<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need advice - how to set up Google sign-on to use Microsoft IdP and MFA from MS? in Peer-Peer Topics</title>
    <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Need-advice-how-to-set-up-Google-sign-on-to-use-Microsoft-IdP/m-p/583#M305</link>
    <description>&lt;P&gt;We have our staff using the MS IdP and we have another one setup to use login cards (ours are thorough ClassLink). I am by no means an expert but have worked though moving a few of our apps to using SSO with Microsoft Azure.&lt;/P&gt;&lt;P&gt;We have MS set as the SSO profile for the organization and then have a second one setup for ClassLink. We apply the MS profile to a group and then the ClassLink one to another group.&lt;/P&gt;&lt;P&gt;When a users that has a profile configured logs into a chromebook it will push them to the login workflow that is configured for them. Those users will see this whenever they login to their Google account.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that error you are seeing is saying that it isn't matching the user from Google to Azure / MS.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;See what attributes and claims are set on the enterprise app single sign-on screen in Azure. In particular check to see what field holds the email address for your users in azure. We have this (user.userprincipalname) set as the unique user identifier. I believe this is what needs to match the email on the google side.&lt;/LI&gt;&lt;LI&gt;Confirm the URLS are set correctly on the profile in Google&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
    <pubDate>Fri, 11 Aug 2023 20:31:22 GMT</pubDate>
    <dc:creator>slvandewalle_gb</dc:creator>
    <dc:date>2023-08-11T20:31:22Z</dc:date>
    <item>
      <title>Need advice - how to set up Google sign-on to use Microsoft IdP and MFA from MS?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Need-advice-how-to-set-up-Google-sign-on-to-use-Microsoft-IdP/m-p/580#M304</link>
      <description>&lt;P&gt;Does anyone have any guides or instructions on how to set this up properly?&amp;nbsp; We have Clever SAML set up for our K-2 students that use the badge reader option to sign into Google.&amp;nbsp; All the instructions I can find for setting up Google to use MS as a login are not additional profiles, but the master profile, and perhaps that's my hang-up?&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have MFA turned on for select users right now as we want to move to MS and get MFA working there as the primary MFA source.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I set up an IdP profile in Google, and tie it to the Enterprise App in Azure - my test user gets the error AADSTS700016 - that my identifier was not found in my company.&amp;nbsp; The value it gives me on that screen doesn't match any settings in Google or Microsoft that I've set up - so I'm not sure where that value exists or how to correct it, or what value to correct it with.&lt;/P&gt;&lt;P&gt;So I'm looking for anyone who already has this set up and working to pick your brain and possibly share details for others who might be interested in getting this going for their district as well.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The guide I was following from MS was this one:&amp;nbsp;&lt;A href="https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial" target="_blank" rel="noopener"&gt;https://learn.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial&lt;/A&gt;&lt;/P&gt;&lt;P&gt;That guide does not mention the error value I'm getting when I try to sign in with my test account.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Secondary to this topic - will this work for Macs and Chromebooks, or only domain-joined PCs?&amp;nbsp; I seem to get an error on a Mac that it's not a domain joined PC when I access the test login screen.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 18:11:01 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Need-advice-how-to-set-up-Google-sign-on-to-use-Microsoft-IdP/m-p/580#M304</guid>
      <dc:creator>Tank</dc:creator>
      <dc:date>2023-08-11T18:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Need advice - how to set up Google sign-on to use Microsoft IdP and MFA from MS?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Need-advice-how-to-set-up-Google-sign-on-to-use-Microsoft-IdP/m-p/583#M305</link>
      <description>&lt;P&gt;We have our staff using the MS IdP and we have another one setup to use login cards (ours are thorough ClassLink). I am by no means an expert but have worked though moving a few of our apps to using SSO with Microsoft Azure.&lt;/P&gt;&lt;P&gt;We have MS set as the SSO profile for the organization and then have a second one setup for ClassLink. We apply the MS profile to a group and then the ClassLink one to another group.&lt;/P&gt;&lt;P&gt;When a users that has a profile configured logs into a chromebook it will push them to the login workflow that is configured for them. Those users will see this whenever they login to their Google account.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I think that error you are seeing is saying that it isn't matching the user from Google to Azure / MS.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;See what attributes and claims are set on the enterprise app single sign-on screen in Azure. In particular check to see what field holds the email address for your users in azure. We have this (user.userprincipalname) set as the unique user identifier. I believe this is what needs to match the email on the google side.&lt;/LI&gt;&lt;LI&gt;Confirm the URLS are set correctly on the profile in Google&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Fri, 11 Aug 2023 20:31:22 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Need-advice-how-to-set-up-Google-sign-on-to-use-Microsoft-IdP/m-p/583#M305</guid>
      <dc:creator>slvandewalle_gb</dc:creator>
      <dc:date>2023-08-11T20:31:22Z</dc:date>
    </item>
    <item>
      <title>Re: Need advice - how to set up Google sign-on to use Microsoft IdP and MFA from MS?</title>
      <link>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Need-advice-how-to-set-up-Google-sign-on-to-use-Microsoft-IdP/m-p/587#M306</link>
      <description>&lt;P&gt;Yes the defaults came with user.userprincipalname as the unique identifier.&amp;nbsp; I haven't had to change that - mail is set to user.mail which I presume should be accurate too.&amp;nbsp; I'm sure the UID is the big one for users to match between systems and I suspect that should be correct.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My URLs in the google SSO IDP area is set to the MS defaults per the learn article and it hasn't said to use the Entity ID page at all on Google.&amp;nbsp; I've made that change - but since I am on a Mac, I still get the "Sign-in failed" page with error "AADSTS9001011" since my Mac is not domain joined - is that some setting I have incorrect that's requiring domain joined devices - as our macs and chromebooks are not domain joined at all.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ARGH - conditional access was set up for domain only machines.&amp;nbsp; I temp disabled that for testing - but it still presents the error - assuming this is a Microsoft 48 hour wait ordeal.&amp;nbsp; Will respond back if it's still an issue after 2 days.&amp;nbsp; #ThanksMicrosoft&lt;/P&gt;</description>
      <pubDate>Sun, 13 Aug 2023 16:56:18 GMT</pubDate>
      <guid>https://www.googleforeducommunity.com/t5/Peer-Peer-Topics/Need-advice-how-to-set-up-Google-sign-on-to-use-Microsoft-IdP/m-p/587#M306</guid>
      <dc:creator>Tank</dc:creator>
      <dc:date>2023-08-13T16:56:18Z</dc:date>
    </item>
  </channel>
</rss>

