π€ Who can do this? You will need to be an admin user within Atlan to configure SSO. You will also need to work with your Google domain administrator to carry out the tasks below in the Google Admin Center.
To integrate Google SSO for Atlan, complete the following steps.
Choose SSO provider (in Atlan)
To choose Google as your SSO provider, within Atlan:
- From the left menu on any screen, navigate to Admin.
- Under the Workspace heading, click SSO.
- Under Choose SAML provider, select Google and then click Configure.
- Under Service provider metadata, copy the ACS URL and Entity ID.
Set up SAML app (in Google Admin Center)
To set up a SAML app, within Google Admin Center:
- From the menu on the left, expand Apps and then click on Web and mobile apps.
- At the top of the table, click the Add app link and then click Add custom SAML app.
- Enter a name for your app, such as Atlan and then click the Continue button.
- Under Option 1: Download IdP metadata click the Download metadata button, save the file, and then click the Continue button.
- Under Service provider details enter your Atlan SAML settings:
- For ACS URL enter the value you copied from Atlan above.
- For Entity ID enter the value you copied from Atlan above.
- Click the Continue button.
- Under Attributes define the following mappings from Google Directory attributes on the left to App attributes on the right:
- Primary email β> email
- First name β> firstName
- Last name β> lastName
- Below the form, click the Finish button.
Assign users to the app (in Google Admin Center)
To assign users to the app, within Google Admin Center:
- From the app page, expand User access.
- Under Service status change to ON for everyone and then click Save.
Upload Google's metadata file (in Atlan)
To complete the configuration of Google SSO, within Atlan:
- From the left menu on any screen, navigate to Admin.
- Under the Workspace heading, click SSO.
- Under Choose SAML provider, select Google and then click Configure.
- To the right of Identity provider metadata click the Import from XML button.
- Select the
GoogleIDPMetadata.xml
file downloaded from Google above. - At the bottom of the screen, click Save.
Congratulations β you have successfully set up Google SSO in Atlan! π
πͺ Did you know? By default, users can now log into Atlan with either Google SSO or a local Atlan account (via email). To only allow logins via SSO, enable the Enforce SSO option in Atlan. Once SSO is enforced, we recommend inviting users only through the SSO provider and not directly from Atlan.