About Passport with Google Workspace
Passport with Google Workspace enables users to log into Mac computers using their Google Workspace credentials. This integration provides seamless authentication using your organization’s Google identity system.How It Works
Passport integrates with your Google Workspace instance using Secure LDAP to authenticate users at the macOS login screen. When users enter their Google Workspace credentials, Passport verifies them against your Google directory and creates or updates the local Mac user account.- Google Workspace
- Iru Endpoint
Prerequisites
- Your organization’s Google Workspace instance needs to support Secure Lightweight Directory Access Protocol (LDAP). Google has a list of supported licenses for the LDAP service here.
- Every Google Workspace user who will sign in with Passport must have a Cloud Identity Premium license assigned in Google Workspace.
- You need access to your organization’s super administrator account.
- If your web browser automatically uncompresses .zip files, temporarily change that setting and download the file again, or compress the uncompressed folder before you upload it to your Passport Library Item.
Create a Secure LDAP Client and Download the Certificate
Passport uses Secure LDAP to communicate with Google to confirm login credentials and gather basic user and group information. When you create a new Secure LDAP client in Google Workspace, you’ll download a certificate to secure communications and turn the service on.Sign in to Google Admin console
Access Apps section
Access LDAP
Add LDAP client when others already exist

Add LDAP client when none exist yet

Enter LDAP client name
Enter description
Continue configuration

Configure user credentials verification

Configure user information reading
Enable System Attributes
Leave custom attributes deselected

Configure group information reading
Review and create LDAP client

Download certificate
Continue to Client Details

Access service settings

Enable service for everyone
Save configuration

Re-Download Your Secure LDAP Certificate (Optional)
After you configure the LDAP client in the previous section, you can always download the certificate that’s used to secure the LDAP communication between Passport and Google. There are many other options, including renaming a certificate, generating additional certificates, and deleting a certificate.Sign in to Google Admin console
Access Apps section
Access LDAP
Select LDAP client

Access Authentication section

Download certificate

Collect Group Email Prefixes for User Provisioning
If you want Passport to set each user’s Mac account type from Google group membership, collect the Group email prefix for each group you plan to map. You will use those values under User provisioning on the Passport Library Item Iru Endpoint tab.Open a group in Google Admin
Copy the group email prefix
Paste the prefix into a document
Repeat for each group
After Initial Setup
Certificate Expiration and Renewal
Google Workspace Secure LDAP certificates expire. Generate, download, and upload a replacement before the current certificate expires so Passport can keep authenticating users without interruption.Open your Passport LDAP client in Google Admin

Review certificate expiration

Note expiration dates for renewal planning
Generate a new certificate

Download the new certificate

Replace the certificate in the Passport Library Item
Remove the previous certificate in Google Admin


Troubleshooting
Correct email and password but sign-in still fails
Correct email and password but sign-in still fails
Secure LDAP certificate expired
Secure LDAP certificate expired




