I was able to look into your question(s) and found that you can set up G-Suite SSO with SAML for Azure. I'll post the related links below. When it comes to the attribute mapping you can follow the SAML - Steps, link below for more details. However, I'll also post the screenshots below for your reference.
- Your Google Cloud (G Suite) Connector application expects the SAML assertions in a specific format, which requires you to add custom attribute mappings to your SAML token attributes configuration. The following screenshot shows an example for this. The default value of Unique User Identifier is user.userprincipalname but Google Cloud (G Suite) Connector expects this to be mapped with the user's email address. For that you can use user.mail attribute from the list or use the appropriate attribute value based on your organization configuration.
- On the Set up single sign-on with SAML page, in the SAML Signing Certificate section, find Certificate (Base64) and select Download to download the certificate and save it on your computer.
- On the Set up Google Cloud (G Suite) Connector section, copy the appropriate URL(s) based on your requirement.
----------
Links:
Azure AD SSO integration with G Suite - Overview