Follow these step-by-step instructions to configure SSO on your IT Glue account using Google as a SAML identity provider. This is great for partners who use Google but haven't yet implemented SSO. By using SSO with Google, you can set up basic SSO authentication without introducing a third-party service such as OneLogin.
If you are configuring SSO for MyGlue using Google, the instructions are the same but you will need to enter different values when configuring Google and your MyGlue account settings page. Click here to see the different values that you'll need to substitute in at key steps within this KB article.
- You must have Administrator level access to IT Glue to configure SSO on your account.
- Ensure your users are provisioned in the identity provider (Google), with exactly the same email address as their IT Glue account. We don’t create user accounts under SSO.
- Before turning this feature on, log in to your IT Glue account twice - once in a regular browser and once in an incognito/private window. This is to ensure that you are still logged in to your account if you get locked out in the other window. Alternatively, you can also log in to two separate browsers.
- As an administrator on your G Suite account, sign in to https://admin.google.com/.
- Click through to Apps > SAML Apps.
- Click the blue plus sign icon in the bottom right corner to open a dialog that will help you build a custom app step by step.
- From the Enable SSO for SAML Application (step 1/5), click on Setup my own custom app at the bottom of the screen.
- From the Google IdP Information (step 2/5), you will find an SSO URL and Entity ID which you will enter in IT Glue later. For now, click Download to download the certificate. You'll need information from it in a moment. Click Next.
- From the Basic information for your Custom App (step 3/5), you can add a name (required), description, and logo in the fields provided to identify the app. Click Next.
- From the Service Provider Details (step 4/5), enter the required information below. When you're done entering the information, click next.
- ACS URL - The URL should be https://subdomain.itglue.com/saml/consume (with your IT Glue subdomain where it says subdomain)
- Entity ID - Enter https://subdomain.itglue.com (with your IT Glue subdomain where it says subdomain)
- Start URL - This is the login URL and it should also be https://subdomain.itglue.com (with your IT Glue subdomain where it says subdomain)
- Signed Response - Disable
- Name ID - Basic Information – Primary Email
- Name ID Format - EMAIL
The screenshot below shows you the screen with sample URLs:
- Leave this window open as you configure IT Glue, but remember to click Finish on the Attribute Mapping (step 5/5) when you are done configuring SSO in IT Glue. No action is required on the Attribute Mapping step.
Getting the fingerprint
To get the fingerprint, you can use the third-party fingerprint calculator from OneLogin:
- Go to https://developers.onelogin.com/saml/online-tools/x509-certs/calculate-fingerprint.
- Paste in the certificate you downloaded further above. To do this, you will need to open the certificate in a text editor to copy the certificate content.
- Select sha1 in the Algorithm drop-down menu.
- Click the CALCULATE FINGERPRINT button. The fingerprint looks something like:
Configuring IT Glue
After setting up Google, you need to configure your IT Glue account to authenticate using SAML. You will need the fingerprint and a few pieces of information from Google to finish the configuration.
- Log in to IT Glue and click Account in the top navigation bar.
- Click Settings from the sidebar.
- Click on the Authentication tab and then turn the Enable SAML SSO toggle switch to ON. Once this is turned on, a form will appear. You will need to collect information from G-Suite and enter it into this form.
- Copy the Google Entity ID and paste it in the IT Glue Issuer URL field.
- Copy the Google SSO URL and paste it in the IT Glue SAML Login Endpoint URL field.
- For the SAML Logout Endpoint URL, enter a URL where IT Glue can redirect users after they sign out of IT Glue. Google does not provide this URL, and this value cannot be left empty. Recommended value: https://apps.google.com/user/hub.
- Enter the fingerprint you created further above in the IT Glue Fingerprint field.
- Enter the certificate in the IT Glue Certificate field.
Important. Ensure there are no extra spaces trailing at the end of the Certificate string (i.e. after -----END CERTIFICATE-----).
- Click Save.
Warning. Click Save only when all information has been entered. If you turn on SSO prematurely, it will break the sign-in experience for all users on your account.
Before you can test your access, you must make one more change.
If you are setting up SSO for MyGlue, complete all steps as instructed in this article. However, there are a few key steps in which you'll need to substitute in different values:
Complete step 7 in the Configuring Google section above but use the following values instead:
- ACS URL - https://app.myglue.com/saml/consume
- Entity ID - https://app.myglue.com
- Start URL - https://app.myglue.com
Enabling the app for your domain
When you create a SAML app, it is turned off by default. This means that for users signed in to your Google domain account, the app will not be visible to them. To turn it on, go to your Google Admin console, click App, and then click SAML Apps. Find your app and select an action from the right side of the screen:
If you do not want to activate the app for everyone, you can take advantage of G Suite/Google Apps organizational units and activate the app for only a subset of users. Refer to the Google documentation for further details about creating these organizations.
Testing SSO authentication
Before you configured SSO, you should have created two IT Glue browser sessions. If you get locked out, you will be able to use the incognito/private window to turn off SSO while you investigate the cause.
For testing, sign out of Google. In a new browser session, sign in to Google again. Next, on the Google search page, click the grid icon to expand the apps menu and then click the More link to see additional apps. Find the app you created and click on it to sign in to IT Glue.
Another way to test SSO access is to go to your account subdomain (mycompany.itglue.com) directly.
When the SSO server is unavailable, how do we access our accounts?
If your SSO provider's service is unavailable, you can still login using your IT Glue username and password at app.itglue.com.
If your SSO is not working, confirm your provider's service is available. Send us an email for assistance.
How do we disable SSO for a user?
If a member has left your team, and you’d like to disable their user account, an Administrator or Manager will need to delete their account from the Account > Users page in IT Glue. We don't currently support disabling user accounts through the SSO server.
Why am I asked to sign in twice before accessing IT Glue?
This can sometimes be triggered when setting up the service provider details (which Step 7 Service Provider Details in Configuring Google indicates to use https://subdomain.itglue.com in the Start URL field). To prevent this leave the "Start URL" blank (see image below).