---
title: Configuring SSO with Google
description: "Google OIDC Setup: these instructions are largely based on OpenID Identity Connect    Before you can create credentials, you need to create a consent screen. This screen is shown to a Detect user when"
---

[Skip to content](https://support.preludesecurity.com/docs/google#main-content)

English

Show submenu for translations

[Contact support](https://support.preludesecurity.com/kb-tickets/new?hsLang=en)

![Prelude\_Wordmark\_Black\_Transparent.png\]](https://support.preludesecurity.com/hs-fs/hubfs/Prelude_Wordmark_Black_Transparent.png?height=50&name=Prelude_Wordmark_Black_Transparent.png)

Open main navigation

Close main navigation

- English
  
  Show submenu for translations
- [Contact support](https://support.preludesecurity.com/kb-tickets/new)
- [Visit the website](https://www.preludesecurity.com/)

[Visit the website](https://www.preludesecurity.com/)

 Find what you're looking for

- There are no suggestions because the search field is empty.

1. [Knowledge Base](https://support.preludesecurity.com/?hsLang=en)
2. [Account](https://support.preludesecurity.com/account?hsLang=en)
3. [SSO](https://support.preludesecurity.com/account?hsLang=en#sso)

# Configuring SSO with Google

Google OIDC Setup: these instructions are largely based on [OpenID Identity Connect](https://developers.google.com/identity/openid-connect/openid-connect)

### Create a new project

- Create a new Project as part of your organization. The example project will be PreludeOIDCProvider part of the Prelude Security organization.

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/814c424-image.png)

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/59eaabe-image.png)

- Your project may take a few minutes to create, but you will get a notification. Select the project to move on.

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/36b8491-image.png)

### Create a Consent Screen

Before you can create credentials, you need to create a consent screen. This screen is shown to a Detect user when they first log in using OIDC. They have to consent to have their identity shared with Prelude.

Select "APIs & Services" then "OAuth consent screen" from the left menu

### ![](https://support.preludesecurity.com/hs-fs/hubfs/eba49b1-image-png.png?width=452&height=450&name=eba49b1-image-png.png)Create a new internal Application

Select the "Internal" type.

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/218bbda-image.png)

### Configure some app domains and points of contact

Next fill in the appropriate values for the app registration. The important values here:

- Links back to the preludesecurity.com website for information on privacy and security: [https://www.preludesecurity.com](https://www.preludesecurity.com)
- Authorized domain: preludesecurity.com (who is allowed to initiate the login flow)
- Developer Contact Info: [support@your-org.com](mailto:support@your-org.com) (a support contact in your organization for helping users with login issues)

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/be058a6-image.png)

### You do not need to add additional Scopes

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/ffce998-image.png)

- Once you hit save and continue, you are done creating your application’s consent screen.

### Create Oauth Client ID

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/5991a12-image.png)

### Type: Web Application

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/f766b58-image.png)

### Name the client and Authorize some URLs to be OIDC clients

Important values:

- Name: PreludeDetect (You can customize this as you see fit)
- Authorized Javascript Origins 
    - [https://api.us1.preludesecurity.com](https://api.us1.preludesecurity.com) (us1 users)
    - [https://api.eu1.preludesecurity.com](https://api.eu1.preludesecurity.com) (eu1 users)
- Authorized redirect URIs 
    - US1: https://platform-auth.us1.preludesecurity.com/oauth2/idpresponse
    - EU1: https://platform-auth.eu1.preludesecurity.com/oauth2/idpresponse

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/cf0e7fa-image.png)

### Create Credentials

These credentials will be imported into PreludeDetect to identify it as an OIDC client for your application.

![](https://support.preludesecurity.com/hubfs/Knowledge%20Base%20Import/7baffa3-image.png)

### Google Configuration URL

While you are done configuring the google side of OIDC, when adding this to Prelude you will be asked for your:

- Client Id
- Client Secret
- Configuration Url (this should always end in .well-known/openid-configuration) 
    - this will be `https://accounts.google.com/.well-known/openid-configuration`

### Configure Prelude User accounts to use SSO

**Note**: After configuring SSO above you must specify which user accounts will use SSO explicitly in Prelude.  Additionally, you cannot update an existing user using password authentication to SSO currently, instead you must delete the user and recreate with SSO auth.

 

1. In the Prelude UI, click your name/id in the top right corner, then select **Account Users**
2. Select Invite a User to invite a new user and specify OpenID Connect to use Entra SSO

- [Monitor](https://support.preludesecurity.com/monitor?hsLang=en#main-content)

    - [Introduction to Control Monitor](https://support.preludesecurity.com/monitor?hsLang=en#introduction-to-control-monitor)
    - [Configuration](https://support.preludesecurity.com/monitor?hsLang=en#configuration)
    - [Client Hardware Security Integrations](https://support.preludesecurity.com/monitor?hsLang=en#client-hardware-security-integrations)
    - [Device Discovery Integrations](https://support.preludesecurity.com/monitor?hsLang=en#device-discovery-integrations)
    - [EDR Integrations](https://support.preludesecurity.com/monitor?hsLang=en#edr-integrations)
    - [Email Integrations](https://support.preludesecurity.com/monitor?hsLang=en#email-integrations)
    - [Identity Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#identity-management-integrations)
    - [Endpoint Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#endpoint-management-integrations)
    - [Vulnerability Management Integrations](https://support.preludesecurity.com/monitor?hsLang=en#vulnerability-management-integrations)
    - [Reporting](https://support.preludesecurity.com/monitor?hsLang=en#reporting)
    - [Troubleshooting](https://support.preludesecurity.com/monitor?hsLang=en#troubleshooting)
- [Detect](https://support.preludesecurity.com/detect?hsLang=en#main-content)

    - [Basics](https://support.preludesecurity.com/detect?hsLang=en#basics)
    - [Integrations](https://support.preludesecurity.com/detect?hsLang=en#integrations)
    - [Probe deployment](https://support.preludesecurity.com/detect?hsLang=en#probe-deployment)
    - [Security tests](https://support.preludesecurity.com/detect?hsLang=en#security-tests)
    - [Alert suppression](https://support.preludesecurity.com/detect?hsLang=en#alert-suppression)
    - [Assurance](https://support.preludesecurity.com/detect?hsLang=en#assurance)
- [Integrations](https://support.preludesecurity.com/integrations?hsLang=en#main-content)

    - [SASE](https://support.preludesecurity.com/integrations?hsLang=en#sase)
- [Account](https://support.preludesecurity.com/account?hsLang=en#main-content)

    - [SSO](https://support.preludesecurity.com/account?hsLang=en#sso)
- [CLI](https://support.preludesecurity.com/cli?hsLang=en)
- [Release Notes](https://support.preludesecurity.com/release-notes?hsLang=en)

[![Origin Technology Logo](https://support.preludesecurity.com/hs-fs/hubfs/origin_logo_inverse_000000.png?width=5000&height=5000&name=origin_logo_inverse_000000.png "Origin Technology Logo")](http://originhq.com)

Prelude Security Knowledge Base

Copyright © 2026, Origin Technology