Integrating Google Workspace with UniFi Fabrics
UniFi Fabrics allow you to centrally manage people and permissions by integrating with Google Workspace as an Identity Provider (IdP). This enables secure, SAML-based authentication and automated user lifecycle management across UniFi services such as WiFi, VPN, and Door Access via the Identity Endpoint app.
For a list of other supported Identity Providers, see Binding an Identity Provider (IdP) To A UniFi Fabric.
Requirement
- A Fabric with Consolidated People Management enabled. For more information, see Getting Started with UniFi Fabrics.
- A supported Google Workspace Subscription: Frontline Standard, Business Plus, Enterprise Standard, Enterprise Plus, Education Fundamentals, Education Standard, Education Plus, or Enterprise Essentials Plus.
- See Compare Google Workspace Editions to learn more.
Set Up Google SAML and Sync Users
- Go to Site Manager.
- Select a Fabric.
- Navigate to Settings > Identity.
- Enable Consolidated People Management and wait for the Identity Sync Service to set up.
- Select Microsoft Entra from the list of IdPs to bind.
- Click Proceed.
- Sign in to your Google Admin console.
- Navigate to Apps > Web and mobile Apps > Add app > Add custom SAML app.
- Provide the requested app details, and click Continue.
- Click DOWNLOAD METADATA and click Continue.
- Paste the ACS URL and Entity ID from UniFi into your Google Admin.
- Click FINISH.
- Go back to UniFi and upload the Google IdP Metadata file and click Apply Changes.
- Go to Google Admin > Apps > LDAP. If you do not see the LDAP tab, use the search bar to look for LDAP, and open it.
- Click Add Client and enter the app name.
- Grant all Access Permissions:
- Tick Entire domain options in Verify user credentials and Read user information fields.
- Enable Read group information.
- Click Add LDAP Client.
- Download the certificate and unzip it. Click CONTINUE TO CLIENT DETAILS.
- Navigate back to UniFi and upload the certificate and key file.
- Enter the primary domain, which can be found in Google Admin Console > Account > Domains > Manage domains.
- Go to Google Admin > Apps > LDAP.
- Ensure that the Service status is ON.
- Select the client you just created, and click Authentication.
- Click Generate New Credentials.
- Navigate back to UniFi and paste the Username and Password.
- Select users to be synced and click Next.
- (Optional) Configure Identity Endpoint Services to streamline how people interact with UniFi services such as WiFi, VPN, and Access Control.