Users with the Manage District Settings user permission can set up a SAML integration with Google. This integration creates user accounts as users log in for the first time.
This is a three-step process:
- In Google, add a new SAML application.
- In Facilities Schedules, configure SAML.
- In Facilities Schedules, set default roles for users who login via Google SAML.
| Important: Because of the technical knowledge required, your district's IT administrator will most likely need to perform this procedure. |
Step 1: In Google, add a new SAML application.
A few things to take note of while setting up the SAML application:
- Fields are case sensitive.
-
You will need the Entity ID (which matches the ACS URL), Google Issuer URL, and certificate information to enter into Facilities Schedules.
Note: Enter https://XXXXX.mlschedules.com/MLSAMLConnect.aspx in the Entity ID and ACS URL fields. Replace “XXXXX” with your custom Schedules subdomain. - From the Name ID format field, select PERSISTENT.
- From the Name ID, select Basic Information > Primary email.
-
In SAML Attribute mapping, Google Directory attributes section, you need to match the text exactly as follows:
- Basic Information
- Primary email -> Email
- Basic Information
- First name -> FirstName
- Basic information
- Last name -> LastName
- Basic Information
- In Attribute mapping, under Group membership, it is required to put Group in the App attribute field and enter names of the Google groups that can log in via SAML in the Google groups section.
| Note: Google’s interface and field names may have changed since this was written. Use these steps as a general guide, and select the closest matching options in your Google portal. |
Step 2: In Facilities Schedules, configure SAML
| Note: A user with the Google super administrator role is required to perform this task. |
-
In Facilities Schedules, select Admin > Single Sign On > SAML Configuration. The SAML Integration Admin page appears.
-
Next to Google, click
. A pop-up appears.
- Do the following:
-
Under Issuer, enter your Google issuer URL.
Note: You can copy the issuer URL from Google Admin Console. In Service Provider Details, click Manage Certificates, copy the Entity ID field and paste it here. -
To let users sign in with Google option on the Schedules login page, enter the Login Link.
Note: To obtain this, click the Google apps icon ( ). Right-click the SAML app for Schedules, click Copy Link Address, and then paste the link.
-
Under Certificate, enter the certificate.
Notes:
- You download this from Google, then enter it here.
- On the certificate, remove ---Begin Certificate and ---End Certificate.
-
- From the Classification for User Groups drop-down, select the applicable group.
- Click Save.
Step 3: In Schedules, set default roles for users who login via Google SAML.
|
Notes:
|
- Select Admin > Single Sign On > SAML Group Settings. The Manage SAML Groups page appears.
-
Click +Add SAML Group. A pop-up appears.
- Do any of the following:
-
Enter a Group Name.
Note: This will be the group name established in Google. - Select the desired Roles.
-
Select the desired Sites.
Note: To select All Sites, select the checkbox.
-
- Click Save.
- Repeat steps 2-4 for each group you want to add.
Comments
0 comments
Please sign in to leave a comment.