Prerequisites
Before you begin configuring Google, make sure that:
- You have a valid subscription with Google Workspace that handles the sign-in process and eventually provides the authentication credentials to the Cloud App Security management console.
- You are logged on to the management console as a Cloud App Security global administrator. For details, see Administrator and Role.
Setting up SSO using Google Workspace
- Login to Google Workspace Admin Console.
- Under the Admin console, navigate to Menu, select Apps, then Web and mobile apps.
- Click Add App, and select Add custom SAML app.
- Under the App Details page, enter the name of the custom app and click Continue.
- On the Google Identity Provider details page, under the Option 2 section, copy the value of the idpID from the SSO URL field, the Entity ID and Certificate to a notepad or text editor.
- Click Continue. This will be used to configure the Cloud App Security SSO.
- In the Service provider details, provide the following values:
- For the ACS URL, the value will be the Cloud App Security SSO URL based on the serving site used. Refer to the following table.
- For the Entity ID, the value will be the Cloud App Security URL based on the serving site used. Refer to the following table:
Serving Site URL EU https://admin-eu.tmcas.trendmicro.com UK https://admin.tmcas.trendmicro.co.uk Japan https://admin.tmcas.trendmicro.co.jp US https://admin.tmcas.trendmicro.com Australia and New Zealand https://admin-au.tmcas.trendmicro.com Canada https://admin-ca.tmcas.trendmicro.com Singapore https://admin.tmcas.trendmicro.com.sg India https://admin-in.tmcas.trendmicro.com - For the Name ID format, select EMAIL
- For the Name ID, select Basic Information > Primary email, then click Continue.
- For the ACS URL, the value will be the Cloud App Security SSO URL based on the serving site used. Refer to the following table.
- In the Attribute Mapping, leave it with the default value and click Finish.
- After the SAML application is created, get the Service Provider ID:
- Go to Menu, then Apps, and Web and mobile apps. Click the SAMP application created earlier to view the settings.
- In the next page, copy the Service Provider ID from the address bar of the browser and save it into a notepad or text editor. This information will be used in configuring Cloud App Security SSO.
- After the SAML application has been created, enable the service to all users by performing the following:
- Go to Meu, then Apps, select Web and mobile app. Click the SAML application created earlier to view the settings.
- In the next page, expand the User Access section to view the access settings.
- Under Service Status, select ON for Everyone and click Save.
Configure your Cloud App Security SSO
- Login to the Cloud App Security web console. Go to Administration and select Single Sign-On.
- Configure the general settings for single sign-on using the following information.
- Select Enable SSO
- Select Okta in Identify Provider
- In the Service URP, input the value as
- In the Application Identifier, input the value of the Entity ID from step XXXX
- In the SAML Signing Certificate, input the value of the certificate from step XXXX
- Click Save.
Adding an Administrator user with Google Workspace user account to Cloud App Security.
- Login to Cloud App Security web console. Go to Administration and select Administrator and Role.
- Under Administrator, click Add. The Administrator screen appears.
- Enter the Google Workspace email address of a user to add as administrator in the Email Address field.
- (Optional) Select the Allow the administrator to switch among Cloud App Security tenants of your organization from the management console.
- Specify a username in the Name filed.
- Turn on "SSO to Console".
- Select a role for the user to be added.
- Click Save.
Testing the CAS SSO Configuration.
- Access the CAS web console depending on the service site. Refer to the table below.
Serving Site URL EU https://admin-eu.tmcas.trendmicro.com UK https://admin.tmcas.trendmicro.co.uk Japan https://admin.tmcas.trendmicro.co.jp US https://admin.tmcas.trendmicro.com Australia and New Zealand https://admin-au.tmcas.trendmicro.com Canada https://admin-ca.tmcas.trendmicro.com Singapore https://admin.tmcas.trendmicro.com.sg India https://admin-in.tmcas.trendmicro.com - Enter the Google Workspace email address of the administrator previously added then press the tab key.
- The previous step should be redirected to the Google Account Sign-In page.
- Login using the Google Workspace email address of the administrator user previously added. This should log the user in to the Cloud App Security web console.