About Passport with Google Workspace
Passport with Google Workspace enables users to log into Mac computers using their Google Workspace credentials. Passport uses your organization’s Google identity system at macOS login.How It Works
Passport integrates with your Google Workspace instance using Secure LDAP to authenticate users at the macOS login screen. When users enter their Google Workspace credentials, Passport verifies them against your Google directory and creates or updates the local Mac user account.- Google Workspace
- Iru Endpoint
Prerequisites
- Your organization’s Google Workspace instance needs to support Secure Lightweight Directory Access Protocol (LDAP). Google has a list of supported licenses for the LDAP service here.
- Every Google Workspace user who will sign in with Passport must have a Cloud Identity Premium license assigned in Google Workspace.
- You need access to your organization’s super administrator account.
- If your web browser automatically uncompresses .zip files, temporarily change that setting and download the file again, or compress the uncompressed folder before you upload it to your Passport Library Item.
Create a Secure LDAP Client and Download the Certificate
Passport uses Secure LDAP to communicate with Google to confirm login credentials and gather basic user and group information. When you create a new Secure LDAP client in Google Workspace, you’ll download a certificate to secure communications and turn the service on.Sign in to Google Admin console
Access Apps section
Access LDAP
Add LDAP client when others already exist
Add LDAP client when none exist yet
Enter LDAP client name
Enter description
Continue configuration
Configure user credentials verification
Configure user information reading
Enable System Attributes
Leave custom attributes deselected
Configure group information reading
Review and create LDAP client
Download certificate
Continue to Client Details
Access service settings
Enable service for everyone
Save configuration
Re-Download Your Secure LDAP Certificate (Optional)
After you configure the LDAP client in the previous section, you can always download the certificate that’s used to secure the LDAP communication between Passport and Google. There are many other options, including renaming a certificate, generating additional certificates, and deleting a certificate.Sign in to Google Admin console
Access Apps section
Access LDAP
Select LDAP client
Access Authentication section
Download certificate
Collect Group Email Prefixes for User Provisioning
If you want Passport to set each user’s Mac account type from Google group membership, collect the Group email prefix for each group you plan to map. You will use those values under User provisioning on the Passport Library Item Iru Endpoint tab.Open a group in Google Admin
Copy the group email prefix
Paste the prefix into a document
Repeat for each group
After Initial Setup
Certificate Expiration and Renewal
Google Workspace Secure LDAP certificates expire. Generate, download, and upload a replacement before the current certificate expires so Passport can keep authenticating users without interruption.Open your Passport LDAP client in Google Admin
Review certificate expiration
Note expiration dates for renewal planning
Generate a new certificate
Download the new certificate
Replace the certificate in the Passport Library Item
Remove the previous certificate in Google Admin
Troubleshooting
Correct email and password but sign-in still fails
Correct email and password but sign-in still fails
Secure LDAP certificate expired
Secure LDAP certificate expired