Google Workspace SAML2 SSO
Seamlessly integrate Flexopus with Google Workspace via SAML2 and control who can access Flexopus in the Google Workspace Admin Console.
How does Google Workspace SAML2 SSO integration work?
The integration of Google Workspace SAML2 Single Sign-On (SSO) offers a seamless and secure login method for users, which can be activated in just a few steps. The integration also includes the automatic synchronization of user profile pictures, which automatically imports the profile picture from the Google Workspace account into the FlexOpus account. A key security aspect of this integration is the use of whitelists. Administrators have the option to specify which email addresses from certain domains should be granted access.
About Google Workspace
Google Workspace provides a SAML-based single sign-on (SSO) solution that allows users to log in to multiple cloud applications with a single set of credentials. This solution promotes security and efficiency by reducing the need to remember multiple passwords and supports integration with various identity providers.
Further integrations
Fragen und Antworten
Werden bei der SAML2-Anmeldung Passwörter an Flexopus übertragen?
Nein. Beim SAML2-Login gibt der Nutzer sein Passwort ausschließlich bei Google ein. Flexopus erhält lediglich eine verschlüsselte Bestätigung der Identität – keine Zugangsdaten. Flexopus speichert keine Passwörter.
Was passiert, wenn sich die E-Mail-Adresse eines Nutzers ändert?
Da die E-Mail-Adresse als eindeutiger Identifikator (UPN) verwendet wird, führt eine Änderung dazu, dass in Flexopus ein neues Benutzerprofil angelegt wird. Das alte Profil bleibt bestehen. Wir empfehlen, bei einer E-Mail-Änderung den Flexopus-Support zu kontaktieren, um eine Zusammenführung der Profile zu veranlassen.
Kann ich festlegen, welche Mitarbeitenden Zugang zu Flexopus erhalten?
Ja. In der Google Admin Console können Administratoren genau steuern, welche Nutzer oder Organisationseinheiten Zugang zur Flexopus-App erhalten. Zusätzlich kann in Flexopus eine Domain-Whitelist konfiguriert werden, die nur bestimmte E-Mail-Domänen zulässt.
Werden neue Mitarbeitende automatisch in Flexopus angelegt?
Ja, sofern die entsprechende Einstellung in Flexopus aktiv ist. Beim ersten erfolgreichen SSO-Login wird automatisch ein Benutzerprofil in Flexopus erstellt. Diese Option ist standardmäßig aktiviert und kann bei Bedarf deaktiviert werden.
Kann ich den Login per E-Mail und Passwort deaktivieren, sobald SSO eingerichtet ist?
Ja. In den Flexopus-Authentifizierungseinstellungen kann der E-Mail/Passwort-Login vollständig deaktiviert werden. Für Notfälle bleibt ein alternativer Adminzugang über eine gesonderte Login-URL erhalten.

