> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Single Sign-On with Google Workspace (Native)

> Configure native Google Workspace SSO for Iru Endpoint using OAuth2 and OpenID Connect. Enable one-click sign-in for admins with Google credentials.

### About Google Workspace Native Integration

Google Workspace Native integration in Iru Endpoint lets you set up native Google Workspace integration for SSO. Users authenticate using their Google Workspace credentials without requiring custom SAML configuration.

#### How It Works

When users attempt to access Iru Endpoint, they're redirected to Google Workspace for authentication using OAuth2/OpenID Connect protocols. After successful authentication, Google Workspace sends an access token back to Iru Endpoint, which validates the user's identity and grants access to the platform.

<Warning>
  If you're [requiring authentication with Automated Device Enrollment](/en/endpoint/enrollment/configure-require-authentication-for-enrollment) for iOS enrollments and using Google Workspace as your identity provider, the Single Sign-On entry must be created [using Custom SAML](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on-with-google-workspace-saml). The built-in Google Workspace integration is not supported.
</Warning>

### Prerequisites

Before you begin, ensure you have:

* [Access to the Iru Endpoint Web App](/en/endpoint/getting-started/foundation/admins-and-access) as an Admin or Account Owner
* A Super Admin account in Google Workspace to complete the Google Workspace configuration steps

<Tabs>
  <Tab title="Iru Web App Configuration">
    ### Configuring Iru Endpoint Connection

    Follow these steps to configure the connection in Iru:

    <Steps>
      <Step title="Navigate to the Account Menu Button">
        In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu).
      </Step>

      <Step title="Access Authentication Settings">
        Click the **Access** option in the menu.

        <Frame>
          <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-access.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=466fdf5fb47efd6bab8b450a5a1e8302" alt="Screenshot of the account menu with Access option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-access.png" />
        </Frame>
      </Step>

      <Step title="Select Admin and Authentication">
        Select the **Admin and authentication** tab (selected by default) and scroll down to **Authentication methods**.
      </Step>

      <Step title="Add Authentication Method">
        Click **+ Authentication method**.
      </Step>

      <Step title="Enter Display Name">
        Enter a display name for the SSO Connection.
      </Step>

      <Step title="Select Google Workspace">
        Select **Google Workspace**.
      </Step>

      <Step title="Create Connection">
        Click **Create**.
      </Step>

      <Step title="Copy Redirect URL">
        Copy the **Redirect URL** into a text document for later use. You'll need this for the Google Workspace configuration.

        <Frame>
          <img src="https://mintcdn.com/iru/tdUGxmJrLWpxmPfN/assets/media/images/google-native_09-32-18.png?fit=max&auto=format&n=tdUGxmJrLWpxmPfN&q=85&s=8e9eb7c658d0c596801cb59a4e78a609" alt="Iru Endpoint SSO Redirect URL to copy for Google Workspace" width="1318" height="520" data-path="assets/media/images/google-native_09-32-18.png" />
        </Frame>
      </Step>

      <Step title="Keep Tab Open">
        Keep the Iru Web App configuration modal open, then switch to the Google Workspace Configuration tab to continue.
      </Step>
    </Steps>

    <Note>
      After completing the Google Workspace configuration, return here to finish setting up the SSO connection in Iru Endpoint. You'll need the Client ID, and Client secret you copied from Google Workspace.
    </Note>

    Follow these steps to complete the configuration:

    <Steps>
      <Step title="Enter Google Workspace Domain">
        Enter your **Google Workspace domain** from Google Workspace.
      </Step>

      <Step title="Paste Client ID">
        Paste the **Client ID** you copied from Google Workspace into the **Client ID** field.
      </Step>

      <Step title="Paste Client Secret">
        Paste the **Client secret** you copied from Google Workspace into the **Client secret** field.

        <Frame>
          <img src="https://mintcdn.com/iru/tdUGxmJrLWpxmPfN/assets/media/images/google-native_10-05-01.png?fit=max&auto=format&n=tdUGxmJrLWpxmPfN&q=85&s=ce0bce036daf3da619b3c8aa25745d8c" alt="Iru Endpoint Client secret field for Google Workspace" width="2118" height="1646" data-path="assets/media/images/google-native_10-05-01.png" />
        </Frame>
      </Step>

      <Step title="Save Configuration">
        Click **Save**.
      </Step>

      <Step title="Confirm Setup">
        Your connection has now been successfully configured and may be enabled and tested.
      </Step>
    </Steps>

    ### Allow for Tenant Authentication

    Once you have configured the OIDC connection in Iru Endpoint and your identity provider, you can allow its use for tenant authentication. For step-by-step instructions, please refer to the **Allowing Tenant Authentication and Managing Connections** section in our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on).

    ### Limit Authentication to Domain

    When configuring the OIDC connection, you can optionally limit authentication to one or more domains. This can be useful when the SSO connection could authenticate to multiple domains. You can limit the authentication to your Iru tenant to a subset of the available domains.

    ### Enforcing Single Sign-On

    Once you have configured at least one Single Sign-on connection, you can disable Passkey, Google Social, and Microsoft Social connections. Disabling these connections will disable the ability for Iru Endpoint administrators in your tenant to authenticate via those methods. Please refer to our [Single Sign-on support article](/en/endpoint/integrations/single-sign-on-integrations/single-sign-on) for step-by-step instructions.
  </Tab>

  <Tab title="Google Workspace Configuration">
    ### Setting Up Google Workspace Application

    <Note>
      Before starting the Google Workspace configuration, complete the initial setup in the **Iru Web App Configuration** tab to get the Redirect URL. You'll need this value to configure the Google Workspace application.
    </Note>

    Follow these steps to configure your Google Workspace application:

    <Steps>
      <Step title="Access Google Developer Console">
        **Log in** to the Google Developer [API Console.](https://console.developers.google.com/) Then click **Create project**.
      </Step>

      <Step title="Configure Project Details">
        Enter a **Project name**.
      </Step>

      <Step title="Select Organization">
        Select the **Organization** from the dropdown menu.
      </Step>

      <Step title="Select Location">
        Select the **Location**.

        <Frame>
          <img src="https://mintcdn.com/iru/tdUGxmJrLWpxmPfN/assets/media/images/google-native_08-30-58.png?fit=max&auto=format&n=tdUGxmJrLWpxmPfN&q=85&s=54f4d8f6168d88108d525e7efa484cc8" alt="Google API Console project Location dropdown" width="2598" height="874" data-path="assets/media/images/google-native_08-30-58.png" />
        </Frame>
      </Step>

      <Step title="Create Project">
        Click **Create**.
      </Step>

      <Step title="Access Credentials">
        In the sidebar, click **Credentials**.
      </Step>

      <Step title="Configure Consent Screen">
        If this is your first time creating a client ID, you may also be prompted to [configure your consent screen](https://support.google.com/googleapi/answer/6158849#zippy=%2Cuser-consent).

        <Frame>
          <img src="https://mintcdn.com/iru/tdUGxmJrLWpxmPfN/assets/media/images/google-native_08-45-03.png?fit=max&auto=format&n=tdUGxmJrLWpxmPfN&q=85&s=3370df7712a2cd9e0d3d11cd3425bf17" alt="Google consent screen configuration prompt" width="2888" height="1204" data-path="assets/media/images/google-native_08-45-03.png" />
        </Frame>
      </Step>

      <Step title="Create Credentials">
        On the right side of the window, near the top, click **+ Create credentials**.
      </Step>

      <Step title="Select OAuth Client ID">
        From the menu that appears, select **OAuth Client ID**.

        <Frame>
          <img src="https://mintcdn.com/iru/tdUGxmJrLWpxmPfN/assets/media/images/google-native_08-50-16.png?fit=max&auto=format&n=tdUGxmJrLWpxmPfN&q=85&s=de24f6c68f2f98e2bad93052d10646c6" alt="Google Create credentials OAuth Client ID" width="2600" height="972" data-path="assets/media/images/google-native_08-50-16.png" />
        </Frame>
      </Step>

      <Step title="Configure Application Type">
        For "**Application Type**," click the menu and select "**Web application**".
      </Step>

      <Step title="Name OAuth Client">
        In the **Name** field, enter a **Name** for your OAuth client.
      </Step>

      <Step title="Configure Authorized JavaScript Origins">
        For **Authorized JavaScript Origins**, use just the domain section from the Redirect URL you copied from the Iru Web App Configuration (e.g., `https://vpriix.id.iru.com`). This domain is unique to each Iru tenant.
      </Step>

      <Step title="Configure Authorized Redirect URIs">
        For **Authorized redirect URIs**, enter the complete Redirect URL you copied from the Iru Web App Configuration (e.g., `https://vpriix.id.iru.com/federated-auth/oidc/callback`).

        <Frame>
          <img src="https://mintcdn.com/iru/tdUGxmJrLWpxmPfN/assets/media/images/google-native_09-26-03.png?fit=max&auto=format&n=tdUGxmJrLWpxmPfN&q=85&s=c5f3ce845da4a0d0ace07f6ab0d2829b" alt="Single Sign-On with Google Workspace (Native) documentation showing Authorized redirect URIs configuration" width="3090" height="2136" data-path="assets/media/images/google-native_09-26-03.png" />
        </Frame>
      </Step>

      <Step title="Create OAuth Client">
        Click **Create**.
      </Step>

      <Step title="Copy Client ID">
        Copy the text from the **Client ID** field and save it for later use.
      </Step>

      <Step title="Copy Client Secret">
        Copy the text from the **Client Secret** field and save it for later use.

        <Frame>
          <img src="https://mintcdn.com/iru/tdUGxmJrLWpxmPfN/assets/media/images/google-native_09-27-24.png?fit=max&auto=format&n=tdUGxmJrLWpxmPfN&q=85&s=dc6b3de9f1f68cacf3d4c0f3a4757584" alt="Google OAuth Client ID and Client Secret fields" width="1112" height="1314" data-path="assets/media/images/google-native_09-27-24.png" />
        </Frame>
      </Step>

      <Step title="Click OK">
        Click **OK**.
      </Step>
    </Steps>

    <Note>
      After completing the Google Workspace Configuration, return to the **Iru Web App Configuration** tab to finish setting up the SSO connection using the Client ID, and Client secret you copied from Google Workspace.
    </Note>
  </Tab>
</Tabs>
