> ## Documentation Index
> Fetch the complete documentation index at: https://specterops-feat-poc-api-playground.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# SAML: Google IDP Configuration

> This document provides instructions for creating an application within Google for compatibility with BloodHound Enterprise.

<img noZoom src="https://mintcdn.com/specterops-feat-poc-api-playground/5XJ7p5p7xL9ZwxE2/assets/enterprise-AND-community-edition-pill-tag.svg?fit=max&auto=format&n=5XJ7p5p7xL9ZwxE2&q=85&s=79b8dea14cb2266671c0a2f64f4b9caa" alt="Applies to BloodHound Enterprise and CE" width="482" height="45" data-path="assets/enterprise-AND-community-edition-pill-tag.svg" />

For general instructions on adding a SAML provider to BloodHound Enterprise, or for configuring users to utilize a SAML provider, see [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml).

See [SAML Order of Operations and Quick Reference](/manage-bloodhound/auth/saml) before starting.

## Create a Google Application

1. On the Admin Console for Google Workspaces, use the left navigation bar and go to Apps -> Web and Mobile Apps

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-58.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=4f4f064fb9f1be9eace64c7aed669759" width="436" height="359" data-path="assets/image-2-58.png" />
</Frame>

2. Select “Add App” -> Add Custom SAML app

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-59.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=3ecbf9ea04a96daf9e45f5b86438ebb8" width="541" height="331" data-path="assets/image-2-59.png" />
</Frame>

3. Give the app an appropriate name, such as BloodHound Enterprise.

   Optionally, add an icon and description.

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-60.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=5c9a966a73a479208e071b7d19227229" width="624" height="418" data-path="assets/image-2-60.png" />
</Frame>

4. On the next screen, download the metadata file and continue.

5. Enter the ACS URL and Entity ID as provided in the BloodHound Enterprise console:

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-61.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=fa5cfce20bcd00456d59629f64ae9ad7" width="624" height="429" data-path="assets/image-2-61.png" />
</Frame>

6. On the next screen, it is required to send the email attribute to BloodHound.

   BloodHound will accept either of the following values as the “App Attributes”:

   * [http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress](http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress)

   * urn:oid:0.9.2342.19200300.100.1.3

<Frame>
  <img src="https://mintcdn.com/specterops-feat-poc-api-playground/jQL0LBD6HCQg_f5l/assets/image-2-62.png?fit=max&auto=format&n=jQL0LBD6HCQg_f5l&q=85&s=e6479ee896f1cc2fd39cad069b8d763a" width="624" height="375" data-path="assets/image-2-62.png" />
</Frame>

7. Follow the instructions at [SAML in BloodHound Enterprise](/manage-bloodhound/auth/saml) to create the SAML provider in BloodHound Enterprise.
