Google Workspace SSO Login Configuration

Purpose

This guide explains how to let Google Workspace users log in to Logsign USO with their Google account. You create an OAuth client in Google Cloud, enter its Client ID and Client Secret on the Google Workspace integration in Logsign, sync the Workspace users into Logsign and assign them a role. From then on, those users are sent to Google's sign-in page when they log in, and their password never reaches Logsign.

Note: the Google Workspace integration in Logsign has three separate capabilities that share one configuration screen but use different credentials. SSO login (this guide) uses a standard OAuth 2.0 Web application client. The Response integration (suspend and reactivate users) and identity and device sync use a Domain-Wide Delegation service account (Service Account JSON). Configuring one does not configure the others, and SSO needs the identity sync to be working, because users must be synced before they can log in.

If your users live in on-premises Active Directory instead, see LDAP Configuration and LDAP Users Login. For Microsoft Entra ID, see Microsoft Entra ID SSO Login Configuration.

How the Login Works

  1. The user opens Logsign, types their username and clicks Next.
  2. Logsign sees that the user was synced from Google Workspace and redirects the browser to Google's sign-in page with the scopes openid email profile.
  3. The user signs in with their Google Workspace account, including any 2-Step Verification your organization enforces.
  4. Google redirects the browser back to https://<logsign-address>/login with an authorization code. Logsign exchanges the code for an ID token directly with Google and verifies its signature against Google's public keys, its audience (your Client ID) and its expiry.
  5. Logsign takes the email address from the verified token, uses the part before @ (for example jane.doe from jane.doe@yourcompany.com), and matches it to a Logsign user synced from the same Google Workspace integration. If Logsign two-factor authentication is enabled for that user, the 2FA step follows. The dashboard then opens.

The round trip must complete within 2 minutes of step 2. If it takes longer, the login fails and the user must start again from the username step.

Prerequisites

Item Requirement
Google Cloud access Permission to configure the OAuth consent screen and create OAuth client IDs in a Google Cloud project owned by your Workspace organization.
Identity sync A Google Workspace integration in Logsign with identity sync already working (Service Account JSON with Domain-Wide Delegation). See Google Workspace Identity and Asset Sync.
Network from Logsign Every Logsign node must reach oauth2.googleapis.com and www.googleapis.com on TCP 443.
Network from users Users' browsers must reach accounts.google.com.
Logsign address The Logsign URI under Settings > System > Dns Settings must be the address users actually open in the browser. Behind a load balancer, use the load balancer address. This value is used to build the redirect URI.
Clock The Logsign server clock must be accurate to within a few seconds, because the ID token's validity window is checked with only 10 seconds of tolerance.

Step 1: Create an OAuth Client in Google Cloud

  1. Open Google Cloud Console and select (or create) the project you want to use for Logsign login.
  2. Go to APIs & Services > OAuth consent screen and configure it if you have not already. Choose Internal so that only users of your own Workspace organization can authenticate.
  3. Go to APIs & Services > Credentials, click Create Credentials > OAuth client ID and choose Web application.
  4. Under Authorized redirect URIs, add https://<logsign-address>/login.
  5. Click Create and copy the Client ID and Client Secret. If you lose the secret, you can add a new one to the same client from the Credentials page.

Important: the redirect URI must match exactly, including https:// and the /login path. Correct: https://siem.yourcompany.com/login. Wrong: https://siem.yourcompany.com/. A mismatch makes Google stop the login with redirect_uri_mismatch.

Step 2: Configure Google Workspace SSO in Logsign USO

  1. Go to Settings > Integrations > Responses, search for Google Workspace, click Configure and open your existing Google Workspace device.
  2. Fill in the SSO fields below and save.
Field Required Description
SSO OAuth Client ID Yes, for SSO The Client ID from Step 1.
SSO OAuth Client Secret Yes, for SSO The Client Secret from Step 1. Stored encrypted by Logsign.
Domain Recommended Your Workspace domain without a scheme, for example yourcompany.com. When set, Google's account picker is limited to that domain. Correct: yourcompany.com. Wrong: https://yourcompany.com or @yourcompany.com.

Users synced from Google Workspace can only log in through Google. If the SSO OAuth Client ID is left empty, these users see the password form but every login attempt fails, because Logsign never checks a password for them.

Step 3: Add the Users to Logsign

SSO only logs in users who already exist in Logsign. It never creates users.

  1. Go to Settings > Enrichment > Identities, click Sync Ldap, select the Google Workspace integration and sync.
  2. Select the users who should have access and click Apply Role Selected.
  3. In the Add Logsign User window choose the role and save.

Behavior to Be Aware Of

  • A user synced from Google Workspace cannot log in to Logsign with a password.
  • Google 2-Step Verification applies at the Google sign-in step. Logsign two-factor authentication, if enabled for the user, applies in addition.
  • Because only the part before @ is used, two Workspace users whose addresses differ only in the domain (for example on a secondary domain) map to the same Logsign username, and only one of them can log in. A Logsign user with the same name from another source (LDAP, Entra ID or a local user) also blocks the match.
  • Suspending a user in Google Workspace stops their next Google sign-in. Disabling the user in Logsign also blocks them regardless of Google.

Troubleshooting

Symptom Likely cause What to check
A Workspace user sees the password form instead of being sent to Google, and the login fails The SSO OAuth Client ID is not set on the Google Workspace device. Step 2.
Google shows redirect_uri_mismatch The authorized redirect URI does not equal https://<logsign-address>/login. The OAuth client in Google Cloud and the Logsign URI under Settings > System > Dns Settings.
Google shows invalid_client or "OAuth client was not found" The Client ID entered in Logsign is wrong or the client was deleted. Copy the Client ID again from the Credentials page.
Google shows "access blocked" or "org_internal" The consent screen is Internal and the user's account is outside your organization, or the Domain field restricts a different domain. The account used and the Domain field.
"Authentication Failed" after returning from Google The username before @ does not match a Logsign user synced from this integration, the user was not added in Step 3, the client secret is wrong, the login took longer than 2 minutes, or the server clock is off. That the user was added in Step 3 with the expected username, the secret, and the server time. Start again from the username step.

For every failed login Logsign records the exact reason in its API service log. If the table above does not explain the problem, contact Logsign Support with the time of the failed attempt and the username.

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

See more
Become a Certified Logsign User/Administrator
Sign-up for Logsign Academy and take the courses to learn about Logsign USO Platform in detail. Enjoy the courses, and get your badges and certificates. In these courses, you'll learn how to use Logsign in your work and add value to your career.
Visit Our Blog
Our Logsign USO Platform illustrate our expertise. So do the blog. Through our blog posts, deepen your knowledge on various SecOps topics or get updated about important news & modern approaches for cybersecurity. Get into the habit of reading valuable information provided by Logsign. Be a step ahead.