Include
- Customers implementing Access Control
- Customers using Google Workspace as their groupware
Purpose
- This article explains how to configure single sign-on (SSO) between Google Workspace and Access Control to enable access control.
Notes
- Please check the required items according to your services and use cases.
- The content of this article is based on the product as of January 2026 and is subject to change without notice.
Table of Contents
- Device Information Collection
- Access Control Operation Policy Review
- Access Control Operation Policy Configuration
User Synchronization from Active Directory to Google Workspace / Access Control
- Organize Users in Active Directory
- Install Google Cloud Directory Sync and Start User Synchronization
- Install HDEPasswordFilter on All Domain Controllers (WS 2016 and later)
- Install HENNGE Directory Sync Tool
- Install Root Certificate for HENNGE Directory Sync Tool Operation
- Create API Client for HENNGE Directory Sync Tool Execution
- Initial Placement of HENNGE Directory Sync Tool Configuration File (config)
- Execute Assign-HDEOnePasswrdSyncGroup
- Set Passwords for Users to be Synchronized
- Confirm Password Settings for Users to be Synchronized
- Run Directory Sync Tool
Settings to Synchronize User Information from Access Control to Google Workspace
- API Authorization Settings for User Provisioning
- User Batch Registration / Update / Delete
Settings Required on the End User Side to Use Access Control Access Control
- Install Secure Browser and Device Authentication
- Configure OTP (One-Time Password) Receipt via Application
- Configure OTP (One-Time Password) Receipt via Email
- Issue Device Certificate
- Install Device Certificate
- Check Device Certificate Installation Status
- Install Application to Read Device Certificate
Access Control Access Policy Configuration
- Assign Access Policy Groups to Users
- Test Access Policy Group Operation
- Assign Browser Policy Groups to Users
Connect Access Control and Google Workspace
- Configure Single Sign-On (SSO) Connection between Access Control and Google Workspace
- Verify Single Sign-On (SSO) Connection between Access Control and Google Workspace
- Configure Single Sign-On (SSO) Connection between Access Control and Chromebook
- Verify Single Sign-On (SSO) Connection between Access Control and Chromebook
- Disconnect Google Workspace Authentication
- Connect to Services Using Single Sign-On (SSO)
- User Provisioning for Services Using Single Sign-On (SSO)
Procedure
Preparation
-
Device Certificate Device Information Collection
* If you are using Device Certificates, please complete this step.
Device information for the target device is required to issue a Device Certificate.
Please select and collect information on the target devices in advance. - Access Control Operation Policy Review
Review the operation policy for Access Control (access control rules, items displayed on the login screen, etc.). - Access Control Operation Policy Configuration
Reflect the reviewed Access Control operation policy in the actual product settings.
User Synchronization from Active Directory to Google Workspace / Access Control
If you want to synchronize users from Active Directory to Access Control, please complete this section.
- Organize Users in Active Directory
-
Install Google Cloud Directory Sync and Start User Synchronization (External Link)
For details, please contact Google or your Google Workspace reseller. - Install HDEPasswordFilter on All Domain Controllers (WS 2016 and later)
- Install HENNGE Directory Sync Tool
- Install Root Certificate for HENNGE Directory Sync Tool Operation
- Create API Client for HENNGE Directory Sync Tool Execution
- Place HENNGE Directory Sync Tool Configuration File (config)
- Execute Assign-HDEOnePasswrdSyncGroup
- Set Passwords for Users to be Synchronized
Change the password for all users to be synchronized once. - Confirm Password Settings for Users to be Synchronized
- Run Directory Sync Tool
Settings to Synchronize User Information from Access Control to Google Workspace
If you want to synchronize users from Access Control to Google Workspace, please complete this section.
- API Authorization Settings for User Provisioning
- User Batch Registration / Update / Delete
Settings Required on the End User Side to Use Access Control Access Control
-
Install Secure Browser
* This step is for customers using Secure Browser. -
Configure OTP (One-Time Password) Receipt via Application
* This step is for customers using OTP. -
Configure OTP (One-Time Password) Receipt via Email
* This step is for customers using OTP. -
Issue Device Certificate
* This step is for customers using Device Certificates. -
Install Device Certificate
* This step is for customers using Device Certificates.
* If you are using a Chromebook, please complete the following step in advance.
Device Certificate [For Chromebook] Cybertrust DeviceiD Importer Registration Method -
Check Device Certificate Installation Status
* This step is for customers using Device Certificates. -
Install Application to Read Device Certificate
* This step is for customers using Device Certificates on iOS devices.
Depending on the service linked with Access Control, this section may be required.
For details, please consult your implementation guide.
Access Control Access Policy Configuration
- Assign Access Policy Groups to Users
-
Assign Browser Policy Groups to Users
* This step is for customers using Secure Browser.
Connect Access Control and Google Workspace
- Configure Single Sign-On (SSO) Connection between Access Control and Google Workspace
- Verify Single Sign-On (SSO) Connection between Access Control and Google Workspace
- Configure Single Sign-On (SSO) Connection between Access Control and Chromebook
- Verify Single Sign-On (SSO) Connection between Access Control and Chromebook
- Disconnect Google Workspace Authentication
-
Connect to Services Using Single Sign-On (SSO) (External Link)
If you have services other than Google Workspace that use SSO, you can download procedures with a proven track record from this section. -
User Provisioning for Services Using Single Sign-On (SSO)
Some services support user provisioning.
You can check which services support provisioning from this section.