> ## Documentation Index
> Fetch the complete documentation index at: https://docs.macstadium.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Enable SAML SSO with Google Workspace Federation

> Configure SAML SSO for MacStadium Portal via Google Workspace. Create a custom SAML app in Google Admin, download metadata, and send it to MacStadium.

<Note>SAML SSO is a paid offering. Contact your account team through the [Customer Portal](https://portal.macstadium.com) for more information.</Note>

<Warning>MacStadium does not support IdP-initiated logins. After SSO is configured, all users must log in at [portal.macstadium.com/sso](https://portal.macstadium.com/sso) using the ID provided by the MacStadium team.</Warning>

1. Go to [Google Admin Console](https://admin.google.com/)

2. Navigate to “Web and mobile apps” (Apps → Web and mobile apps in the left menu or use [this link](https://admin.google.com/ac/apps/unified))\\
   <img src="https://mintcdn.com/macstadiuminc/bll0b6tt9scf_iyB/images/attachments/28262749454747.png?fit=max&auto=format&n=bll0b6tt9scf_iyB&q=85&s=f60470be120fbf7a1e365e2a2686a536" alt="Google Admin Console left menu with Web and mobile apps option highlighted" width="2354" height="1466" data-path="images/attachments/28262749454747.png" />

3. Create a new “Custom SAML App” (click Add app)\\
   <img src="https://mintcdn.com/macstadiuminc/bll0b6tt9scf_iyB/images/attachments/28262749456027.png?fit=max&auto=format&n=bll0b6tt9scf_iyB&q=85&s=fe86899bcf48ee818cd7e4303559f9c8" alt="Google Admin Web and mobile apps page with Add app dropdown showing Custom SAML app" width="974" height="566" data-path="images/attachments/28262749456027.png" />

4. Enter “App name” (e.g. MacStadium Portal)

5. Download the metadata by clicking Download Metadata - Keep this file for sharing with our support team later.\\
   <img src="https://mintcdn.com/macstadiuminc/bll0b6tt9scf_iyB/images/attachments/28262763978523.png?fit=max&auto=format&n=bll0b6tt9scf_iyB&q=85&s=e33456d732a829cef34bbe5491ca9172" alt="Google SAML app setup with Download Metadata button" width="2560" height="1740" data-path="images/attachments/28262763978523.png" />

6. Configure
   * **ACS URL:** `https://idp.macstadium.com/saml2/idpresponse`
   * **Entity ID:** `urn:amazon:cognito:sp:us-east-1_pusi8jHs1`
   * Configure email mapping with the "Show Advanced Settings" menu
   * Select EMAIL for the Name ID Format field
   * Select Primary Email for the Name ID field\\
     <img src="https://mintcdn.com/macstadiuminc/bll0b6tt9scf_iyB/images/attachments/28262763979675.png?fit=max&auto=format&n=bll0b6tt9scf_iyB&q=85&s=b6d9da962c207eef1f35b0df8a6129d8" alt="Google SAML app Service Provider Details with ACS URL, Entity ID, and Name ID fields" width="2560" height="1740" data-path="images/attachments/28262763979675.png" />

7. Map Primary email to email\\
   <img src="https://mintcdn.com/macstadiuminc/bll0b6tt9scf_iyB/images/attachments/28262749462171.png?fit=max&auto=format&n=bll0b6tt9scf_iyB&q=85&s=0a7d0b3887b02886fb12856a949289f7" alt="Google SAML app Attribute mapping with Primary Email mapped to email" width="2416" height="1642" data-path="images/attachments/28262749462171.png" />

8. Click Finish to complete the setup

9. Provide our support team with the metadata file from step 5
