Configuring Single Sign-On (SSO) with Google
This article explains how to configure the SAML SSO integration of Google Workspace with Quickpass.
Prerequisites
- Google Workspace/GSuite configured with the user accounts that will be used for accessing Quickpass..
- Primary or Super Role in Quickpass
- SuperAdmin role for Google
- All of your Technicians configured in Login Management in Quickpass will need an account in Google with exactly the same email address.
Manual - https://support.getquickpass.com/hc/en-us/articles/360040722434-How-to-Setup-Quickpass-Dashboard-Logins
Bulk Import - https://support.getquickpass.com/hc/en-us/articles/4411037813783-How-to-Bulk-Import-Quickpass-Dashboard-Logins- Note the Primary and Super Roles will still be able to login with their Quickpass Account username and password to allow access in the case of challenges with the SSO.
- Initial configuration steps as per https://support.getquickpass.com/hc/en-us/articles/4419178721559-Setting-up-Dashboard-Logins-for-SSO-SAML-
- We suggest creating a specific Google Security Group to use and adding the corresponding Quickpass Login Role email addresses to this group
- Before turning this feature on, log in to your Quickpass account twice - once in a regular browser and once in an incognito/private window or another browser. This is to ensure that you are still logged in to your account if you get locked out in the other window.
Instructions
- Login to the Google Admin page with your Super Admin role.
https://admin.google.com - Click on Apps -> Web and mobile Apps
- Click on the Add App dropdown and select Add custom SAML app
- Type in a Name for the App - (we suggest Quickpass SSO)
- Type in a Description if you wish.
- Add the App Icon if you wish (you can download this image file to use by right clicking and selecting Save Image As)
- Click Continue
- On the SSO for SAML Apps configuration page, copy and paste these values into the appropriate section of the Quickpass Dashboard for setting up Authentication Options (https://support.getquickpass.com/hc/en-us/articles/4419178721559-Setting-up-Dashboard-Logins-for-SSO-SAML-)
- Click Save on the Quickpass Dashboard
- Back on the Google Custom SAML app screen click Continue
- Populate one of these values into the Google Page depending on your Quickpass Tenant Location
- ACS URL - Assertion Consumer Service (ACS) URL
NA or Oceania https://admin.getquickpass.com/api/auth/sso/login/callback EU https://eu-admin.getquickpass.com/api/auth/sso/login/callback
- Entity ID - Copy and Paste the value shown on the Quickpass Dashboard
- Start URL - Populate one of these values into the Google Page depending on your Quickpass Tenant Location
NA or Oceania https://admin.getquickpass.com EU https://eu-admin.getquickpass.com - Put the check box in the "Signed Response" box.
- NameID - Change the values to match this screen
- Click Continue
- ACS URL - Assertion Consumer Service (ACS) URL
- On the Attributes screen click ADD MAPPING button and populate the values to look like this
- Click Finish
- Once this configuration is completed you will be taken to a page in the Google Admin screen that looks like this.
- Change the User Access options to match your desired Google Security Group you configured.
Testing
- In another browser or an Incognito/Private Browser Log open the Quickpass Dashboard
NA or Oceania https://admin.getquickpass.com EU https://eu-admin.getquickpass.com - Enter the Email address of your login and click Continue with SSO
- You should be prompted to log in with the Google Credentials for the account you are testing with.
- Login with the Credentials for the Test account
- Approve the Google Authenticator or other approved login method
- You should be taken to the Quickpass Dashboard Customers list.
- Login with the Credentials for the Test account
Comments
0 comments
Please sign in to leave a comment.