How do I use groups to apply a SAML2 policy in Google?

When using Google Workspaces with our SAML 2.0 Identity Provider function, you will likely want to apply the SAML2 authentication policy or profile to groups to make it easy to transition to 2FA for users.

Select this option first:

Preview

 

Then, you will be presented with the option of selecting the desired scope. You will want to select a group. Google allows you to add individual users, which is adequate for Proof of Concept (POC) or free trial purposes. However, it is easier to manage users through a designated group when in production:

Preview