> Source: [sk136993](https://support.checkpoint.com/results/sk/sk136993)

# sk136993 - Configure G Suite and Okta with CloudGuard SaaS Authentication Service

| Property | Value |
|----------|-------|
| Solution ID | sk136993 |
| Date Created | 2018-09-27 |
| Last Modified | 2019-07-08 |
| Technical Level | General |
| Products | Email Security |
| Versions | Cloud |

## Solution

This page describes how to configure CloudGuard SaaS to work with Okta as an Identity Provider and G Suite as Service Provider. After the configuration is finished, all login requests to G Suite will go through CloudGuard SaaS Authentication Service.

**Table of Contents:**

* Prerequisites
* Steps
  * Add and Configure Okta as an Identity Provider
  * Configure G Suite to use CloudGuard SaaS Authentication Service as Identity Provider

**Important Notes**

**#1 -** This procedure will impact **all G Suite users** in your domain; it cannot be done only for specific user groups.

**#2 -** The change of Identity Provider in G Suite takes effect **immediately**.

**#3** - Besides the configuration described in this article, you need to **associate G Suite** to CloudGuard SaaS in order to **synchronize your users** . This is done under Identity Protection\\Configuration\\SaaS Applications. Please consult the [Identity Protection Admin Guide](https://sc1.checkpoint.com/documents/CloudGuard_SaaS_IdentityProtection/html_frameset.htm), section *Getting Started - Initial Configuration*, for more details.

Prerequisites {#Prerequisites}
------------------------------

Administrator privileges to Okta and G Suite are required for the following procedure.

Steps
-----

### Add and Configure Okta as an Identity Provider {#Okta}

1. Log into CloudGuard SaaS portal and go to Configuration under the module Identity Protection. Under the tab Identity Providers, click on Add Identity Provider.
2. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Add IDP_CGS portal1809040728.png)
3. In the wizard that opens, select Okta and click Next.
4. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Add IDP_Wizard1_Okta1809040729.PNG)
5. Enter your domain name and click Next.
6. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Add IDP_Wizard2_Okta1809040739.PNG)
7. Copy the Entity ID and the Reply URL to a text file and save them for later. Click Next.
8. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Add IDP_Wizard3_Okta1809040740.PNG)
9. Log in to your Okta organization as an administrator. Under Applications, click Add Applications and Create New App.
10. In the dialog that opens, select the SAML 2.0 option and click Create.
11. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/OktaSP11808130510.png)
12. In Section 1, General Settings, enter 'CloudGuard SaaS - Authentication Service' in the App name field. Click Next.
13. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/OktaSP21808130513.png)
14. In Section 2 'Configure SAML', Part A 'SAML Settings', fill in the Single sign on URL and Audience URI (SP Entity ID) fields respectively with the Reply URL and the Entity ID URL copied in step 4 from the CloudGuard SaaS portal.
15. For Name ID format, select Persistent.
16. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/OktaSAMLSettings General18081305231907070930.png)
17. 
18. In the Attribute Statements section, add the following attribute statement (in format URI reference).
19. Name: **/claims/emailaddress**
20. Value: **user.email**
21. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/Okta_AttributeStatements21809270741.png)
22. Finally, select 'I am an Okta customer adding an internal app' and 'This is an internal app that we have created'. Click Finish.
23. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Okta_finish1808140856.PNG)
24. Download Identity Provider metadata. Right click on the blue link 'Identity Provider metadata' and choose Save link as. Add the extension .xml to the file name before saving.
25. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Okta_metadata1808140900.png)
26. In CloudGuard SaaS portal, upload the metadata xml file in the Add Identity provider Wizard. Click Next.
27. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Add IDP_Wizard4_Okta1809040805.PNG)
28. Assign the newly created app to all G Suite users in Okta. Then, click the Connect button in the Add Identity Provider wizard. This will open an Okta login form where you are prompted to enter your email address and password. After validation, you should see a Login Success message.
29. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Add IDP_Wizard5_Okta1809040806.PNG)
30. 

### Configure G Suite to use CloudGuard SaaS Authentication Service as Identity Provider

1. In the CloudGuard SaaS portal, navigate to Configuration under Identity Protection. In the box corresponding to the Okta Identity Provider you just configured, click on Click to add SaaS.
2. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk134192/Okta_addSaaS1809040748.PNG)
3. In the wizard that opens, select G Suite and click Next.
4. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/Add SaaS _ GSuite1809270753.PNG)
5. Entity ID and Reply URL are pre-filled. Click Next.
6. Copy and paste the Sign-in page URL and the Sign-out page URL to a text file and save for later. Download the certificate and click Finish to save and close the wizard.
7. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/Add SaaS_cert_GSuite1809270756.png)
8. Log into the G Suite admin console. Click on Security.
9. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/G Suite admin1810012345.png)
10. Scroll down to section 'Set up single sign on (SSO)' and expand it.
11. Check the boxes 'Setup SSO with third party identity provider' and 'Use a domain specific issuer'.
12. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/GSuite_config_checkboxes1810030319.png)
13. Upload the certificate downloaded in step 4 from the CloudGuard SaaS portal.
14. We recommend doing this before filling out the Sign-in page and Sign-out page URLs due to a randomly observed Google behavior that clears out the URLs after uploading the certificate.
15. Fill out the Sign-in page URL and Sign-out page URL with the URLs provided by the Add Service Provider wizard in step 4.
16. You can leave empty the Change password URL. Click Save.
17. You're done! All login requests to G Suite will now go through CloudGuard SaaS Authentication Service before reaching Okta. Login events will be shown in the CloudGuard SaaS portal under Identity Protection\\Events.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
