OpenID Connect SSO with Google Workspace

If your organization uses Google Workspace (formerly G Suite) you can seamlessly integrate Google authentication into Infosec IQ and leverage the “Sign in with Google” function on the Infosec IQ login page. This article explains how to configure Google SSO in an Infosec IQ account as well as how to configure an account with an imported SSO configuration.

Infosec IQ account with no existing SSO

If your Infosec IQ account has never been configured to use SSO, you can enable Google SSO by doing the following:

  1. Log into Infosec IQ and navigate to the settings gear > User Settings. This will take you to your user profile on account.infosecinstitute.com.
  2. In the Organization section, click on Manage.
  3. Under Email domains, click Add:
  4. The Create Email Domain settings will open up. Enter your Google Workspace domain into the Domain field and save. The Ignore Variant Emails? will usually be set to No.
    CreateEmailDomain
  5. Click to the Security tab of your organization, and click Edit in the Security Policy section.
  6. In the Edit Security Policy settings, enable Require all users to use SSO and save.
    Edit_Sec_Policy

After making these changes, admins will be redirected to Google for authentication either by clicking Sign in with Google or by entering their email address and clicking Next.

SSO_Login

When a new admin is invited to Infosec IQ, they will only be able to create their account by authenticating through Google.

Account_Setup_Google_SSO

Note: Learners will not be required to authenticate to access campaigns and training unless the Learner Authentication setting is enabled.

Updating an Infosec IQ account with an imported Google SSO conection

If your Infosec IQ account was configured to use Google for SSO prior to the rollout of Infosec Accounts, you will see a message on your Infosec Accounts profile indicating that you have an imported configuration:

Your existing SSO configuration will continue to work, though you will not be able to utilize the Sign in with Google feature. Imported configurations cannot be deleted until a new configuration has been activated, so to migrate we’ll need to create an empty SSO configuration and then remove both. Follow these steps to update your Google configuration:

  1. Click Create in the Single sign-on section shown above.
  2. The Setup single sign-on settings will open up. Click Save without making any changes to the configuration. This will create an empty SSO configuration.
  3. You’ll be returned to the main profile page after saving. On your newly-created SAML configuration, select Actions > Edit.
  4. Enable Activate this config and click Save.
    activate_this_config
  5. Once this step is complete, you will now see both an active SAML connection and an inactive connection called Migrated (from IQ).
  6. Remove both configurations by selecting Actions > Delete.
  7. Perform the steps in the first section of this article Infosec IQ account with no existing SSO.