This guide covers configuring SSO between Atlas and Google Workspace. For general SSO concepts and the Atlas-side wizard in full, see How do I configure Single Sign-On (SSO)?
Step-by-step instructions
⚠ The steps below depend on how you log in — check yours before you start.
Look at the web address you use to log in:
Log in at atlas-hub.co.uk? Open the atlas-hub.co.uk section below.
Log in at app.ihasco.co.uk? Open the app.ihasco.co.uk section below.
If you log in at atlas-hub.co.uk
If you log in at atlas-hub.co.uk
Step 1 – Create a SAML 2.0 application in Google Workspace
Sign in to the Google Admin console.
Go to admin.google.com.
Sign in with an account that has Super Admin or equivalent privileges to manage apps and security.
Create a new custom SAML app for Atlas.
In the Admin console, go to Apps → Web and mobile apps.
Click Add app and select Add custom SAML app.
Enter an application name, for example "Atlas SAML SSO", and optionally add a description and icon.
Click Continue.
Download Google IdP metadata and certificate.
Download the IdP metadata XML file and/or note the SSO URL and Entity ID that Google provides.
Download the certificate (if it's provided separately); this will be required in Atlas.
Click Continue after you've downloaded or copied the required information.
Configure basic SAML settings with Atlas values. On the Service Provider details step, use values from the Atlas Single Sign On configuration wizard:
Set ACS URL (Assertion Consumer Service URL) to the Atlas Single Sign On URL.
Set Entity ID (or Audience URI) to the Atlas Audience / Entity ID.
For Name ID format, select EMAIL or EMAIL_ADDRESS, unless your Atlas administrator specifies a different format.
For Name ID, select Primary email (or another identifier required by your internal standards and Atlas configuration).
Leave optional fields at their defaults unless instructed otherwise by your Atlas administrator.
Click Continue.
Important: Don't use generic values from other documentation. Always use the exact values generated for your Atlas environment.
Configure Google Workspace SAML attributes / mappings (if required).
On the Attribute mapping step, click Add mapping to create attribute mappings.
Configure attributes to include at least email address, first name, and last name.
Example mappings:
App attribute: email → User field: Primary email
App attribute: given_name → User field: First name
App attribute: family_name → User field: Last name
The phone number attribute is optional and can be skipped.
Use clear, consistent attribute names (for example email, given_name, family_name) that you'll later map in Atlas.
Click Finish to create the app.
Enable the app for users.
After the app is created, open it in the Web and mobile apps list.
Go to the User access section.
Turn the app ON for the organisational units (OUs) or groups whose users should be able to access Atlas.
Save your changes.
Step 2 – Add users in Google Workspace and Atlas
Confirm and assign users in Google Workspace.
In the Admin console, go to Directory → Users.
Ensure that users who will sign in to Atlas exist, are active, and are in OUs or groups where the Atlas SAML app is turned ON, so they can authenticate via SSO.
Add the same users in Atlas.
In Atlas, open the user management area.
Create or confirm user accounts that match the identifiers used in Google Workspace (typically the primary email address).
Make sure these identifiers match exactly so SSO can correctly map users between Google Workspace and Atlas.
Step 3 – Configure Single Sign On in Atlas
Open the Single Sign On configuration page in Atlas and follow the wizard.
Configuration name and protocol.
Enter a clear configuration name, for example "Google Workspace Single Sign On".
Select SAML 2.0 (or the equivalent option) as the protocol, matching what you configured in Google Workspace.
Atlas Single Sign On endpoints.
In the wizard step labelled Atlas Single Sign On endpoints, review the values shown (Single Sign On URL and Audience / Entity ID).
Confirm these match the values you entered in the Google Workspace SAML configuration (for example, ACS URL and Entity ID / Audience URI).
Identity provider configuration (Google metadata, certificate, URLs). In the relevant step of the Atlas wizard, paste or upload the Google identity provider details you collected earlier:
IdP metadata XML (or SSO URL and Entity ID)
Certificate
Sign-in URL (and logout URL, if applicable)
Save this configuration step after entering all required values.
User attribute mapping. Follow the wizard prompts and map the Google Workspace SAML attributes to Atlas user fields:
Map the attribute containing the email address (for example email) to the Atlas email field.
Map the attribute containing the first name (for example given_name) to the Atlas first name field.
Map the attribute containing the last name (for example family_name) to the Atlas last name field.
Mapping a phone number attribute is optional and can be skipped.
Confirm all required mappings are completed, then finish the wizard and check the configuration saves without errors.
Step 4 – Test the connection
Run the test from Atlas:
On the Atlas Single Sign On configuration page for Google Workspace, select Test connection.
Atlas starts the test and redirects you to the Google Workspace sign-in page.
Expected behaviour:
Atlas redirects you to the Google Workspace sign-in page for your domain.
You can successfully authenticate using a user who is allowed to access the Atlas SAML app in Google Workspace.
After successful authentication, you're redirected back to Atlas.
Atlas displays a message confirming that the connection test is successful.
If you log in at app.ihasco.co.uk
If you log in at app.ihasco.co.uk
Step 1 – Add the iHasco Training SAML app to Google Workspace
Sign in to your Google Workspace account.
Go to Apps → Web and mobile apps.
Click Add app, then Add custom SAML app to show Step 1 App details.
In App name, enter iHasco Training.
Download the iHasco logo using this link: iHasco app icon, then upload it as your App icon.
Click Continue to show Step 2 Google IdP details.
Find Option 2 and copy the field names and values in the first table below into a text editor — you'll need them when you create the Google IdP details in Atlas.
Click Continue to show Step 3 Service provider details.
In another browser tab, sign in to iHasco Atlas LMS as an administrator.
Go to Settings, scroll to the Advanced card, and click Single Sign On.
Scroll to SAML2 SERVICE PROVIDER DETAILS and copy the values across from Atlas to Google Workspace, using the second table below.
Select PERSISTENT as the Name ID format.
Click Continue to show Step 4 Attributes.
Set the mappings shown in the third table below.
Click Finish.
Under User access, assign your training users to the iHasco Training app.
Copy from Google Workspace (2 – Google Identity Provider details) into your text editor:
Google Identity Provider details |
SSO URL |
Entity ID |
Certificate file contents |
Copy from Atlas (SAML2 Service Provider details) into Google Workspace (3 – Service provider details):
Atlas — SAML2 Service Provider details | Google Workspace — Service provider details |
User Login URL | Start URL |
Assertion Consumer Service (ACS) URL | ACS URL |
Entity ID / Metadata URL | Entity ID |
Attribute mappings (Step 4 Attributes in Google Workspace):
Google Directory attribute | App attribute |
Primary Email | emailaddress |
First name | firstname |
Last name | lastname |
Step 2 – Create the Google IdP details in Atlas
In iHasco Atlas LMS, sign in as an administrator.
Go to Settings, scroll to the Advanced card, and click Single Sign On.
Click Add Provider and select SAML2.
Type a name for this provider in Description.
Scroll to IDENTITY PROVIDER DETAILS and, using the values in your text editor from Step 2 Google IdP details, copy them across using the first table below.
Scroll to USER ATTRIBUTE MAPPING and set the mappings shown in the second table below.
Click Save, then click Enable now.
Copy from Google Workspace (2 – Google Identity Provider details) into Atlas (Identity provider details):
Google Workspace | Atlas — Identity provider details |
SSO URL | Single Sign-on URL |
Entity ID | Entity ID |
Certificate file (all file contents) | X509 (Public) Certificate |
User attribute mapping in Atlas:
Atlas field | Mapped value |
Email address | emailaddress |
First name | firstname |
Last name | lastname |
Step 3 – Set the registration method in Atlas
Go to Settings.
Scroll down to the Advanced card and click Security.
Find Registration Method and select Single Sign On Provider.
Choose your new provider as the Selected Provider.
Click Save changes.
Step 4 – Test SSO using Google Workspace
Note: Before testing, add users to the iHasco Training application in Google Workspace, and sign out of any iHasco administrator accounts.
In Google Workspace, open the iHasco Training application.
Click TEST SAML LOGIN.
If the test is successful, you'll be signed in and taken to the iHasco My Learning screen (or to the iHasco Atlas LMS if testing with a pre-registered admin account).
Troubleshooting tips
If the connection test fails:
Confirm that Entity ID / Audience URI and ACS URL / Single Sign On URL in Google Workspace exactly match the values shown in the Atlas Single Sign On endpoints step.
Check that the user is allowed to authenticate to the Atlas SAML app in Google Workspace and that the same user exists in Atlas with matching identifiers.
Verify that the SAML attribute names / claims for email, first name, and last name in Google Workspace match the mappings you configured in Atlas.
Review any error messages in Atlas and in the Google Admin console → Reports → Audit → SAML (or similar) to identify where the problem is.
If you still can't resolve the issue yourself, see I can't resolve SSO issues, what should I do?
