> For the complete documentation index, see [llms.txt](https://docs.keeper.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.keeper.io/sso-connect-cloud/jp/identity-provider-setup/g-suite-keeper.md).

# Google Workspace

{% hint style="success" %}
最初に[管理コンソールの設定](/sso-connect-cloud/jp/admin-console-configuration.md)の手順を完了してください。
{% endhint %}

Google WorkspaceとKeeperを連携すると、以下の機能を利用できます。

* SAML 2.0によるSSO認証
* Google Cloud APIとSCIMによる自動プロビジョニング (ユーザーとグループ)
* SCIMによる自動プロビジョニング (ユーザーのみ)

SSOのみ、SSOとプロビジョニング、プロビジョニングのみのいずれかを設定できます。

## Google Workspaceの設定

Google Workspace管理コンソールにアクセスするには、[https://admin.google.com/](https://admin.google.com) にログインします。

**\[Apps]** > **\[Web and Mobile Apps]** 画面を開きます。

<div><img src="/files/wdn4k6LtQptySWG4FSaz" alt=""> <figure><img src="/files/wdn4k6LtQptySWG4FSaz" alt=""><figcaption><p>ウェブアプリおよびモバイルアプリ</p></figcaption></figure></div>

続いて、**\[Add App]**、**\[Search for apps]** の順に選択します。

<div><img src="/files/lvkFglcA6kJWeNPA9h8C" alt=""> <figure><img src="/files/lvkFglcA6kJWeNPA9h8C" alt=""><figcaption><p>新しいKeeper SAMLアプリを追加</p></figcaption></figure></div>

**\[Enter app name]** で「**Keeper**」を検索し、「**Keeper Web (SAML)**」を選択します。

<div><img src="/files/GDbA3n2WbxC8gl35KT28" alt=""> <figure><img src="/files/GDbA3n2WbxC8gl35KT28" alt=""><figcaption><p>Keeper Web (SAML)アプリを選択</p></figcaption></figure></div>

## Keeperアプリを設定

**\[Option 1]** でIdPメタデータをダウンロードし、**\[CONTINUE]** を選択します。

<div><img src="/files/loTlTXRtNJRZvWMA8xXn" alt=""> <figure><img src="/files/loTlTXRtNJRZvWMA8xXn" alt=""><figcaption><p>Googleメタデータをダウンロード</p></figcaption></figure></div>

## サービスプロバイダの詳細情報

**\[Service Provider Details]** 画面には、入力フィールドがいくつかあります。**ACS URL**と**Entity ID**を、クラウドSSOコネクトインスタンスで使用する値に置き換えます。

<div><img src="/files/QfVo6rF1dWN9lU4xhyJn" alt=""> <figure><img src="/files/QfVo6rF1dWN9lU4xhyJn" alt=""><figcaption><p>Keeper SPの詳細</p></figcaption></figure></div>

**ACS URL**と**Entity ID**は、Keeper管理コンソールでクラウドSSOコネクトのプロビジョニングメソッドを開き、**\[表示]** を選択すると確認できます。

<div><img src="/files/tatOOBduMsjOWEsVa0Zm" alt=""> <figure><img src="/files/tatOOBduMsjOWEsVa0Zm" alt=""><figcaption><p>クラウドSSOコネクト情報</p></figcaption></figure></div>

Service providerセクションに、**ACS URL**と**Entity ID**の値が表示されます。

<figure><img src="/files/V33AAJbyxPZK9olLFnJE" alt=""><figcaption><p>ACS URLおよびエンティティID</p></figcaption></figure>

**ACS URL**と**Entity ID**をコピーして Service provider details に貼り付け、**\[Signed Response]** にチェックを入れて **\[CONTINUE]** を選択します。

<div><img src="/files/CyhZk4vC1a9FE8Q0SnTJ" alt=""> <figure><img src="/files/CyhZk4vC1a9FE8Q0SnTJ" alt=""><figcaption><p>Keeper SPの詳細情報入力</p></figcaption></figure></div>

## 属性マッピング

Attributes画面で、以下の3つのマッピングがあることを確認します。マッピングフィールドを **First Name**、**Last Name**、**Primary Email** に設定し、**\[Finish]** を選択します。これで、Google WorkspaceからKeeperへのSAML連携が完了です。

{% hint style="info" %}
カスタムSAMLアプリを選択または作成した場合は、**\[Add New Mapping]** をクリックして **First**、**Last**、**Email** の3つのフィールドを作成してください。スペルは完全一致である必要があります。
{% endhint %}

<div><img src="/files/3B6oxAgK3C7n3nJXIBbh" alt=""> <figure><img src="/files/3B6oxAgK3C7n3nJXIBbh" alt=""><figcaption><p>Google属性</p></figcaption></figure></div>

## Keeper SAMLアプリの詳細

設定が完了すると、Keeper SAMLアプリの詳細ページが表示され、SAML接続とサービスの概要を確認できます。SSOを有効にするには、**\[OFF for everyone]** の領域をクリックします。

<figure><img src="/files/LYLQA2XMiuxf3rFzwkr1" alt=""><figcaption></figcaption></figure>

## 全ユーザーでSSO Connectを有効にする

全ユーザーでKeeper SSOコネクトを有効にするには、**\[ON for everyone]** を選択して **\[SAVE]** をクリックします。

<div><img src="/files/zEskPtsxXA0Bhy3UBVOp" alt=""> <figure><img src="/files/zEskPtsxXA0Bhy3UBVOp" alt=""><figcaption></figcaption></figure></div>

## グループのSSO Connectを有効にする

特定のグループでKeeper SSOコネクトを有効にするには、**\[Service status]** の左側にある **\[Groups]** を選択し、Keeper SSOコネクトに関連付けたいグループを検索して選択し、**ON** にチェックを入れて **\[SAVE]** をクリックします。

<figure><img src="/files/Cb7LgzCTBNV9YSOvW78g" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Googleは現在、Keeperチームへのグループプロビジョニングは利用できません。
{% endhint %}

## Google Workspaceメタデータをインポート

Keeper管理コンソールに戻り、クラウドSSOコネクトのプロビジョニングメソッドを開いて **\[編集]** を選択します。

<div><img src="/files/d8JfMbnAvQhcinuUQgpl" alt=""> <figure><img src="/files/d8JfMbnAvQhcinuUQgpl" alt=""><figcaption><p>クラウドSSOコネクトを編集</p></figcaption></figure></div>

**\[Browse Files]** を選択し、以前にダウンロードしたGoogleメタデータファイルを選びます。

<div><img src="/files/5cD9TS8uM9JV58h6XV4b" alt=""> <figure><img src="/files/5cD9TS8uM9JV58h6XV4b" alt=""><figcaption><p>Googleメタデータファイルをアップロード</p></figcaption></figure></div>

メタデータファイルがプロビジョニングメソッドに反映されれば、設定は成功です。プロビジョニングの構成画面を閉じて問題ありません。

<div><img src="/files/gBXfIkNS3CsPjmWzy1DZ" alt=""> <figure><img src="/files/gBXfIkNS3CsPjmWzy1DZ" alt=""><figcaption></figcaption></figure></div>

## Google Workspaceのシングルログアウト (SLO) 設定に関する注意

{% hint style="info" %}
2022年時点では、Googleはシングルログアウトを有効にしない設定をデフォルトとしています。そのため、Keeperからログアウトしても、Googleからの完全なログアウトは開始されません。
{% endhint %}

## SSOの設定が完了しました

Keeper SSOコネクトをGoogle Workspaceと連携する設定は以上で完了です。GoogleアカウントでKeeperにログインする手順は以下のとおりです。

1. Keeperボルトを開き、**\[法人SSOログイン]** をクリックします。
2. SSO設定時にKeeper管理コンソールに指定した法人ドメインを入力します。クラウドSSOコネクトのステータス画面では「SSO Connect Domain」と表示されます。
3. **\[接続]** をクリックし、Google Workspaceの認証情報でログインします。

エンドユーザーの操作手順 (Keeperが起点となるログイン) については、[このガイド](/user-guides/jp/enterprise-end-user-setup-sso.md)をご参照ください。

以下は、SSOエンドユーザー向けの動画です。\
<https://vimeo.com/329680541>

## ユーザーとチームのプロビジョニング

Google Workspaceからユーザーとチームをプロビジョニングする方法は、以下の2通りです。

### オプション 1 (推奨): ユーザーとグループのプロビジョニング

Google WorkspaceではSCIMグループをネイティブでは利用できないため、Keeperではユーザーとグループのプロビジョニングを自動化するGoogle Cloud Functionを用意しています。設定手順は以下をご参照ください。

[Cloud Serviceを使用したGoogle Workspaceのユーザーとチームのプロビジョニング](/sso-connect-cloud/jp/identity-provider-setup/g-suite-keeper/google-workspace-user-and-group-provisioning-with-cloud-function.md)

### オプション 2: ユーザーのみをプロビジョニングする

SCIM直接統合でGoogle WorkspaceからKeeperへユーザーのみ (グループは対象外) をプロビジョニングする手順は、以下をご参照ください。

[SCIMを使用したGoogle Workspaceユーザープロビジョニング](/sso-connect-cloud/jp/identity-provider-setup/g-suite-keeper/google-workspace-user-provisioning-with-scim.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.keeper.io/sso-connect-cloud/jp/identity-provider-setup/g-suite-keeper.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
