Integrations

/

Google Workspace SAML2 SSO

With the Google Workspace SAML2 SSO integration, your employees log in to Flexopus with their familiar Google login credentials – securely, easily and without additional passwords. User management remains centralized in Google Workspace.

No items found.
No items found.

What is the Google Workspace SAML2 SSO integration?

The Google Workspace SAML2 SSO integration connects Flexopus to your Google Workspace directory via the standardized SAML2 protocol (Security Assertion Markup Language). In this process, Google Workspace takes on the role of the Identity Provider (IdP): It confirms the identity of the users and securely transmits this information to Flexopus.

During the login process, the user is redirected from Flexopus to Google, logs in there with their existing Google login credentials, and is then automatically logged into Flexopus. Flexopus itself does not store any passwords.

Additionally, profile attributes such as first name, last name, email address, department and job title can be automatically transferred and synchronized in Flexopus via the SAML2 connection.

What is the purpose of integration?

The integration simplifies access to Flexopus for the entire organization and significantly reduces administrative effort. Typical use cases include:

  • Central login management: Employees use their Google login credentials for Flexopus as well – no separate account is necessary.
  • Automatic user creation: New users are automatically created in Flexopus upon their first SSO login, without manual setup by administrators.
  • Access control via Google Workspace: Administrators define in the Google Admin Console which users or organizational units have access to Flexopus.
  • Profile synchronization: Master data such as name, department and job title are taken directly from Google Workspace and kept up to date.
  • Increased security: Central authentication via Google eliminates the risk of weak or reused passwords in Flexopus.

How easy is the integration?

The setup of the Google Workspace SAML2 SSO integration is done entirely via the Google Admin Console and the Flexopus administration settings. No programming knowledge is required.

Essentially, a custom SAML app is created in Google Workspace, a metadata file is downloaded, and uploaded to Flexopus. Next, some attributes are mapped and access rights are configured. After a short test, the integration is ready for use.

For complete step-by-step setup instructions, please visit our Help Center.

What are the advantages of integration?

  • Simple login for everyone: Employees log in with their familiar Google login details – no additional password for Flexopus.
  • Automatic user creation: New users are automatically created in Flexopus upon their first login – no manual effort required from admins.
  • Central access control: Whoever is granted access to Flexopus is controlled directly in the Google Admin Console.
  • Profile synchronization: Name, email, department and job title are automatically imported from Google Workspace.
  • Increased security: No additional passwords, no password management in Flexopus – authentication is handled entirely by Google.
  • Enforceable SSO: Administrators can disable email/password login in Flexopus and thus enforce SSO as the only login option.
  • Included free of charge: SAML2 SSO integration is part of Flexopus and does not incur any additional license costs.
Developed By
Flexopus GmbH
Frequently Asked Questions

questions and answers

Are passwords transmitted to Flexopus during SAML2 login?

No. With SAML2 login, the user enters their password exclusively at Google. Flexopus only receives encrypted confirmation of identity – no login data. Flexopus does not store passwords.

What happens if a user's email address changes?

Since the email address is used as a unique identifier (UPN), a change will result in a new user profile being created in Flexopus. The old profile will remain. We recommend contacting Flexopus support if your email address changes, in order to arrange for the profiles to be merged.

Can I specify which employees have access to Flexopus?

Yes. In the Google Admin Console, administrators can precisely control which users or organizational units have access to the Flexopus app. Additionally, Flexopus allows you to configure a domain whitelist that only permits certain email domains.

Are new employees automatically added to Flexopus?

Yes, provided the corresponding setting is active in Flexopus. A user profile is automatically created in Flexopus upon the first successful SSO login. This option is enabled by default and can be disabled if needed.

Can I disable email and password login once SSO is set up?

Yes. In the Flexopus authentication settings, email/password login can be completely disabled. For emergencies, an alternative admin access will remain available via a separate login URL.