question

matekubi-7768 avatar image
0 Votes"
matekubi-7768 asked ·

Integration between Azure and Google - SSO and User Provisioning from Google to Azure

Hello,

Scenario:
We have G Suite as an identity provider in our company. Some of users also use Azure and Office 365. We want to be able to login by using Google account to Azure Ad and later have this account in AD and assign roles and groups in AD and whole Azure. We want to change passwords in Google etc.

1) How to setup SSO from Google to Azure?

2) Is that possible to user provisioning from Google to Azure?

azure-active-directory
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

MarileeTurscak avatar image
0 Votes"
MarileeTurscak answered ·

You need to integrate Google Cloud (G Suite) Connector with Azure Active Directory.

To do this, you need:

  • An Azure AD subscription.

  • Google Cloud (G Suite) Connector single sign-on (SSO) enabled subscription.

  • A Google Apps subscription or Google Cloud Platform subscription.

https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial

You can provision users from Azure to Google but not the other way around.

https://cloud.google.com/solutions/federating-gcp-with-azure-ad-configuring-provisioning-and-single-sign-on

· Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

matekubi-7768 avatar image
0 Votes"
matekubi-7768 answered ·

Hello,

Thanks for your response.

Mentioned by you tutorial describes the integration process in another way. From Azure to Google. As below:

  • Control in Azure AD who has access to Google Cloud (G Suite) Connector.

  • Enable your users to be automatically signed-in to Google Cloud (G Suite) Connector with their Azure AD accounts.

  • Manage your accounts in one central location - the Azure portal.

I'm looking for a solution in another way - from Google (this is an identity provider) to Azure. Can you help with this?



· Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

JeevanDesarda-0592 avatar image
0 Votes"
JeevanDesarda-0592 answered ·

As you would like to use G Suite as IDP you need to follow this article. This article talks about how you configure Office 365 for SAML IDP.
https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-fed-saml-idp

This should help you get this integration working.

Thanks,

Jeevan Desarda

· Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.