Failed: federation between Google Workspace and Microsoft Entra ID

Ammar Aganovic 60 Reputation points
2023-11-24T08:54:09.58+00:00

Hi!

I'm trying to implement "federation between Google Workspace and Microsoft Entra ID" following this link:
https://video2.skills-academy.com/en-us/education/windows/configure-aad-google-trust
but I keep getting the error :

Get-MgDomainFederationConfiguration_List: Unable to find target address

Status: 500 (InternalServerError)
ErrorCode: InternalServerError
Date: 2023-11-24T08:47:52

Headers:
Transfer-Encoding             : chunked
Vary                          : Accept-Encoding
Strict-Transport-Security     : max-age=31536000
request-id                    : aa60df35-81be-41ad-81ec-eed6e2cee7ce
client-request-id             : cff7f6ae-af41-4b29-83ad-6b3cb266e6fd
x-ms-ags-diagnostic           : {"ServerInfo":{"DataCenter":"Switzerland North","Slice":"E","Ring":"5","ScaleUnit":"002","RoleInstance":"ZR2PEPF000000D0"}}
Date                          : Fri, 24 Nov 2023 08:47:52 GMT

Any idea what am I doing wrong or how to debug?

Active Directory Federation Services
Active Directory Federation Services
An Active Directory technology that provides single-sign-on functionality by securely sharing digital identity and entitlement rights across security and enterprise boundaries.
1,259 questions
{count} votes

Accepted answer
  1. Akhilesh 9,515 Reputation points Microsoft Vendor
    2023-12-02T07:25:20.5233333+00:00

    @Ammar Aganovic
    Thank you for posting your query on Q&A.

    I’m glad that you have some progress with the federation setup. the primary domain in Google Workspace is the one that is used to exchange the SAML token with Microsoft Entra ID. You need to make sure that the primary domain in Google Workspace matches the domain that you want to federate in Microsoft Entra ID.

    If you have multiple domains in Google Workspace, you can change it to primary domain. Post which you would need to federate the new primary domain with Microsoft Entra ID. However, changing the primary domain might affect other Google services kindly check the documents from Google Workspace.
    Auto-provisioning of users from external sources like Google to Entera ID did not require any license and it includes identity and access management free features.

    However, features such as conditional access policies, self-service password reset, and other security reporting, may require licenses.

    Users who need to use Power BI or Office applications will require additional licenses assigned to them in Entra ID.
    I hope this answer helps! If you have any further questions, please feel free to ask.

    Thanks,

    Akhilesh.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.