> ## Documentation Index
> Fetch the complete documentation index at: https://docs.airmdr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Google SSO Set-up and Configuration

> AirMDR supports Google single sign-on to authenticate users for access to the AirMDR application.

### Overview

AirMDR supports SAML 2.0 Single Sign-On (SSO) with Google Workspace so your users can authenticate to AirMDR using their Google identities. This centralizes access control, reduces password sprawl, and enables security controls such as MFA and conditional access policies managed in Google Admin.

### Pre-requisites

<Tip>
  * Google Workspace **Super Admin** access to Google Admin Console.
  * AirMDR **Super Admin** access.
  * Decide which users/OUs should be enabled for this SSO app.
</Tip>

### SSO Set-up & Configuration

<Steps>
  <Step title="Create a Custom SAML app in Google">
    1. Go to [Google Admin](https://admin.google.com/).
    2. Sign in with an admin account.
    3. In the left-hand navigation pane, select **Apps → Web and mobile apps**.

           <img src="https://mintcdn.com/airmdr/2cTyO6HkJVzkBCTh/images/GoogleSSO1.png.png?fit=max&auto=format&n=2cTyO6HkJVzkBCTh&q=85&s=920518c2f889635cebb10416ec9f47c2" alt="Google SSO1 Png Pn" width="689" height="631" data-path="images/GoogleSSO1.png.png" />
    4. Add Custom SAML app
       1. Click **Add app → Add custom SAML app**

              <img src="https://mintcdn.com/airmdr/2cTyO6HkJVzkBCTh/images/GoogleSSO2.png?fit=max&auto=format&n=2cTyO6HkJVzkBCTh&q=85&s=6d25eb0c2591dcaa02178dbfdaddce4e" alt="Google SSO2 Pn" width="839" height="283" data-path="images/GoogleSSO2.png" />
       2. Provide a name to the application

          Example: **app\_airmdr\_com** (logo optional)
       3. Click **Continue**.

              <img src="https://mintcdn.com/airmdr/iW08WKudhr5T7hT6/images/GoogleSSO3.png?fit=max&auto=format&n=iW08WKudhr5T7hT6&q=85&s=5a94148d21fde1bd53fa3f1810f5980e" alt="Google SSO3 Pn" width="1186" height="839" data-path="images/GoogleSSO3.png" />
    5. Collect IdP details

           <Check>
             Copy and securely save the **Identity Provider (IdP)** details, you’ll paste these into AirMDR later
           </Check>

       * From the **Google IdP Information** screen, **save** the following:
         * **SSO URL (IdP SSO URL)**\
           `https://accounts.google.com/o/saml2/idp?idpid=<code>`
         * **Entity ID (Issuer)**\
           `https://accounts.google.com/o/saml2?idpid=<code>`
         * **Certificate** (download the X.509 certificate).

               <Note>
                 If the downloaded Google certificate has a file extension of `.cert`.\
                 Users must ensure the file extension is changed to `.crt` before uploading in to the AirMDR.

                 <u>For example</u>: `Google.crt`
               </Note>

               <img src="https://mintcdn.com/airmdr/iW08WKudhr5T7hT6/images/GoogleSSO4.png?fit=max&auto=format&n=iW08WKudhr5T7hT6&q=85&s=9b64fbb669a8a7575c58ffb2947af8d7" alt="Google SSO4 Pn" width="933" height="519" data-path="images/GoogleSSO4.png" />
    6. **Service Provider (SP) details for AirMDR**
       * Enter the following **exact values** when prompted:
         * **ACS URL**: `https://app.airmdr.com/airmdrapi/sso/acs`
         * **Entity ID (SP)**: `https://app.airmdr.com/airmdrapi`
       * Click **Continue** → **Finish**.

             <img src="https://mintcdn.com/airmdr/iW08WKudhr5T7hT6/images/GoogleSSO5.png?fit=max&auto=format&n=iW08WKudhr5T7hT6&q=85&s=f9ba0ef9b74f605daea322411dbb8b55" alt="Google SSO5 Pn" width="1072" height="771" data-path="images/GoogleSSO5.png" />
    7. **Turn the app ON for users**
       * In the apps list, click the SAML app you just created (e.g., *app\_airmdr\_com*) to open its settings page.
       * **Enable user access**
         1. In the app’s overview page, locate **User access**

                <img src="https://mintcdn.com/airmdr/iW08WKudhr5T7hT6/images/GoogleSSO6.png?fit=max&auto=format&n=iW08WKudhr5T7hT6&q=85&s=0df3f8d0e640836f4679c005ccd84176" alt="Google SSO6 Pn" width="1593" height="486" data-path="images/GoogleSSO6.png" />
         2. Click the **▾** (dropdown) next to **User access**, switch it **ON for everyone**
         3. Click **SAVE** (mandatory to save the changes made).

                <img src="https://mintcdn.com/airmdr/iW08WKudhr5T7hT6/images/GoogleSSO7.png?fit=max&auto=format&n=iW08WKudhr5T7hT6&q=85&s=25eae37490ae90ae6d29abfea87a67fa" alt="Google SSO7 Pn" width="1593" height="530" data-path="images/GoogleSSO7.png" />
  </Step>

  <Step title="Configure SSO in AirMDR">
    1. Sign in to [AirMDR](https://app.airmdr.com) with your credentials.
    2. Open your organization
       * **Admin → Organizations List** → click your **Org Name**.

             <img src="https://mintcdn.com/airmdr/EitY_4oy_K99KXt7/images/GoogleSSO13.png?fit=max&auto=format&n=EitY_4oy_K99KXt7&q=85&s=302d991906c3ada2b575eb1910ad4559" alt="Google SSO13 Pn" width="754" height="1650" data-path="images/GoogleSSO13.png" />
    3. **Edit SSO settings**
       1. In **SSO Settings**, click **Edit.**

              <img src="https://mintcdn.com/airmdr/EitY_4oy_K99KXt7/images/GoogleSSO9.png?fit=max&auto=format&n=EitY_4oy_K99KXt7&q=85&s=b7342125bb9963dd1e0e2e384813f447" alt="Google SSO9 Pn" width="1220" height="456" data-path="images/GoogleSSO9.png" />
       2. Choose **Yes, New Config**.

              <img src="https://mintcdn.com/airmdr/EitY_4oy_K99KXt7/images/GoogleSSO10.png?fit=max&auto=format&n=EitY_4oy_K99KXt7&q=85&s=580e23ee5e105356bc6c0bbc377ef877" alt="Google SSO10 Pn" width="978" height="520" data-path="images/GoogleSSO10.png" />
    4. **Complete the fields** (paste values collected in the **Google IdP Information** screen)
       * **Identity Provider**: **Custom**
       * **Certificate**: **Upload** the X.509 certificate downloaded from Google
       * **SSO endpoint (IdP SSO URL)**: `https://accounts.google.com/o/saml2/idp?idpid=<code>`
       * **Use Issuer ID**: **Yes**
       * **Issuer ID (IdP Entity ID)**: `https://accounts.google.com/o/saml2?idpid=<code>`
    5. Click **Submit**.

           <img src="https://mintcdn.com/airmdr/EitY_4oy_K99KXt7/images/GoogleSSO15.png?fit=max&auto=format&n=EitY_4oy_K99KXt7&q=85&s=df3da2401ffcff132262fc7fde7073b9" alt="Google SSO15 Pn" width="1026" height="1268" data-path="images/GoogleSSO15.png" />
  </Step>
</Steps>

## Field mapping (quick reference)

| Where                     | Field label            | Value                                                  |
| :------------------------ | :--------------------- | :----------------------------------------------------- |
| **Google → IdP info**     | **SSO URL**            | `https://accounts.google.com/o/saml2/idp?idpid=<code>` |
| **Google → IdP info**     | **Entity ID (Issuer)** | `https://accounts.google.com/o/saml2?idpid=<code>`     |
| **Google → IdP info**     | **Certificate**        | Download X.509 certificate                             |
| **Google → SP details**   | **ACS URL**            | `https://app.airmdr.com/airmdrapi/sso/acs`             |
| **Google → SP details**   | **SP Entity ID**       | `https://app.airmdr.com/airmdrapi`                     |
| **AirMDR → SSO Settings** | **Identity Provider**  | **Custom**                                             |
| **AirMDR → SSO Settings** | **SSO endpoint**       | Paste **SSO URL** from Google                          |
| **AirMDR → SSO Settings** | **Use Issuer ID**      | **Yes**                                                |
| **AirMDR → SSO Settings** | **Issuer ID**          | Paste **Entity ID (Issuer)** from Google               |
| **AirMDR → SSO Settings** | **Certificate**        | Upload the Google X.509 certificate                    |

## Validation

* In Google Admin, ensure **User access = ON** for the target OU/group.
* In AirMDR, after **Submit**, log out and initiate login via **Sign in with SSO** (or use your org-specific SSO link if provided).
* If sign-in fails, double-check:
  * Typos in **SSO endpoint** and **Issuer ID** (must match Google exactly).
  * Certificate uploaded is the **current** Google IdP certificate.

<Frame>
  <Icon icon="rocket-launch" />  Hurray! You are Logged in Successfully
</Frame>
