Configure SSO with Google Workspace
Before you begin — Read SSO Integration: How It Works first. Each user's Sfax Username must equal their Google primary email.
In the Google Admin console, go to Apps › Web and mobile apps › Add custom SAML app, then complete the Service Provider Details.
| Google field | Value |
|---|---|
| ACS URL | https://app.sfaxme.com/sso/sso.aspx |
| Entity ID | https://app.sfaxme.com/ |
| Start URL | Leave blank (Start URL sets RelayState) |
| Name ID format | |
| Name ID | Basic Information › Primary email (the default) |
| Signed response | Leave unchecked. Sfax requires the assertion to be signed, which Google does by default; signing the full response is not required. |
Then turn the app ON for the correct organizational unit or access group.
Leave Start URL blank — Google's Start URL sets the SAML RelayState. Pointing it at a Sfax URL can force a redirect that blocks sign-in, so leave it empty and launch Sfax from the Google app launcher.