Note
With Device Trust and Google Workspace you can make sure every device is known, secure, and compliant before it can access company applications, and empower your organization to remediate their own device health issues with step-by-step instructions.
With this integration you can:
- Import and synchronize your Google Workspace users and groups.
- Protect the Device Trust admin dashboard with Google single sign-on (SSO) authentication.
- Allow your users to sign in to Device Trust-protected apps with their Google credentials.
Tip
Before you begin
Before you can set up Device Trust and Google Workspace, you’ll need:
- 1Password Device Trust
- A Google Workspace plan.
- Google Admin console access with super administrator permissions.
This feature is not currently available to all Device Trust customers. To make sure you have access, select your profile in the top-right corner of the Device Trust admin console. If you see Identity Providers in the sidebar, you have access. If you see Authentication & Provisioning, contact 1Password Device Trust support to turn on the feature.
Note
This integration currently only supports apps that use SAML. 1Password uses OIDC, so you can’t add protection to 1Password using this integration.
You can’t add Google Workspace apps (like Docs, Sheets, Gmail) to this integration because third-party apps can’t change the existing login flow for Google Workspace apps.
These steps were recorded in November 2024 and may have changed since. Refer to the Google Workspace admin documentation for the most up-to-date steps.
Step 1: Activate your Device Trust account
If you haven’t already, you’ll need to sign in to 1Password.com and create your Device Trust tenant.
Note
- Sign in to your account on 1Password.com.
- Select 1Password Admin Console in the top-left corner.
- Choose Kolide. This creates your Device Trust tenant.
Step 2: Create a Device Trust-enabled group in the Google admin console for testing
To test the implementation and make sure it works the way you want it to, first create a Device Trust-enabled group in Google Workspace and populate it with a few users for testing. You can use this test group to limit which users have access to Device Trust during your testing.
Configure group information
- Open two browser windows side-by-side. In one window, sign in to the Google Admin console.
- In the second window, sign in to Device Trust.
- In the Device Trust admin console, select your profile in the top-right corner, then select Settings and choose Identity Providers in the sidebar.
- In Device Trust, select the Set Up button for Google, then select Set Up Single Sign On Provider.
- In the Google Admin console, select Directory > Groups in the sidebar.
- Select Create group.

- Fill out the fields, including:
- Group name: Enter the name “Device Trust Enabled”.
- Group email: Enter the email address you want to use.
- Group description: Enter a description of the group. For example: “Device Trust Enabled Users”.
- Select the check box next to Security.
Configure access settings
You can configure access settings in the way that works best for your organization, but we recommend limiting who can join the group. This makes sure the group is small for your initial test:
- In the Google Admin console, in the “Who can join the group” section, select Only invited users.
- Once you’ve configured the other settings, select Next at the bottom of the page.
- Select Create Group at the bottom of the page.

Add people to the group
- In the Google Admin console, select Add members to Device Trust Enabled.
- Select Add members, then in the Find a user or group field, search for your test users and select them.
- Choose Add to group.

Step 3: configure SAML SSO for Device Trust
Add Device Trust as a custom SAML app within your Google Workspace portal. This allows Device Trust to use Google as a single sign-on (SSO) service provider for authenticating users into the Device Trust admin or end-user portal, along with any apps you’re managing within Device Trust.
Set up the Device Trust application for SSO
- In the Google Admin console, select Apps > Web and mobile apps.
- Select the Add apps dropdown, then select Add custom SAML app.

- In the App name field, enter the name “Device Trust”.
- Optionally, if you’d like to add the Kolide logo to your app, download the Kolide logo. Then select the camera icon and upload the file.
- Select Continue at the bottom of the page.
- Copy the SSO URL from the Google Admin console and paste it into the Provider SSO URL field in Device Trust.
- Select the copy icon by the certificate in the Google Admin console and paste it into the Provider X.509 Certificate box in Device Trust.
- In the Google Admin console, select Continue.
- In Device Trust, copy the Kolide ACS URL and paste it into the ACS URL field in the Google Admin console.
- In Device Trust, copy the Kolide Entity ID, then paste it into the Entity ID field in the Google Admin console.
- In the Google Admin console, select Continue, then select Finish.
- In Device Trust, select Save Settings.

Set up user access
- In the Google Admin console, select the User access dropdown.

- Select the Groups dropdown.
- Search for the Device Trust Enabled group and select it.
- Select the check box next to On for the Service status, then select Save.

Step 4: Configure provisioning for Device Trust
Import and synchronize your organization’s Google Workspace users and groups into Device Trust.
Provision users
Important
- In Device Trust, select Set Up User Provisioning.
- Select Log in with Google Workspace.
- Choose your Super admin account and sign in.
- Under “Select what Device Trust can access”, select the check box next to Select all.
- On the “User Provisioning” pop-up, you can choose how you want to import identities and groups.
Configure import settings
On the User Provisioning pop-up, choose how you want to import identities and groups.
The first time you use the updated selectable groups feature, you’ll need to select Re-authenticate to opt-in. You won’t be required to re-authenticate next time you use this feature.
By default, we recommend you do not import suspended user identities. You can change this by selecting “Import identities marked ‘Suspended’. Suspended accounts are accounts that have been disabled by your Google Workspace administrator but still exist in your directory. Accounts that were previously imported and then suspended remain in Device Trust until manually removed.
Under “In-Scope Group Types”, choose which types of Google Workspace groups to import. Only the selected types will be imported.
- Google Groups (Email Lists): Primarily for email and distribution lists.
- Security: For managing access and permissions for sensitive data, systems, or resources.
- Dynamic: Based on user attributes (department, location, role, and more). Dynamic groups are available only on certain Google Workspace plans. Learn more about dynamic groups in Google Workspace.
Under “Imported Identities and Groups”, define which groups and users Device Trust imports from Google Workspace.
- Import all in-scope groups and their identities: Imports every in-scope group defined in Google Workspace and the users in those groups.
- Import all in-scope groups and their identities, except the following…: Imports all groups except those you exclude.
- Exclude identities in selected groups, even if imported by other groups: Use this option to prevent importing users who belong to excluded groups, even if they’re also in other in-scope groups.
- Import only selected in-scope groups and their identities: Imports only the specific groups you select and the identities that belong to them.
Step 5: Activate the IdP
Complete provisioning setup
- In Device Trust, select the vertical ellipsis button, then select Activate.
- In Device Trust, select the vertical ellipsis button on the Google Workspace card under Identity Providers, then choose Make Primary.
- To make sure that single sign-on and user provisioning are working correctly, in a new private browser window, go to
https://app.kolide.comand sign in. A private browser window makes sure the existing session is not cached. - Sign in to Device Trust with your admin account.
- Sign in with your Google credentials for your admin account.
- After you’ve successfully signed in, close the private browser window.
Turn on Device Trust
Protecting the Device Trust admin dashboard with Device Trust itself makes sure that your dashboard is more secure. Device Trust checks the compliance of the device and blocks access if the device is non-compliant, allowing you to test Device Trust capabilities and features before you add more apps to Device Trust.
- In the Device Trust admin console under Identity Providers, select Google Workspace.
- Select Single Sign-On Provider.
- In the Device Trust section, select the check box next to Protect Kolide Admin Dashboard with Device Trust.
- Select Update Settings.
Step 6: Test Device Trust
To test the Device Trust sign-in process from the perspective of your organization:
- Sign in as a user that belongs to your Device Trust Enabled group.
- As an optional step if your organization uses an MDM, pre-install the Kolide agent to simulate pushing the agent out to your devices. This is optional because the user will be prompted to install the agent if it is not present.
- In a new private browser window, go to
https://app.kolide.comand sign in with your Google credentials. - You’re redirected to the “Kolide is Verifying Your Device” screen, which shows you that the Kolide agent is installed. If you downloaded the Kolide agent in step 2, the device is registered to you and you’re signed in to the Device Trust admin console.
- If you didn’t already download the Kolide agent, you’re prompted to download the agent. Download the installer for your operating system and follow the on-screen instructions through to the success message.
- In the task bar, you’ll see a Kolide icon that appears after about 60 seconds.
- In a new private browser window, go to
https://app.kolide.com. A private browser window makes sure the existing session is not cached. - Sign in with your Google Workspace credentials using your username and password.
- You’re redirected to the “Kolide is Verifying Your Device” screen, which shows you that the Kolide agent is installed.
If the agent was pre-installed on the end-user device, it will register the device. If the agent is not installed, the user will be prompted to download and install the agent before the new device can be registered.
To see how Device Trust handles failed Checks, first set up device health Checks for your organization. Then:
- In Device Trust, choose the Devices tab and select your device to see if there are any failing Checks.
- Select Details on a Check that is straightforward to fix, like File Extensions Are Not Visible in Finder.
- Select Actions > Edit Check Settings.
- In the Remediation Strategy section, select Configure.
- Choose Block Immediately and select Save.
- In a new private browser window, go to
https://app.kolide.com. - Sign in with your Google Workspace credentials using your username and password.
- When redirected to Device Trust, you should be blocked by Device Trust based on the Check you configured earlier.
- Select Fix this Issue, which opens a new tab that shows you how to fix the Issue.
- Fix the Issue, then return to the Device Trust window and select I’ve fixed it. Recheck now.
Device Trust will run a real-time Check to validate that the Issue has been fixed before completing the sign-in flow.
As part of future testing, continue to add new users to the Device Trust Enabled group and have users test the sign-in flow.
Step 7: Add apps to Device Trust
Step 7.1: Add an app
After you’ve configured and tested Device Trust and Google Workspace, add Device Trust-protected apps with Device Trust’s App Catalog, or add a custom app if you can’t find your app in the catalog.
Note
Configure an app
- In Device Trust, select the Apps tab.
- Select + Add Application.
- Search or scroll to find the app you want to add and select it.
- Optionally, you can edit the name or description of the app.
- Select Next Step.
Configure a custom app
- In Device Trust, select the Apps tab.
- Select + Add Application.
- Select New Custom SAML App.
- Enter the name of the app. Optionally, you can add a description of the app.
- Select Next Step.
Step 7.2: configure app settings
To connect your app to Device Trust, you’ll need to copy and paste configuration details between the two. If you’re adding an app from the App Catalog, you can select the Docs button to learn where to find your app’s configuration details. If you’re adding a custom app, check your app’s documentation. Configuration setting names can vary depending on the app.
Copy and paste your app’s configuration details
Copy the
Entity IDfrom your app and paste it into theEntity IDfield in Device Trust.Copy the
ACS URLfrom your app and paste it into theACS URLfield in Device Trust.If the
Audience URIis the same as theEntity ID, leave theAudience URIfield blank.If the
Audience URIfield is different from theEntity ID, copy theAudience URIfrom your app and paste it into theAudience URIfield in Device Trust.Copy the
Response Host(name of the service provider) and paste it into theResponse Hostfield.If your app requires the SAML response to be signed for authentication, then select the checkbox next to “Sign Response Body”. Check your app’s documentation or configuration requirements to determine if this setting is necessary.
Copy and paste Device Trust’s configuration details
- Copy the
Entity ID(Issuer) in Device Trust and paste it into theEntity ID(Issuer) field in your app. - Copy the
Sign On URLin Device Trust and paste it into theSign On URLfield in your app. - Copy the
Metadata URLin Device Trust and paste it into theMetadata URLfield in your app. - Copy the Signing Certificate in Device Trust and paste it into the Signing Certificate field in your app.
Optional app settings
If your app allows signing AuthnRequests or requires sending information like Name ID Format, Single Sign-On URL, and Logout URL, you can add those to the optional app settings fields.
Get help
To get help with Device Trust, contact 1Password Device Trust support.
To get help with 1Password Business, contact 1Password Support.
Video walkthrough
If you prefer a step-by-step visual tutorial of the Connect Device Trust to Google Guide, we’ve prepared the video below.
Was this article helpful?
Glad to hear it! If you have anything you'd like to add, feel free to contact us.
Sorry to hear that. Please contact us if you'd like to provide more details.