I am a Zivver admin
Configure and manage Zivver
SSO with Google Workspace
Introduction
How do you set up SSO as a Zivver administrator?
Zivver supports Single Sign-On (SSO) through Google Workspace, allowing users to log in to Zivver with their workplace credentials.
SSO operates on the basis of Security Assertion Markup Language (SAML) v2.0; in this scenario, Google Workspace is the Identity Provider (IdP) and Zivver is the Service Provider (SP).
To activate SSO in Zivver, you need the following:
- You are a Zivver administrator.
- You have access to the Admin panel in Workspace.
- You have Super Admin rights in Workspace, which are required to set up a new SSO link.
Set up SSO connection in Workspace
- Log in to Google Workspace.
- In the menu on the left, click Apps > Web and mobile apps.
- Click Add app > Add custom SAML app.
A new window opens. - Enter a name in App name, for example
Zivver
. - Optional: Enter a Description and an App icon.
- Click .
- Click .
- Click .
- Set ACS URL to
https://app.zivver.com/api/sso/saml/consumer/
. - Set Entity ID to
https://app.zivver.com/SAML/Zivver
. - Optional: Set Start URL to
https://app.zivver.com/
. - Leave Signed Response unchecked.
- Set Name ID format to EMAIL.
- Set Name ID to Basic information > Primary email.
- Click .
- Click .
- In Google directory attributes, select Primary email.
- In App attributes, enter
https://zivver.com/SAML/Attributes/ZivverAccountKey
. - Click .
You are automatically redirected to the page of the SAML application of Zivver. - Click User access.
- At Service status, select ON for everyone.
- Click .
You have successfully set up SSO in Workspace.
Set up SSO connection in Zivver
Follow these steps to configure the newly created SSO connection in Zivver:
- Log in to the Zivver WebApp.
- Click the
Organization Settings.
- Expand
User administration.
- Click Single Sign-on.
- Select Manually.
- Open the IDP metadata file you downloaded from Google Workspace.
- Paste the contents of the IDP metadata file into the Identity Provider’s .XML field in Zivver.
- Click .
- On top of the page, click .
You have successfully set up the SSO link in Zivver.
Zivver 2FA exemption (optional)
By default, a Zivver account is protected with an additional login method (2FA). 2FA is also required when logging in via SSO. You can disable Zivver’s 2FA when users log in via SSO with Google Workspace.
Google Workspace does not indicate in the SAML response whether the user has already specified an extra login method. Google Workspace always provides this SAML response:
urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
This means the SAML response does not contain information from which Zivver can decide whether the user is logged in securely with 2FA.
Follow these steps to configure 2FA exemption for Google Workspace in Zivver:
- Click
Organization Settings.
- Expand
User administration.
- Click Single Sign-on.
- Scroll down to the Zivver 2FA exemptions card.
- In the Authentication methods to be exempted field, enter the following value:
urn:oasis:names:tc:SAML:2.0:ac:classes:unspecified
. - Click .
You have now successfully set a 2FA exemption for Google Workspace. When users log in via SSO, Zivver will not ask for 2FA.
Logging into the WebApp with SSO
- Go to the WebApp.
- Enter your email address.
- Select your role in Zivver:
- User: you will be redirected directly to your organization’s login screen.
- Administrator: you can choose between your Zivver password and your workplace login credentials.
- Log in with your organization’s workplace login credentials.
Depending on a 2FA exemption, you may be prompted for an additional login method. - Enter your additional login method.
You are now logged into the WebApp.
Logging into Outlook with SSO
To log in with SSO using the Zivver Office Plugin in Outlook, follow these steps:
- Click the Zivver tab.
- Click
Manage accounts.
- Click add_circle Add an account.
- Select the email address you want to log in with.
- Click Yes, I want to login.
You will be redirected to your organization’s login screen. - Log in with your organization’s workplace login credentials.
Depending on a 2FA exemption, you may be prompted for an additional login method. - Enter your additional login method.
You are now logged into Outlook.