Forum Discussion
Question about SSO
- Jan 08, 2019
Hi Mike! According to documentation for configuring SSO with Azure AD and G Suite, you can only have one identity provider for the tenant. Based on this, it sounds like all of your domains will either have to use Azure AD or all use Google as the IDP.
Q: Can I enable single sign-on for only a subset of my G Suite users?
A: No, turning on single sign-on immediately requires all your G Suite users to authenticate with their Azure AD credentials. Because G Suite doesn't support having multiple identity providers, the identity provider for your G Suite environment can either be Azure AD or Google -- but not both at the same time.
Reference: https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial
Hi Mike! According to documentation for configuring SSO with Azure AD and G Suite, you can only have one identity provider for the tenant. Based on this, it sounds like all of your domains will either have to use Azure AD or all use Google as the IDP.
Q: Can I enable single sign-on for only a subset of my G Suite users?
A: No, turning on single sign-on immediately requires all your G Suite users to authenticate with their Azure AD credentials. Because G Suite doesn't support having multiple identity providers, the identity provider for your G Suite environment can either be Azure AD or Google -- but not both at the same time.
Reference: https://docs.microsoft.com/en-us/azure/active-directory/saas-apps/google-apps-tutorial
Just for clarification:
- Azure AD supports multiple IDPs, one per domain
- G Suite supports only one IDP