Articles in this section

Google Workspace Single Sign-On via SAML

Using Security Assertion Markup Language (SAML), your users can use their Google Cloud credentials to sign into Dialpad.

Let's dive into the details.

Who can use this

Dialpad's Google Workspace SAML integration is available to all Dialpad users.

Refer to our to see if you have access to this feature. If you have questions about your plan, reach out to your Customer Success Manager or Dialpad Customer Care.

To configure this integration, you must be signed in to Google Workspace as a Super Admin.


Configure Google Workspace SSO SAML

First, you'll need to configure SSO with Google as SAML IdP.

From your Google Admin Portal:

  1. Select Security

  2. Select Authentication

  3. Select SSO with SAML applications

  4. Copy the SSO URL and Entity ID

    • You will need these details when configuring your Service Provider (SP)

      Screenshot of the Google Workspace Admin console under Security > Authentication > SSO with SAML applications, featuring an orange box highlighting the SSO URL and Entity ID fields within the Google Identity Provider details section.
  5. Select ADD CERTIFICATE

  6. Copy the certificate

    • You will need the certificate details when configuring your Service Provider (SP)
      Screenshot of the Google Workspace Admin console under SSO with SAML applications, featuring orange boxes highlighting the 'ADD CERTIFICATE' button at the bottom and an arrow pointing to the copy icon next to Certificate 1. 

Set up Dialpad as a SAML 2.0 Service Provider (SP)

Next, it's time to set up Dialpad as a SAML 2.0 Service Provider.

  1. Go to https://dialpad.com/authentication/saml

  2. Select Google from the list of providers

  3. Enter the SSO URL and Entity ID in the appropriate fields

  4. Paste the copied X.509 Certificate into the Certificate box

    • Remove “BEGIN” and “END CERTIFICATE”
      Screenshot of the Dialpad SAML Configuration page for Google, featuring orange boxes highlighting the populated 'IdP SSO Url', 'IdP Entity ID (Issuer)', and 'Certificate' text entry fields.

  5. Select Save

Set up Google Workspace as a SAML Identity Provider (IdP)

Now it's time to set up Google Workspace as a SAML Identity Provider.

From the Google Admin Portal:

  1. Select Apps

  2. Select Web and mobile apps

  3. Select the Add app, then Search for apps

    Screenshot of the Google Admin Console under Apps > Web and mobile apps, featuring orange boxes highlighting 'Web and mobile apps' in the left menu and the 'Add app' dropdown with 'Search for apps' selected.

  4. Enter Dialpad

  5. Select Dialpad Web (SAML)

    Screenshot of the Search apps page in the Google Admin Console featuring an orange box and arrow highlighting the 'Dialpad' app listed under the 'Web (SAML)' platform, pointing to its blue 'Select' button.
  6. Navigate to Option 2 and enter the SSO URL, Entity ID and Certificate saved from Step 1

  7. Select Continue

    Screenshot of the Dialpad Web (SAML) setup page in Google Admin showing an orange box around Option 2 with the SSO URL, Entity ID, and Certificate fields, and another orange box highlighting the blue 'CONTINUE' button in the bottom right corner.
  8. Enter the following Dialpad-specific provider details

    • ACS URL: https://dialpad.com/saml/sso/google/your-domain.com

    • Entity ID: https://dialpad.com/api/saml/metadata/google/your-domain.com

    • Start URL: https://dialpad.com

    • Leave the Signed Response box unchecked

      • When the Signed Response box is unchecked, only the assertion is signed

      • When the Signed Response box is checked, the entire response is signed

    • Set the NameID Format to Transient

    • Set the Name ID as the primary email

      Screenshot of the Dialpad Service Provider Details page in Google Admin showing fields populated for ACS URL, Entity ID, Start URL, Name ID format set to TRANSIENT, and Name ID set to Basic Information > Primary email, with a blue 'CONTINUE' button in the bottom right corner.
  9. Select Continue

  10. Navigate to Attribute Mapping

  11. In the Basic Information category:

    • Provide the "Primary Email" [Email], "First Name" [FirstName], and "Last Name" [LastName]

    • Select Finish

Screenshot of the Dialpad Attributes mapping page in Google Admin showing Google Directory attributes mapped to 'FirstName', 'LastName', and 'Email' app attributes, with a blue 'FINISH' button located in the bottom right corner.

Turn on SSO for Dialpad

Now it's time to turn on SSO for your Dialpad App.

From the Google Admin console:

  1. Navigate to Apps

  2. Select Web and mobile apps

  3. Select Dialpad

  4. Select User Access

    Screenshot of the Dialpad application details page in the Google Admin Console featuring orange boxes highlighting 'Web and mobile apps' in the left menu bar and the 'User access' panel displaying 'OFF for everyone'.
  5. Select an organizational unit

  6. Select On for everyone

  7. Select Save
    Screenshot of the Dialpad Service Status page in the Google Admin Console featuring orange boxes highlighting the Organizational Units panel on the left, the selected 'ON for everyone' radio button under Service status, and an arrow pointing to the 'SAVE' button.

This will activate the single sign-on for the selected organizational unit.

Verify SSO is working between Google Workspace and Dialpad

Now it's time to do a final check and verify that SSO works between Google Workspace and Dialpad.

  1. Open https://dialpad.com/saml/login/google/your-domain.com

  2. Enter your company domain, then select Next

    Screenshot of the Dialpad 'Login With Another Provider' screen featuring a 'Domain' input field with purple outline, alongside 'Cancel' and purple 'Next' buttons.

That's it! You'll be redirected to Google for authentication and then automatically redirected back to Dialpad.

Enforcing SAML-based SSO

Add an extra level of security by blocking your users from using other SSO providers when logging into Dialpad.

To restrict the use of other authentication providers, navigate to your Admin Settings at Dialpad.com

  1. Select My Company
    Screenshot of the Dialpad Admin portal featuring orange circles highlighting the gear settings icon on the left navigation bar and the dropdown menu item 'My company'.

  2. Navigate to Authentication

  3. Select SAML

  4. Select Prevent users from logging in with other SSO providers

  5. Select Save

    Screenshot of the Dialpad SAML Configuration page showing orange boxes highlighting the gear icon, the selected 'SAML' tab under Authentication, the checked 'Prevent users from logging in with other SSO providers' option, and an arrow pointing to the purple 'Save' button.

Note

Once changes were saved, your users won't be able to use Microsoft and Google SSO, (or even their username and password) to log in to Dialpad.

Was this article helpful?
0 out of 0 found this helpful

Comments

0 comments

Article is closed for comments.