Sophos Firewall: Set up Google Workspace as an IdP
Google Workspace is now a support identity provider (IdP) in Sophos Firewall version 23 and later, allowing users to authenticate using their Google credentials. Learn about the new IdP integrationβs capabilities, limitations, and the set up steps.
**Captions are generated by machine translation may contain errors**
------
*Video Chapters*
00:00 Intro
00:17 Overview
00:55 Prerequisites
01:29 Google Workspace as an IdP
02:19 Set up Google Cloud Console
03:04 Add service account
03:30 Add JSON private key
03:47 Set up Google Admin Console
04:36 Add new IdP server
05:00 Configure redirect URIs
06:03 Verify hostname
06:17 Import groups
07:00 Enable IdP in services
07:18 Verify IdP integration
07:56 View login activity
08:18 Verify user mapping
08:41 Outro
------
*Relevant Documentation*
β
Enable Google Admin SDK API
https://console.cloud.google.com/apis/library/admin.googleapis.com
π Access Google OAuth client
https://console.cloud.google.com/apis/credentials
β
Set βNot enforced β for iam.managed.disableServiceAccountKeyCreation
https://console.cloud.google.com/iam-admin/orgpolicies
π Access Google service account
https://console.cloud.google.com/iam-admin/serviceaccounts
π Configure domain-wide delegation
https://admin.google.com/ac/owl/domainwidedelegation
π OpenID discovery endpoint
https://accounts.google.com/.well-known/openid-configuration
π Redirect URIs (OAuth client)
https://console.cloud.google.com/apis/credentials
π‘ Required delegation scopes (read-only)
https://www.googleapis.com/auth/admin.directory.group.readonly
https://www.googleapis.com/auth/admin.directory.group.member.readonly
https://www.googleapis.com/auth/admin.directory.rolemanagement.readonly (only if role-based administration is required)
------
π‘ Ask questions and get expert answers in the Sophos Community. https://community.sophos.com
βΆοΈ Watch more expert video tutorials. https://techvids.sophos.com
π Follow and subscribe. https://www.youtube.com/@SophosCybersecurity
------