G Suite SSO
Set up G Suite SSO to log in to the Panther Console
Panther supports integrating with G Suite (now named Google Workspace) as a SAML provider to enable logging in to the Panther Console via SSO.
- 1.Log in to the Panther Console.
- 2.Click the gear icon in the upper right. In the dropdown menu, click General.
- 3.Click the Identity & Access tab.
Keep this browser window open, as you will need the Audience and ACS URL values in the next steps.
Note that it may take up to 24 hours for your changes to propagate in Google Workspace.
Make the following modifications to create the SAML app for Panther:
- In the Service Provider Details window, enter the ACS URL and Entity ID values you obtained from the Panther Console earlier in this documentation.
- On the Attribute mapping page, configure the following attribute mappings:
- First Name:
- Last Name:
- Primary email:
- 2.Next to Enable SAML, set the toggle to ON.
- 3.In the Default Role field, choose the Panther role that your new users will be assigned by default when they first log in via SSO.
- 4.Below the Identity Provider URL field, click click here to upload the metadata file you downloaded from Google while configuring the SAML app.
- 5.Click Save Changes.
To test your setup, go to your Panther sign-in page and click Login with SSO.
Amazon Cognito (which powers Panther's user management) does not yet support IdP-initiated login, meaning you cannot login to Panther from G Suite. The login must be initiated from Panther, the service provider.
For this reason, the "Test SAML Login" button in the G Suite admin console may not work, but as long as you can login from Panther you have configured it correctly.