> Source: [sk137853](https://support.checkpoint.com/results/sk/sk137853)

# sk137853 - How to configure G Suite and Microsoft Azure AD with CloudGuard SaaS Authentication Service

| Property | Value |
|----------|-------|
| Solution ID | sk137853 |
| Date Created | 2018-12-09 |
| Last Modified | 2019-04-17 |
| Technical Level | General |
| Products | Email Security |
| Versions | Cloud |

## Solution

This page describes how to configure CloudGuard SaaS to work with Microsoft Azure AD as an Identity Provider and G Suite as a Service Provider. After the configuration is finished, all login requests to G Suite will go through the CloudGuard SaaS Authentication Service.

**Table of Contents:**
----------------------

* Prerequisites
* Procedure
  * Add and configure Azure AD as an Identity Provider
  * Configure G Suite to use the CloudGuard SaaS Authentication Service as Identity Provider

**Important Notes**
-------------------

* This procedure will i**mpact all G Suite users** in your domain; it cannot be done only for specific user groups.
* The change of Identity Provider in G Suite takes effect **immediately**.
* Besides the configuration described in this article, you need to **associate G Suite** to CloudGuard SaaS in order to **synchronize your users** . This is done under Identity Protection\\Configuration\\SaaS Applications. Please consult the [Identity Protection Admin Guide](https://sc1.checkpoint.com/documents/CloudGuard_SaaS_IdentityProtection/html_frameset.htm), section *Getting Started - Initial Configuration*, for more details.

Prerequisites {#Prerequisites}
------------------------------

* Administrator privileges in Microsoft Azure AD and G Suite
* Premium subscription to Microsoft Azure AD

Procedure {#Steps}
------------------

### Add and Configure Azure AD as an Identity Provider {#AzureAD}

1. Log into CloudGuard SaaS portal and go to **Configuration** under the module**Identity Protection** . Under the tab **Identity Providers** , click on **Add Identity Provider**.
2. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk133692/Add IDP_CGS portal1809040508.png)
3. A wizard will open. Select **Microsoft Azure AD** and click **Next**.
4. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk137853/Add IDP_Wizard1_AzureAD1812090603.PNG)
5. Enter your domain name and click **Next**.
6. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk137853/Add IDP_Wizard2_AzureAD1812090603.PNG)
7. Copy the Entity ID and the Reply URL to a text file and save them for later. Click **Next**.
8. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk137853/Add IDP_Wizard3_AzureAD1812090604.PNG)
9. Log into the Microsoft Azure AD admin console (<https://portal.azure.com>). In the left pane, click on **Azure Active Directory**.
10. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD11812090742.png)
11. In the sub menu bar, click on **Enterprise Applications**.
12. Click on **New Application**.
13. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD21812090744.png)
14. Choose to create a **Non-gallery application** . Give a display name to your new application, for example 'CGS Authentication Service'. Click **Add**.
15. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD31812090745.png)
16. You will be redirected to the new Application dashboard. Navigate to the menu item **Single sign-on** and select **SAML** as the SSO method.
17. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD41812090746.png)
18. 
19. The SAML configuration page will now open. In section 1, Basic SAML Configuration, click the pencil icon to edit.
20. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk137853/AzureAD4_bis1812090638.png)
21. In Identifier and Reply URL, paste, respectively, the Entity ID and Reply URL copied from the CloudGuard SaaS portal in step # 4. Click **Save**and then close.
22. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD4_ter1812090748.png)
23. 
24. In section 3, SAML Signing Certificate, download the federation metadata xml file.
25. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD4_qar1812090749.png)
26. Go back to the **Add Identity Provider** wizard in CloudGuard SaaS and upload the metadata file just downloaded from the Azure AD management console. Click **Next**.
27. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk137853/Add IDP_Wizard4_AzureAD1812090653.PNG)
28. In the Azure AD management console, navigate to **Users and groups** and click **Add user**.
29. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD51812090750.png)
30. Select all your G Suite users and click **Select** and then **Assign**.
31. ![](https://sc1.checkpoint.com/sc//SolutionsStatics/sk137853/AzureAD61812090751.png)
32. Sign out from the Azure AD management console. Then, go back to the Add Identity Provider wizard in CloudGuard SaaS and click the button **Check Connectivity**. This will open an Azure AD login form where you will be prompted to enter your email address and password. After validation, you should see a Login Success message.
33. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk137853/Add IDP_Wizard5_AzureAD1812090703.png)
34. 

### Configure G Suite to use CloudGuard SaaS Authentication Service as an Identity Provider {#GSuite}

1. In the CloudGuard SaaS portal, navigate to **Configuration** under **Identity Protection** . In the box corresponding to the Azure AD Identity Provider you just configured, click on **Click to add SaaS**.
2. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk137853/AzureAD_Add SaaS1812090710.png)
3. A wizard will now open. Select **G Suite** and click **Next**.
4. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/Add SaaS _ GSuite1809270753.PNG)
5. Entity ID and Reply URL are pre-filled. Click **Next**.
6. Copy and paste the Sign-in page URL and the Sign-out page URL to a text file and save for later. Download the certificate and click **Finish** to save and close the wizard.
7. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/Add SaaS_cert_GSuite1809270756.png)
8. Log into the G Suite admin console. Click on **Security**.
9. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/G Suite admin1810012345.png)
10. Scroll down to section **Set up single sign on (SSO)** and expand it.
11. Check the boxes **Setup SSO with third party identity provider** and **Use a domain specific issuer**.
12. ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk136993/GSuite_config_checkboxes1810030319.png)
13. Upload the certificate downloaded in step 4 from the CloudGuard SaaS portal. We recommend doing this before filling out the Sign-in page and Sign-out page URLs due to a randomly observed Google behavior that clears out the URLs after uploading the certificate.
14. Fill out the Sign-in page URL and the Sign-out page URL with the URLs provided by the Add Service Provider wizard in step 4. You can leave empty the Change password URL. Click **Save**.
15. All login requests to G Suite will now go through the CloudGuard SaaS Authentication Service before reaching the Azure AD. Login events will be shown in the CloudGuard SaaS portal under **Identity Protection\\Events**.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
