

For example, if the domain in your email address is, you would place your. Where should match the domain in your email address. Your IdP configuration must be placed at this URI on your domain: This file establishes which IdP you use and allows your external collaborators to discover your IdP settings. well-known file on your organization’s public website. To set up your third-party or Google IdP, you need to place a. After you establish the connection, you need to allowlist your IdP in the Admin console. To connect Google Workspace to your identity provider (IdP), you can use a. You must provide your IdP settings directly to your collaborator before you share encrypted files for the first time, as well as any time you change your IdP settings. Your collaborator's external key service can't access your IdP settings in the Admin console. This access can be automated and ensures your collaborator's service has immediate access to any changes to your IdP settings. Your collaborator's external key service can easily access your IdP settings. Requires changing DNS settings for your server, outside of the Admin console. well-known file.ĬSE availability corresponds to the general availability of Google Workspace services. Only a Google Workspace Super Admin can manage your IdP setup.ĬSE availability (uptime) depends on availability of the server that hosts your. IdP settings are stored on Google servers.Īn IdP admin can manage your setup instead of a Google Workspace Super Admin.

IdP settings are stored on your own server. There are several considerations for each method, as described in the table below. well-known file that you host on your organization's website or the Admin console (which is your IdP fallback). You can set up your IdP-either a third party IdP or Google identity-using either a. Use Google identity-If your security model doesn't require additional isolation of your encrypted data from Google, you can use the default Google identity as your IdP.Ĭhoose how to connect to your IdP for CSE.Learn more about using SAML-based SSO with Google Workspace. Already use a third-party IdP for SAML-based Single-Sign-On (SSO)? It's recommended that you use the same IdP for CSE that you use for access to Google Workspace services.
