# How-to: configuring the Google App Connector for Crowd

> How to configure the Google App Connector in Atlassian Crowd and enable single sign-on for Google Apps – step by step.

Source: https://www.xalt.de/en/blog/how-to-google-app-connector-for-crowd/

TEAM XALT Atlassian Platinum Partner · 20 September 2021 · 6 min

The Google App Connector is delivered by default with Crowd from Atlassian and can be configured directly in the Crowd Administration. The Google App Connector for Crowd allows you to actively use Single Sign-On (SSO) for your apps and open apps such as Docs or Sheets from Jira or Confluence without further authentication.

You can find out how to use the Google App Connector in Crowd further down.

## What is Single Sign-On (SSO)?

Simply put, Single Sign-On allows you to log in to multiple apps (here Atlassian software and Google Apps) with just one account and use them simultaneously. You probably know this from the apps. You log in to your Gmail and can simultaneously use Google Docs or Meets.

### How does SSO work with the Google App Connector?

In the case of Google Apps, authentication is therefore your Google user ID and your password. Google Apps handles the SSO part with its Google Account website.

When you log in to Gmail in the morning, you are prompted to enter your authentication details on the Google Account website, which then redirects you back to Gmail in your browser upon successful authentication.

The Google account remembers that you successfully authenticated this morning, so the redirect happens again when you open a Docs & Sheets page later in the day. No further authentication is required.

**In colloquial terms, this means:**

- Authentication: The data used to authenticate a user.
- SSO - When you log in to one application, you do not need to log in to another application to access it (at least for a certain period in the same browser).

The major advantage of using Google as a [SSO](https://www.atlassian.com/de/software/access/guide/elements/single-sign-on) solution for Atlassian Crowd is that you can configure the SSO functionality yourself.

**You can find out how to configure and use the Google App Connector for Crowd here:**

## Configuring the Google Apps Connector for Crowd

### Prerequisites – You need Google Suite

To enable [Single Sign-On in Google Workspace](https://support.google.com/a/answer/60224?hl=de), you need the Premier, Education, or Partner edition of Google Workspace. The free Standard version of Workspace does not support SSO. Therefore, be sure to check your version beforehand and upgrade if necessary.

### Step 1: Configuring the Crowd application, directories, and group details

In this step, you enter the application details of the Google App Connector in Crowd. You can manage access to Google Apps by linking people directories and/or groups with the apps.

![Atlassian Crowd Admin Console](https://cdn.sanity.io/images/c475o02b/production/c859f1e5491d749f4f66f16c5f8187b0d5bb9e42-1502x494.png?w=1504&q=75&fit=max&auto=format)

Crowd Admin Console

#### 9 steps to configure the Google App Connector in Crowd

1. Log in to the Crowd administration console.
2. Click the Applications tab in the top navigation bar.
3. Click the link for the application name "Google Apps".
4. If required, you can change the description. Make sure the "Active" checkbox remains checked.
5. Click the Directories tab and select one or more user directories containing the users who should have access to Google Apps.
6. To determine which users within the directory are allowed to authenticate to the application, you can either:

  1. On the Directories tab, change the Allow all to authenticate option to True. This allows all users in this directory to log in to Google Apps. (The default setting is False.)

**OR**

1. Use the Add button on the Groups tab to select one or more user groups.
2. Click the Permissions tab and set the directory permissions for the application.
3. If required, you can change the application options on the Options tab:

  1. Output in lowercase - See Enforcing lowercase for usernames and groups for an application.
    2. Enable aliasing - see Setting a user’s aliases.
4. Click the Configuration tab and create your SSO keys as described in step 2.

![Atlassian Crowd Google App Connector](https://cdn.sanity.io/images/c475o02b/production/d88e82b8526df5b1c2dd8c2703300de4d29c4df8-2874x872.png?w=1504&q=75&fit=max&auto=format)

![Atlassian Crowd](https://cdn.sanity.io/images/c475o02b/production/34207f90a531872eb29502008d3d00d1a9b811b4-2328x954.png?w=1504&q=75&fit=max&auto=format)

![Atlassian Crowd Google App Connector](https://cdn.sanity.io/images/c475o02b/production/b93661a4994eef74c916f1755525376627bbe277-1858x702.png?w=1504&q=75&fit=max&auto=format)

![Atlassian Crowd Google App Connector](https://cdn.sanity.io/images/c475o02b/production/fd24d2529bd964de98bf318157a9fb7f60a9ecbc-1860x656.png?w=1504&q=75&fit=max&auto=format)

![Atlassian Crowd](https://cdn.sanity.io/images/c475o02b/production/33d402295b33d95a8026c474dfc83e90c001793f-1496x734.png?w=1504&q=75&fit=max&auto=format)

### Step 2: Generating single sign-on (SSO) authentication keys

To link your Google Apps with Crowd, you now need to create authentication keys: a “Public Key” and a “Private Key”. In the open window, go to “Configuration” and click “Create new keys”

With Atlassian Crowd you generate a public key and a private key and store them in the Crowd

database. Once the keys have been created, you will see the message "DSA keys successfully generated and stored".

### Step 3: Configuring Google Workspace and connecting it to Crowd

For Google to communicate with Crowd, SSO must be adjusted in the Google Workspace admin environment. Only then is authentication with Google Apps possible.

#### Here is how to configure Google Apps so that Crowd is recognised:

1. Sign in to your Google Apps dashboard as an administrator.
2. Then click **‘Security’.**
3. Navigate to **‘Advanced settings’.**
4. Click Set up **Single Sign-On** (SSO).
5. Copy the URLs from the Crowd configuration screen (see above) and paste them into the Google Apps screen.
6. Now upload the public key that Crowd created for you in Step 2 above:

  1. Now click Browse under "Verification certificate".
    2. Navigate to the Google Apps configuration in Crowd and download the public key by clicking the Download button next to the **Public key** label.
    3. Select the public key certificate (filename DSAPublic.key) and upload it to Google Apps.
7. If required for your network configuration, tick the **Use a domain-specific issuer** checkbox and enter all required network masks in Google Apps. You can find instructions for these settings in the documentation.
8. Finally, save your changes.

### Step 4: Checking whether users can authenticate with Google

In the final step, it is important to verify that the configuration of the Google App Connector with Crowd was successful.

#### To do this, proceed as follows:

1. In the Crowd admin interface and app configuration, go to the "Authentication test" tab
2. Enter the login details of, for example, yourself or a test user, and click "Test".
3. If you have set everything up correctly, you will receive a success message and you are done.

???? You have now successfully configured the Google App Connector in Crowd, and all your users no longer need to sign in to Cloud Apps individually.

### Bonus tip

#### The username must exist in both Google Apps and Crowd

The username must exist in both Google Apps and Crowd and be identical. The Crowd Google Apps Connector does not support automatic user addition. If the user exists in Crowd but not in Google Apps, they cannot log in.

Do you need support with configuring your Crowd application or other Atlassian software such as Jira or Confluence? You can find more information here: [XALT Atlassian Services](https://www.xalt.de/en/atlassian-services/).

## Need help configuring Crowd?

We'll help you with SSO, user management and administering your Atlassian systems.

[Talk to us](https://www.xalt.de/en/contact/)

## More articles

### [Personal AI Agents Compared: Rovo, OpenClaw, and Agent SDKs Like Claude or OpenAI](https://www.xalt.de/en/blog/personal-ai-agents-compared-rovo-openclaw-and-agent-sdks/)

Rovo, OpenClaw, or Claude/OpenAI: how personal AI agents differ in 2026 and which approach fits your team.

*Atlassian*

### [BaFin Compliance for Atlassian Cloud – What Financial Institutions Need to Know Now](https://www.xalt.de/en/blog/bafin-compliance-atlassian-cloud-migration/)

New EU FSA rules have been in effect for Atlassian Cloud in financial services since December 2024. We show what has changed and how you can migrate to the cloud in a BaFin-compliant way.

*Atlassian*

### [Atlassian Team '26 Recap: The Shift to the AI-Native Organization and the Role of the Teamwork Graph](https://www.xalt.de/en/blog/atlassian-team-26-recap-teamwork-graph/)

XALT was on the ground at Atlassian Team '26 in Anaheim. Our recap covers the Teamwork Graph, Rovo, and the new Teamwork, Service, Product, Software, and Strategy Collections – and what it means for enterprises in Germany.

*Atlassian*

---

*This version is for AI agents. Every page of this site is available as Markdown: append `index.md` to its path. Index of all pages: [llms.txt](https://www.xalt.de/llms.txt)*
