**Allow Unsigned Responses**: No

**Sign Requests**: Yes

::Image[]{src="https://app.archbee.com/api/optimize/oAyFj2GHlBeBVWF5OAir2/VWZT_sa_zTOmbwdrcTeTq-20251015-093124.png" size="60" width="2070" height="1914" position="center" showCaption="false"}
:::
::::

## Service provider initiated SSO

::::WorkflowBlock
:::WorkflowBlockItem
Go to [make.com](https://make.com).&#x20;
:::

:::WorkflowBlockItem
Click **Sign in with SSO**.
:::

:::WorkflowBlockItem
Enter the namespace you chose for your organization.
:::

:::WorkflowBlockItem
Log in using your Microsoft credentials and consent to Make's access to your user data.
:::
::::

