Met de SAML 2.0-standaard kunt u single sign-on (SSO) configureren voor een aantal cloud-apps. Nadat u SSO hebt ingesteld, kunnen uw gebruikers hun Google Workspace-gegevens gebruiken om zich via SSO aan te melden bij een app.
Gebruik SAML om SSO voor SugarCRM in te stellen.
Step 1: Set up Google as a SAML identity provider
Ga in de Google Admin-console naar Menu.
Apps
Web- en mobiele apps .
Voor deze taak moet u zijn aangemeld als superbeheerder .
- Klik op 'App toevoegen'.
Zoek naar apps .
- Voer bij 'Appnaam invoeren ' 'Sugar' in.
- In the search results, point to Sugar and click Select .
- In the Google Identity Provider details window, for Option 2: Copy the SSO URL, entity ID, and certificate :
- Klik naast SSO-URL op Kopiëren
en sla de URL op.
- Klik naast SHA-256-vingerafdruk op Kopiëren.
en sla de vingerafdruk op.
You need these details to complete the setup in SugarCRM.
- Klik naast SSO-URL op Kopiëren
- Klik op Doorgaan .
- On the Service provider details page, for ACS URL and Start URL , replace {your-sugar-domain} with your SugarCRM domain.
- Klik op Doorgaan .
- (Optional) To map Google directory attributes to the corresponding app attributes, in the Attribute Mapping window:
- Klik op Kaart toevoegen.
- Klik op Veld selecteren
Selecteer een kenmerk van de Google-directory.
- For App attributes , enter the corresponding app attribute.
- (Optional) To enter group names that are relevant for this app:
- For Group membership (optional) , click Search for a group , enter one or more letters of the group name, and select the group name.
- Add additional groups as needed (maximum of 75 groups).
- For App attribute , enter the corresponding groups attribute name of the service provider.
Ongeacht hoeveel groepsnamen u invoert, het SAML-antwoord bevat alleen groepen waarvan een gebruiker (direct of indirect) lid is. Ga voor meer informatie naar 'Over het toewijzen van groepslidmaatschap' .
- Klik op Voltooien .
Step 2: Set up SugarCRM as a SAML 2.0 service provider
- Open an Incognito browser window, go to the SugarCRM sign-in page , and sign in with your SugarCRM administrator account.
- Selecteer het SugarCRM-beheerdersaccount.
- Ga naar Beheerder
Wachtwoordbeheer
SAML-authenticatie .
- Vink het vakje 'SAML-authenticatie inschakelen' aan.
- For Login URL , paste the SSO URL that you copied in Step 1.
- For X509 Certificate , paste the SHA-256 fingerprint that you copied in Step 1.
- Klik op Opslaan .
Stap 3: Schakel de app in voor gebruikers.
Ga in de Google Admin-console naar Menu.
Apps
Web- en mobiele apps .
Voor deze taak moet u zijn aangemeld als superbeheerder .
- Klik op Suiker .
- Klik op Gebruikerstoegang .
To turn a service on or off for everyone in your organization, click On for everyone or Off for everyone , and then click Save .
- (Optional) To turn a service on or off for an organizational unit:
- Selecteer aan de linkerkant de organisatie-eenheid.
- Om de servicestatus te wijzigen, selecteert u Aan of Uit .
- Kies er één:
- If the Service status is set to Inherited and you want to keep the updated setting, even if the parent setting changes, click Override .
- If the Service status is set to Overridden , either click Inherit to revert to the same setting as its parent, or click Save to keep the new setting, even if the parent setting changes.
Leer meer over organisatiestructuur .
- (Optional) To turn on a service for a set of users across or within organizational units, select an access group. For details, go to Customize service access using access groups .
- Ensure that your SugarCRM user account email domains match the primary domain of your organization's managed Google Account.
Stap 4: Controleer of SSO werkt
SugarCRM supports both identity provider-initiated and service provider-initiated SSO.
Verifieer de door de identiteitsprovider geïnitieerde SSO.
Ga in de Google Admin-console naar Menu.
Apps
Web- en mobiele apps .
Voor deze taak moet u zijn aangemeld als superbeheerder .
- Klik op Suiker .
- Klik in het gedeelte Sugar op Test SAML Login .
The app should open in a separate tab. If it doesn't, troubleshoot the error message and try again. For details on troubleshooting, go to SAML app error messages .
Controleer of de serviceprovider SSO heeft geïnitieerd.
- Sluit alle browservensters.
- Go to https://{your-domain-name}.my.sugarCRM.com , replace {your-domain-name} with your SugarCRM domain, and sign in with your SugarCRM administrator account.
You should be redirected to the Google sign-in page. - Selecteer je account en voer je wachtwoord in.
After your credentials are authenticated, the app should open.
Stap 5: Gebruikersprovisionering instellen
As a super administrator, you can automatically provision users in the app. For details, go to Configure SugarCRM user provisioning .
Google, Google Workspace en aanverwante merken en logo's zijn handelsmerken van Google LLC. Alle andere bedrijfs- en productnamen zijn handelsmerken van de bedrijven waaraan ze zijn verbonden.