SugarCRM cloud-app

Met de SAML 2.0-standaard kunt u single sign-on (SSO) configureren voor een aantal cloud-apps. Nadat u SSO hebt ingesteld, kunnen uw gebruikers hun Google Workspace-gegevens gebruiken om zich via SSO aan te melden bij een app.

Gebruik SAML om SSO voor SugarCRM in te stellen.

Step 1: Set up Google as a SAML identity provider

  1. Ga in de Google Admin-console naar Menu. en dan Apps en dan Web- en mobiele apps .

    Voor deze taak moet u zijn aangemeld als superbeheerder .

  2. Klik op 'App toevoegen'. en dan Zoek naar apps .
  3. Voer bij 'Appnaam invoeren ' 'Sugar' in.
  4. In the search results, point to Sugar and click Select .
  5. In the Google Identity Provider details window, for Option 2: Copy the SSO URL, entity ID, and certificate :
    1. Klik naast SSO-URL op Kopiëren en sla de URL op.
    2. Klik naast SHA-256-vingerafdruk op Kopiëren. en sla de vingerafdruk op.
      You need these details to complete the setup in SugarCRM.
  6. Klik op Doorgaan .
  7. On the Service provider details page, for ACS URL and Start URL , replace {your-sugar-domain} with your SugarCRM domain.
  8. Klik op Doorgaan .
  9. (Optional) To map Google directory attributes to the corresponding app attributes, in the Attribute Mapping window:
    1. Klik op Kaart toevoegen.
    2. Klik op Veld selecteren en dan Selecteer een kenmerk van de Google-directory.
    3. For App attributes , enter the corresponding app attribute.
  10. (Optional) To enter group names that are relevant for this app:
    1. For Group membership (optional) , click Search for a group , enter one or more letters of the group name, and select the group name.
    2. Add additional groups as needed (maximum of 75 groups).
    3. For App attribute , enter the corresponding groups attribute name of the service provider.

    Ongeacht hoeveel groepsnamen u invoert, het SAML-antwoord bevat alleen groepen waarvan een gebruiker (direct of indirect) lid is. Ga voor meer informatie naar 'Over het toewijzen van groepslidmaatschap' .

  11. Klik op Voltooien .

Step 2: Set up SugarCRM as a SAML 2.0 service provider

  1. Open an Incognito browser window, go to the SugarCRM sign-in page , and sign in with your SugarCRM administrator account.
  2. Selecteer het SugarCRM-beheerdersaccount.
  3. Ga naar Beheerder en dan Wachtwoordbeheer en dan SAML-authenticatie .
  4. Vink het vakje 'SAML-authenticatie inschakelen' aan.
  5. For Login URL , paste the SSO URL that you copied in Step 1.
  6. For X509 Certificate , paste the SHA-256 fingerprint that you copied in Step 1.
  7. Klik op Opslaan .

Stap 3: Schakel de app in voor gebruikers.

Voordat u begint: Om een ​​service voor bepaalde gebruikers in of uit te schakelen, plaatst u hun accounts in een organisatie-eenheid (om de toegang per afdeling te beheren) of voegt u ze toe aan een toegangsgroep (om toegang te verlenen aan gebruikers binnen of tussen afdelingen).
  1. Ga in de Google Admin-console naar Menu. en dan Apps en dan Web- en mobiele apps .

    Voor deze taak moet u zijn aangemeld als superbeheerder .

  2. Klik op Suiker .
  3. Klik op Gebruikerstoegang .
  4. To turn a service on or off for everyone in your organization, click On for everyone or Off for everyone , and then click Save .

  5. (Optional) To turn a service on or off for an organizational unit:
    1. Selecteer aan de linkerkant de organisatie-eenheid.
    2. Om de servicestatus te wijzigen, selecteert u Aan of Uit .
    3. Kies er één:
      • If the Service status is set to Inherited and you want to keep the updated setting, even if the parent setting changes, click Override .
      • If the Service status is set to Overridden , either click Inherit to revert to the same setting as its parent, or click Save to keep the new setting, even if the parent setting changes.

        Leer meer over organisatiestructuur .

  6. (Optional) To turn on a service for a set of users across or within organizational units, select an access group. For details, go to Customize service access using access groups .
  7. Ensure that your SugarCRM user account email domains match the primary domain of your organization's managed Google Account.

Stap 4: Controleer of SSO werkt

SugarCRM supports both identity provider-initiated and service provider-initiated SSO.

Verifieer de door de identiteitsprovider geïnitieerde SSO.

  1. Ga in de Google Admin-console naar Menu. en dan Apps en dan Web- en mobiele apps .

    Voor deze taak moet u zijn aangemeld als superbeheerder .

  2. Klik op Suiker .
  3. Klik in het gedeelte Sugar op Test SAML Login .

    The app should open in a separate tab. If it doesn't, troubleshoot the error message and try again. For details on troubleshooting, go to SAML app error messages .

Controleer of de serviceprovider SSO heeft geïnitieerd.

  1. Sluit alle browservensters.
  2. Go to https://{your-domain-name}.my.sugarCRM.com , replace {your-domain-name} with your SugarCRM domain, and sign in with your SugarCRM administrator account.
    You should be redirected to the Google sign-in page.
  3. Selecteer je account en voer je wachtwoord in.

After your credentials are authenticated, the app should open.

Stap 5: Gebruikersprovisionering instellen

As a super administrator, you can automatically provision users in the app. For details, go to Configure SugarCRM user provisioning .


Google, Google Workspace en aanverwante merken en logo's zijn handelsmerken van Google LLC. Alle andere bedrijfs- en productnamen zijn handelsmerken van de bedrijven waaraan ze zijn verbonden.