google workspace saml error app_not_configured
For Google Workspace admins and agents setting up SAML SSO. Use when logins fail with app_not_configured. Not for certificate or attribute-mapping errors.
Fix Google Workspace SAML error appnotconfigured
TL;DR
appnotconfigured means Google Workspace received a SAML request for an app that has no SAML configuration, or the entity ID in the request does not match the configured one. Open the SAML app in the Admin console and compare the entity ID with what the app sends. Nine times out of ten the app is pointing at the wrong SSO URL or entity ID.
The error
Error: app_not_configured
This app is not configured for SAML single sign-on in Google Workspace.Use this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=google workspace saml error app_not_configured"Fix it
Step 1: Open the SAML app in Google Admin
Google Admin -> Apps -> Web and mobile apps -> [your app], and confirm it exists and is ON for the failing user.Expected: The app is listed, enabled, and assigned to the user's org unit.
Step 2: Compare the entity ID
In the app's Service provider details, note the Entity ID. Compare it with the entity ID your app actually sends in the AuthnRequest.Expected: They match exactly. A trailing slash mismatch is enough to trigger appnotconfigured.
Step 3: Check the SSO URL the app uses
Confirm the app points at the SSO URL Google shows for this SAML app, not a generic or old one.Expected: The app's IdP SSO URL matches the Admin console value.
Step 4: Re-download the IdP metadata
Download fresh IdP metadata from the Google Admin console and import it into the app, then retry login.Expected: Login proceeds past Google instead of landing on the error page.
Step 5: Test with a direct app URL
Start the login from the app's login page (SP-initiated) rather than the Google app launcher.Expected: SP-initiated login works, which confirms the entity ID mapping is now right.
When this applies
- Google Workspace SAML logins fail with appnotconfigured
- You just set up a custom SAML app in Google Admin
- Logins work for some apps but not this one
When it doesn't
- The error is a certificate or signature error (different validation stage)
- The app is not in the Admin console at all (add it first)
- You use Google OIDC sign-in rather than SAML
Compatibility
Google Workspace SAML apps (custom SAML). Admin console UI as of 2026.
Variant phrasings
google saml app not configured error
Same error. The entity ID check fixes most cases; the SSO URL check fixes most of the rest.
appnotconfigured google workspace sso
If it broke after working, someone edited the SAML app config. Check the Admin audit log for changes.
saml error 400 appnotconfigured
The 400 wrapper is the same condition. Fix the entity ID or SSO URL mapping.
Why it happens
Google looks up the SAML app by the entity ID in the incoming AuthnRequest. If nothing matches, or the matching app is off for that user, it returns appnotconfigured. This is a routing failure, not a crypto failure: the request never reaches signature validation because Google does not know which app it belongs to.
Edge cases
- Multiple SAML apps for the same vendor collide when they share an entity ID; keep them unique
- Org unit scoping can make the app ON for you but OFF for the failing user; check assignment
- After editing a SAML app, Google can take several minutes to propagate; retest after a short wait
If it still fails
- Capture the exact timestamp, the failing username, and the full error from the IdP system log before changing anything else.
- Reproduce with a single test user so you are not debugging a crowd.
- Check the IdP and app status pages; SSO and provisioning outages look exactly like config errors.
- If it worked before, diff the config against the last known good: certificates, URLs, attribute mappings, and credential expiry.
- Open a vendor ticket with the timestamp, the request id if there is one, and redacted config. Never send secrets or private keys.
Prevention
- Track certificate and credential expiry with alerts, not memory.
- Run a synthetic login per SSO app daily so breakage pages you, not a user.
- Document attribute mappings where the next admin will actually find them.
- Test provisioning with a single user before bulk changes.
- Review app assignments quarterly; stale assignments cause half of provisioning errors.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_R4KpGhqdvbmkNE5QPCmHkA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.