Follow

Integrating with Google Workspace for Education Fundamentals

The Process in a Nutshell

Here's a summary of what you'll need to do to get your instance of Populi integrated with your Google Workspace for Education Fundamentals (or whatever it's called this week) account using Single Sign-On.

  1. Create a Google Super Administrator Account for Populi (e.g. populi@schooldomain.edu).
  2. Set up an SPF record to allow Populi to send email on behalf of your .edu domain.
  3. Confirm that all Google users have matching Populi user accounts. For example, Populi user jimbob23 must also be Google user jimbob23@school.edu. If usernames do not match up exactly, those users won't be able to log in after the integration!
  4. Notify your users of the upcoming changes:
    • They will now log in to Google with their Populi password.
    • They will need to update passwords and possibly other settings in desktop clients like Outlook and Thunderbird.
    • Set up a time with us to flip the switch (we really don't recommend the middle of a workday for this!). Depending on your email migration plan, you may need to point your MX records at Google right before we make the change.

Give Populi an Administrator Account

Once you've activated your free GWEF account, log in to the Apps control panel and create a Super Administrator account for Populi (e.g. populi@schooldomain.edu); send the welcome email to support@populiweb.com. Populi uses this account to automate user-creation (that is, add email accounts in Google)—so make sure it has Super Administrator-level access!

Check your SPF DNS Record

Next, to ensure proper email delivery, have your IT staff ensure that your domain has an SPF DNS Record that looks something like this:

v=spf1 a mx include:email.populi.co include:_spf.google.com ~all

Refer to this article for the details.

Notify Populi Support

Once you've completed the previous steps, let us know the Populi-specific username and password by contacting Populi Support. Please allow a few days for Populi Support to accomplish the steps below. In addition to the below steps, Populi Support also does an analysis of your GWEF setup and makes sure that the integration will be successful. Google regularly changes the way their consoles are designed which often result in having to do more research to make sure the setup is successful. Below are our internal instructions to ourselves, presented to you so you know which settings we'll be changing and why:

In https://admin.google.com...

  1. Search for Set up single sign-on (SSO) with a third party IdP and click on the top result.
  2. Click Set up single sign-on (SSO).
  3. We'll upload a verification certificate to ensure secure communication between Google and Populi. We'll also change the following settings:
    • Sign-in page URL: https://yourcollegedomain.populiweb.com/router/saml/idp/receive
    • Sign-out page URL: https://yourcollege.populiweb.com/router/logins/logout
    • Change password URL: https://yourcollege.populiweb.com/router/myprofile/settings/security
    • Check Use a domain specific issuer

Then, in https://console.developers.google.com...

  1. We'll create a new Project called Populi API. (You may need to enable the developer console in the admin console. Search for Google Developers Console or Google Cloud Platform.)
  2. We'll then enable the following settings:

    • Admin SDK
    • Gmail API
    • All Quotas: we'll set the per-user limit to the maximum value
    • Service Accounts: We'll create a new account named Populi Service Account, set the Role to Project Owner, and check the boxes for Furnish a new private key and Enable Google Domain-wide Delegation.
  3. The Service Account JSON key should automatically download (this might only work in Google Chrome).

Then, over in Populi...

  1. In Account > Account Settings > Integrations > Google JSON Private Key, paste that JSON key you just downloaded.
  2. In Populi > Account > Account Settings > Single Sign-On (IdP), set Should other applications be allowed to authenticate against Populi? to Always let other applications authenticate.

Then back over in https://admin.google.com...

  1. Go to Security > API Controls > App access control > Manage Domain Wide Delegation.
  2. Set the Client Name to the client_id as specified in the JSON private key you just downloaded.
  3. Set the Scopes to:
                    
                    https://www.googleapis.com/auth/calendar,
                    https://www.googleapis.com/auth/admin.directory.user,
                    https://www.googleapis.com/auth/gmail.settings.basic,
                    https://www.googleapis.com/auth/gmail.labels
    
                

Activate the Integration

Once these settings are complete, we will confirm a time with you to activate the integration.

  1. You'll go to admin.google.com > Security > SSO With Third-party IDPs.
  2. Check next to Set up SSO with third-party identity provider.
  3. Click Save. This turns on the SSO integration on the Google side.
  4. We will simultaneously activate a similar setting internally at the Populi side.

Once the integration is activated, any previous Google passwords will no longer work—it will instead require a valid Populi username and password. Depending on your preference, we may change some Populi usernames to be the same as Google usernames (or the other way around), but that should be fairly rare.

Let your users know about this several days before the integration is activated. Explain to them how their login process to Google will change.

What happens in Populi now?

Read more about this in Questions about Google.

Users

You can add and suspend user accounts.

When creating a new user, you'll now have the option to create a Google account with the same username. Your users can now log in to Google with their Populi credentials; those same credentials can even connect a desktop email client like Thunderbird or Outlook to GMail.

Email

Once logged into Populi, when you (or any of the users at your institution) click Email it will open the Gmail account you have through your institution.

Composing Email in Populi

There are some limitations with how the Email integration works. To take advantage of some of the advanced Email features in Populi, Populi still uses the native Compose Email view. It opens when you click Email links within Populi (like "Email This Section", "Email Staff", etc.). Messages sent from Populi will show up in a new Sent From Populi folder in Gmail; nor will messages sent from Gmail appear anywhere in Populi.

Use GMail for personal or unofficial correspondence.

Use Populi for official, school-related correspondence, or anything that requires a public record, such as:

  • Anything you want to appear on a person's Activity Feed
  • Mailing Lists or One-Time Lists
  • Emailing students in a course, or groups of people found in Data Slicer Reports, or any other group-emailing you need to do
Was this article helpful?
4 out of 6 found this helpful
Submit a request

9 Comments

  • 0
    Avatar
    Steve Sutcliffe

    Perhaps this changed with the last few updates, but I'm unable to find Settings > Integrations

  • 0
    Avatar
    Lindsay Luecht

    Does Populi integrate with Google Docs?

  • 0
    Avatar
    Brendan O'Donnell

    Lindsay,

    It doesn't integrate in terms of functionality (i.e. embedding a Google word doc into a Lesson), but if you have Apps for Education and use Docs as part of that suite, your people would access it via signing in through Populi.

  • 0
    Avatar
    Shawn Maggard

    We have two mail domains, one is user@students.hcu.edu and the other is user@hcu.edu which helps us distinguish from a faculty or staff account from a student account. Is it possible to integrate both into Populi and keep the domain and subdomain?

  • 0
    Avatar
    Mark Ackerman

    Shawn,

    Unfortunately, Populi can only integrate with Google Apps for Education on one domain, so you would have to pick either hcu.edu or students.hcu.edu. This is a case of Populi being more strict than what Google allows. Google allows domain aliasing and the ability to have separate domains. Here's a link to Google's Help Article on the subject of having multiple domains:

    http://www.google.com/support/a/bin/answer.py?answer=182078

    Despite Google's flexibility, we recommend having staff, faculty, and students all on the same root domain. You would never want to have johndoe@students.hcu.edu be a different person than johndoe@hcu.edu, since that would inevitably result in the staff member getting emails intended for the student, and perhaps vice-versa, if the sender has both addresses in his auto-complete database (Hello, FERPA nightmare). If you consolidated down to one domain, you could have students.hcu.edu as a domain alias in Google Apps for mail delivery continuity.

    I understand that you probably have additional reasons for wanting the students.hcu.edu subdomain, but unfortunately provisioning multiple, separate domains via Populi isn't an option right now.

    Thanks, Mark

  • 0
    Avatar
    Carlos Marin

    Would Populi be able to ask a school using Google Apps to talk to us regarding their experience with this? We'd like to explore it.

  • 0
    Avatar
    Mark Ackerman

    Hey Carlos, 

    I'll see if I can get someone in touch with you.  I'll follow up by email.

    Thanks!

    Mark

  • 0
    Avatar
    Chris Chiacchierini

    We already had students, staff and faculty using GA before we went live with Populi. We are just starting up with Populi and have not yet toggled our users to "Is A User" in Populi. When making the transition, the default username/email doesn't match the user's alternate email (the GA email address that was imported from our old system) in the "Edit User Access" pop up box. This would seem to indicate that we would have to manually enter each user's GA prefix to assure a match. Is there a way to have the pop up box pull the alternate email into the username/email field automatically? Manual entry would take time during which many users would not be able to access Google Apps.

  • 0
    Avatar
    Mark Ackerman

    Hi Chris,

    Typically, in a situation like yours, you would want to create Populi accounts for all of your GA users before integrating GA with Populi. We could create all of your Populi student user accounts in bulk based on the alternate email address, as well. However, the nomenclature for default usernames is fixed and not customizable at this time. I'll follow up with you in a support request so we can go through the details.

    Thanks!

    Mark

Article is closed for comments.