Google Authentication (SAML)
Ivanti Neurons currently offers the option to choose Google as the external authentication provider for your tenant. Google centralizes the end user log on experience, reduces the occurrence of password related calls to the help desk, and produces granular controls over policies and audit trails.
Configure and Enable External Authentication
![Closed](Skins/Default/Stylesheets/Images/transparent.gif)
-
In the Ivanti Neurons Platform, navigate to Admin > Authentication.
The Authentication page appears.
-
In the External Authentication (SSO) section, click Configure & Enable.
The Enable External Authentication (SSO) page appears.
-
From the Provider drop-down, select Google.
-
From the Sign-In Method drop-down, select Saml 2.0.
Google SAML 2.0 Configuration Settings appears. It is recommended to leave this tab open for future reference when configuring the details in Google Admin console.
![Closed](Skins/Default/Stylesheets/Images/transparent.gif)
-
Log in to Google Admin console.
-
Navigate to Apps > Web and mobile apps.
-
Click Add app, then select Add custom SAML app.
The App details page appears.
-
Enter a name for the SAML app and click CONTINUE.
-
Select DOWNLOAD METADATA to download the metadata file and click CONTINUE.
-
Enter the values in the Service provider details available in the Ivanti Neurons tab that was open:
-
ACS URL: Assertion Consumer Service URL.
-
Entity ID: Unique identifier.
-
-
Select Signed response and click CONTINUE.
-
Click ADD MAPPING and enter the details in the Google Directory attributes:
-
First name: given_name.
-
Last name: family_name.
-
Primary email: email.
-
-
Click FINISH.
The application is now created in Google.
-
On the Web and mobile apps, follow these steps to grant access to appropriate administrator groups:
-
Click View details under User access.
-
Select Administrators from the drop-down of Groups.
-
Enable the Service status and click Save.
All members of the administrator group will now have access to the application.
-
-
Navigate to Ivanti Neurons Platform and click Select file.
-
Open the downloaded metadata file and click Upload to complete the upload.
-
Click Continue.
![Closed](Skins/Default/Stylesheets/Images/transparent.gif)
You must connect with your Google credentials to validate your connection settings.
-
On the Validate Connection Settings page, click Validate Settings.
The validation takes place automatically. You will receive a confirmation screen if login is successful.
-
Return to the Validate Connection Settings page and select the check box to confirm login success.
Google is now configured, but it is not enabled. To enable, you need to convert your Ivanti Neurons Platform accounts to Google.
-
Click Continue to proceed to the Convert your Ivanti Neurons platform account page.
![Closed](Skins/Default/Stylesheets/Images/transparent.gif)
-
E2018 Authentication failed: User failed to authenticate with Google. Check that the username and password are correct, and that the user has permissions on the Google Application Registration.
-
E2019 Missing optional claims: Validation step failed because the additional optional claims were not present in the token returned to Ivanti Neurons Platform from Google.
-
E2020 Unable to link to Neurons Platform user account: The Google user login does not match with the Ivanti Neurons Platform user. The Ivanti Neurons Platform user account email address must match the email address used to login into Google.
![Closed](Skins/Default/Stylesheets/Images/transparent.gif)
-
On the Convert your Ivanti Neurons platform account page, click Sign Out & Enable. Ivanti Neurons is signed-out.
-
Click Sign in with Google to complete the process.
-
You can now view Google application in Admin > Authentication with an Enabled status.
-
Click Sign out from the Neurons platform.
Now, when you sign back in, you are routed to Google to choose the account and sign in with Google credentials.
Configure Auto Provisioning
Enabling auto provisioning will automatically grant access to Ivanti Neurons for all members within the Google Application Registration without having to go through the manual invite process. When a new member logs in for the first time, a new Ivanti Neurons Platform account will be provisioned in Ivanti Neurons > Members. All new auto-provisioned members will be granted the access control roles defined in the set up.
![Closed](Skins/Default/Stylesheets/Images/transparent.gif)
-
In Ivanti Neurons Platform navigate to Setup > Authentication.
The Authentication Method page appears.
-
In the External Authentication section, click Actions and select Enable auto provisioning.
-
From the Default roles drop-down, select the access control role that you want to be assigned to all new members.
To set up Roles, go to Ivanti Neurons > Admin> Roles.
-
Click Enable Auto Provisioning to confirm the role selection and enable auto provisioning for all new members.
Once enabled, you can edit default access control roles and disable auto provisioning. These changes will only apply to members provisioned after the modifications and will not affect existing members.
Enabling auto-provisioning grants all Google Application Registration users access to Ivanti Neurons. You can restrict access to certain users or groups from within the Google Application.
(Optional) Update Metadata (Ivanti Neurons Platform)
-
In Ivanti Neurons Platform, navigate to Admin > Authentication.
The Authentication page appears.
-
In the External Authentication section, click Actions > Update metadata.
The Update SAML metadata page appears.
-
In Google Configuration Settings, click Select file.
-
Open the downloaded metadata file and click Upload.
-
Click Continue to validate the metadata.
-
On the Validate New SAML metadata page, click Validate SAML Metadata.
-
A new tab opens on your organization’s sign-in page. Enter your credentials and sign in.
The validation takes place automatically. You will receive a confirmation screen if login is successful.
-
Return to the Validate New SAML metadata page and select the check box to confirm login success.
-
Click Continue to proceed to the Save New SAML Metadata page.
-
Click Save changes to complete the process.
A notification confirming the successful update of client secret is received.
(Optional) Delete Authentication Method (Ivanti Neurons Platform)
-
In the Ivanti Neurons Platform, navigate to Admin > Authentication.
The Authentication page appears.
-
In the External Authentication (SSO) section, click Actions > Delete authentication method.
The Delete External Authentication screen appears.
-
Click Sign Out & Re-authenticate.
Ivanti Neurons is signed-out.
-
Click Sign in with email and password.
-
Enter the credentials and click Sign In.
-
Navigate to Admin > Authentication > External Authentication, then click Actions > Delete authentication method.
Delete External Authentication screen appears.
-
Click Delete Authentication Method.
The existing authentication method is now deleted.