<@UF9FNKG1G> <https://support.google.com/a/answer/...
# administration
s
c
Yup exactly so step 3 part 5 where it says mapping to primary email, we seem to have run into an issue with that step
@Sam-I-Am
@Sam-I-Am based on digging around it seems to potentially be a domain setup thing? But we do not do ecommerce through netsuite so not sure what will enable google to tie into netsuite. All netsuite setup is complete other than domain or something outside the steps outlined in this google document
s
did you provided the assertion URL, metadata xml with x.509 cert in netsuite setup? check this document out https://docs.oracle.com/cloud/latest/netsuitecs_gs/NSISS/NSISS.pdf
c
@Sam-I-Am i am not sure about the assertion URL, we did the metadata file import form gsuite admin to netsuite for usre
i do not see anything with the word "assertion" in that document
s
SAML = Security Assertion Markup Language
try this SAML tool from Onelogin to determine your setting and validate them. https://www.samltool.com/online_tools.php
c
download the free trial to operate correct?
also does SAML SSO for google work in sandbox too or ONLY production? In a past life I had a ton of trouble with SAML OKTA integration in sandbox, worked in production though @Sam-I-Am
thanks for all the help
s
it should work for sandbox, since prod and sandbox are on the same domain now and use the same assertion url and x.509 certificate. Note that by default sandbox access is limited to admin you need to reset the access for the users otherwise login will fail.
c
cool ill let you know how it goes thanks
so it said my XML metadata is valid @Sam-I-Am
thats the one currently loaded in our sandbox instance
is there domain registration/authentication or is that the SAML response section?
also what do you mean I need to reset access, like recheck give access on the employee record post SAML connection?
s
yes
c
ok cool thanks