Prompt
What SSO should I use for a SaaS app with Google Workspace and Azure AD customers?
Latest observation
Oct 7, 2026
OpenAI APIWeb search: off
For a SaaS app serving both Google Workspace and Azure AD / Microsoft Entra ID customers, the safest default is:
Use SAML 2.0 for enterprise SSO
Why:
- It’s the most universally supported option across both Google Workspace and Microsoft Entra ID.
- It’s the easiest way to support customer-managed identity providers in a B2B SaaS product.
- It fits common enterprise buying/security requirements.
Also support OIDC/OAuth 2.0 if you can
If you’re building a modern app, it’s often worth supporting OpenID Connect as well, because:
- It’s simpler to implement than SAML.
- It works well for modern apps and APIs.
- Microsoft and Google both support it.
But if you need a single answer for enterprise customer SSO compatibility, SAML 2.0 is the best baseline.
Practical recommendation
For a SaaS product, the usual pattern is:
- Primary enterprise SSO: SAML 2.0
- Optional modern auth: OIDC
- User lifecycle provisioning: SCIM 2.0 if you want automatic user provisioning/deprovisioning
What I’d choose
If you’re asking what to implement first:
- SAML 2.0
- SCIM 2.0
- Add OIDC if you want a smoother/modern auth path or mobile/API support
Important caveat
If your app is only used by your own internal users, then use:
- Google Workspace + OIDC
- or Azure AD + OIDC
But for customer-facing SaaS with mixed enterprise customers, SAML is the most interoperable choice.
If you want, I can also give you:
- a decision matrix for SAML vs OIDC,
- a recommended auth architecture for SaaS multi-tenant SSO,
- or which IdP features matter most for Google Workspace and Entra ID.