Skip to main content

AD_4nXdmpgOXsvaz1wiShY0ycNZw5ij-LBt5nl3RmOTT9oFJLC2tJizU4rLU7XYccb2Mrck9lUTXWlwb8YGO3xMCn_TL9I1wU16v0DeIMmYvpyICTv_vbrCsMtrOQYsxcqPh701M7ETvAg?key=Yg0bIKlRDyoGqa2629dnzTIX

Netskope Global Technical Success (GTS)

Netskope Admin SSO - Google IDP Integration

Netskope Cloud Version - 124

 

Objective

This document provides step-by-step instructions to configure SSO with Google IDP for Netskope Admin accounts, enabling seamless authentication and role-based access.

 

Prerequisite

Google Workspace Admin Access – Required to configure SAML in Google Admin Console.

Netskope Admin Access – Required to enable SSO in the Netskope tenant.

 

Configuration

Step 1 - Create Custom User Attributes in Google Workspace

  1. Log in to Google Admin Console
  2. Navigate to Directory > Users > Manage Custom Attributes.

AD_4nXcdvKlGBUoeg-XY6NTS3wdSFESjK5HKAyqNUA8oClp6Xnaoc75mOuKU0bqkQ90zFuks7Tnb2Kmxj1JkNzEgLVd3Q8utWXGgLejQudwPcQvl9thD18gQnVVjyaE_4dKoCaUrT-79rw?key=Yg0bIKlRDyoGqa2629dnzTIX

 

  1. Click Add Custom Attribute and configure the following:

Category Name: Netskope Attributes

Attribute Name: admin-role

Data Type: Text

Visibility: Visible to user and admin , Single-Value

 

AD_4nXfLcz1FZ2nRSM3Ig6x6oQ-DOskpYUFY7wINS82HO5RfNanBqgi1XKYQLwjuB22Y9HrSU5lCicRvkf6a1WPfIJadM3pZ1FXt0LCNkYh3L7tw-RMg7HkaRDC09PD6ofHH-CILnwZqkA?key=Yg0bIKlRDyoGqa2629dnzTIX


 

AD_4nXf4qIx4_8CDJTXThP5dIvZLDYdhM-x-eiR2XhIG0xwLRXoQI31xcjFc2XRLbQwHeE2qBXEtp2eO0tAmreSDTgJ_hQ-yPnSZWCBp7xQRSjnDzDsKkz7QqCGeO0kEnGMewVCBCol-?key=Yg0bIKlRDyoGqa2629dnzTIX

  1. Click Save

 

Step 2: Assign SSO Role Value to Users

  1. In Google Admin Console, go to Directory > Users.
  2. Select the user who needs Netskope Admin Access.
  3. Click User Information > Custom Attributes (Netskope Attributes).

AD_4nXfOOn8NI2LC47J3BVzoJuzDkWEj9GCY0qzAWlBXuR5W96D4MISg_LYp-X1g56iu-RbVfBCRPv32ZRSb9HRGavmUSnRL-n47CXeR3QRUIezHqQkoC0-z36EnDM4lq4WWtWJXl91N?key=Yg0bIKlRDyoGqa2629dnzTIX

 

  1. Assign the admin-role value, such as:

Tenant Admin

Delegated Admin

AD_4nXeCH8cwgnZaoA-p-VmoSctoRoEWEszwiL00c8u7S1E40otiSAOkdZxNancfB2fbZ-yuy0mchj6XZBGfMNWSWkl2wDtKHdHTGvVVISlLuW5eUOhH7ROHfkY-oPT6s_XsjY-bzLxfTw?key=Yg0bIKlRDyoGqa2629dnzTIX

AD_4nXd3gF31P48fMWJd30e9Mr2n5zLo_EQNWaYyO8ke4bGrzPrMNMcbEIuhhT-lCR1lOhjJUs96ysVUHKhFSiUDKEpzQtHERbMxtnwfOb_NLvOsgOKQjluF5znuxgQGSq4rziTmsQLc_w?key=Yg0bIKlRDyoGqa2629dnzTIX

  1. Click Save.

 

Step 3: Create the SAML Web App in Google Workspace

  1. Go to Google Admin Console > Apps > Web and mobile apps.
  2. Click Add App > Add custom SAML app.

AD_4nXcE_iWIrEtz1WxJC63zOHf6mHf9wVavyLi_fcnWBxGRN6Mjyh_2uZYUPfG7qrCI_JzdHAiqh7HNPFNHWdmJjifXdH4Fv3uof58tsZPZ_VTyaPioyhzWYdy6u1fEZ7nSmg?key=Yg0bIKlRDyoGqa2629dnzTIX

 

  1. Enter an App Name (e.g., "Netskope Tenant SSO") and an optional logo.

AD_4nXf6MJzjjSJaRa21jaAXBDWoZfXrzkgO7Welnd8ZwK_zZWwawAoxISLcJDTkWGnof3iTp2LOCg6uszzNXDgyTFnh89EYEcTasd2Crd6x9xOJCOWi64wRAsuqGpZwS7wfjFpxlVIX?key=Yg0bIKlRDyoGqa2629dnzTIX

 

  1. Click Continue.
  2. Copy the SSO URL, entity ID, and download the certificate

AD_4nXeAkNJsLuutWw7lRCdThb9J3rU6VxqGnnMr26_bK9-3ZFXeiNC2l3wq1S_sj1nAvd-pA3RwLTI5kpm0e9a7nQ5foIoD8TXTCGvsKYusah4icF1_kVKRv4L8Cl1TxSYrJSl9Af0BzQ?key=Yg0bIKlRDyoGqa2629dnzTIX

 

6.We have to get the ACS URL and Entity ID from Netskope SSO settings and select the Name ID Format and Name ID as shown below.

AD_4nXf5tawb7-xousvmmNflVzjHf_aTgVE6EH0zodFgZS6gsJS25UBmne9trDkHhM5QdOZ3UfYa9ZTbjOPjtb1ztQYTdTfM9cNjL3QAUD0ETFlLRrPKmKzwzQapGc_-SB9M12Fl1haZVA?key=Yg0bIKlRDyoGqa2629dnzTIX

 

7. Open a new browser tab and log in to the Netskope Console. ( Do not close the Google IDP configuration page, as we need to retrieve the ACS URL and Entity ID from Netskope)

 

Step 4: Configure Netskope WebUI SSO

  1. Log in to Netskope Admin Console.
  2. Path: Netskope Tenant UI >>> Settings >>> Administration >>> SSO
  3. Configure a New SSO Account as shown below

(The IDP SSO URL, Entity ID, and IDP Certificate were copied and downloaded from Step 3, Point 5.)

AD_4nXeSxyi9XCuz85_0aYQs-j39ZqhSvfv3KzvzVLiy4V4JjNFqvGGt-krLXPtFEMjCh3a6mJ8IYZtIEfXatcmswmjT4bN8RnNh3HJISWxFCY0rBfRkvRKyaKtSySIxicg876NYnwX7RQ?key=Yg0bIKlRDyoGqa2629dnzTIX

 

  1. After saving the configuration, you will receive the Entity ID and ACS URL. Make sure to save them, as they are required for the IDP configuration.

AD_4nXdEOLgNCoaj19_-l34w6_ORcYUwedyCESmdNnGXjEgW-SoV7yEkxwJDUTI6-r49__tFZQG2WrggPiK2eSGnfDxqkHUhF-O_FzEjN1n5sAuKhQIZIxBxLYQYDKXGk38p3ylWI-vZHA?key=Yg0bIKlRDyoGqa2629dnzTIX

AD_4nXdd5jOA4pk_3Y3M3UCPUuPXrqQuJ6Iw9sBpO8oRB9pj8WnscviEyWnatg3tXsbjNM8YXoWax0pVIvMjaMHQZKvNd7CpVcVpctReWroJ2jMnqgl9sK2xaIjsGpEXkpImJe-tOH-B0w?key=Yg0bIKlRDyoGqa2629dnzTIX

 

Step 5: Resume the IDP configuration that was paused at Step 3, Point 7.

  1. Add the ACS URL and Entity ID copied from Netskope, then click Continue.

AD_4nXfvUo0TVLg2guGFG1bwGg3lQr8UHSQzS4gDRaO7F5hPT4l7vrD-dc1tboteFSu4UVElkw8KSB-yTMnjr--LxNue_q0T6VLeFl0Nc0beJd4YDpAaaqOH6CK0Kw6tkDADWzjEZNeJ7w?key=Yg0bIKlRDyoGqa2629dnzTIX

 

  1. Click on Add Mapping and configure the values as shown below, then click the Finish button.

AD_4nXckOPoyKYOXouDwGzMFDMDh9ixVFa23_VbyCtnsPeq6-aPUrwypIIICakt1hw87Gmpi53oGR-DcLKa1N3fHmaGgj5PvYB94hBTG7Qe_yQlv1cxApS3lpa44Zi-kYjyG418bGcfjcA?key=Yg0bIKlRDyoGqa2629dnzTIX

 

  1. Enable the Service

AD_4nXcmGHZrrRz9sSSPBxFMjCv33LqzqFSfXDjwBY104z0r6MzI0za7dd4qhtecsJbJlZMUJ4lenLZx-MK-70MLPNLTHTLKUOHQcHMCwgIzuyPESH3Yqx_b7640oyF9r5ppwjHfT7-BPw?key=Yg0bIKlRDyoGqa2629dnzTIX

 

Verification

Audit Logs:

AD_4nXdrNuWQ0vjr-daPIHEN67zVM4jV7xQkhTuhrljnD1rlB0Z1cfcC-UgYR_INrv0_4hIClJnX_VjOGuiohB4ISOvzYd1p_8l01o_YpVWlE_nA8I5RvblK-9bGEJU0v5id6R7q0cAT?key=Yg0bIKlRDyoGqa2629dnzTIX

 

Admin page:

AD_4nXdyM7NNpNu3HL6pUFAgHizUYbpQkZ66AUXJTyJWdEYP07EbAv2T3YSDvd5uaPSqikPa2zpuQDpI_7yOeCZCYH2D82EpgKGubndh4lxsYR1FXe493VijPcVUoK-YNn1-DMbiCYmIcw?key=Yg0bIKlRDyoGqa2629dnzTIX

 

Terms and Conditions

  • All documented information undergoes testing and verification to ensure accuracy.
  • In the future, it is possible that the application's functionality may be altered by the vendor. If any such changes are brought to our attention, we will promptly update the documentation to reflect them.

 

Notes

  • This article is authored by Netskope Global Technical Success (GTS).
  • For any further inquiries related to this article, please contact Netskope GTS by submitting a support case with 'Case Type – How To Questions'.

 

Be the first to reply!