Change the SSO configuration of a Google SecOps instance

Supported in:

This document describes how to change the identity provider (IdP) of a Google SecOps instance. You might need to do this to switch to a different third-party IdP or to migrate from a third-party IdP to Cloud Identity.

This document covers the following procedures:

Change the third-party identity provider

This section describes how to change your Google SecOps instance to use a different third-party identity provider. Complete the following steps:

  1. Set up the new third-party identity provider and workforce identity pool.

  2. In Google SecOps, under Settings > SOAR settings > Advanced > IDP group mapping, change the IdP group mapping to reference groups in the new identity provider.

Update SSO settings

Complete the following steps to change the SSO configuration for Google SecOps:

  1. Open the Google Cloud console, and then select the Google Cloud project that is linked to Google SecOps.

  2. Go to Security > Google SecOps.

  3. On the Overview page, click the Single Sign-On tab. This page displays the IdPs you configured when Configuring a third-party identity provider for Google SecOps.

  4. Use the Single Sign-On menu to change SSO providers.

  5. Right-click the Test SSO setup link, and then open a private or incognito window.

  6. Return to Google Cloud console, click the Security > Google SecOps > Overview page, and then click the Single Sign-On tab.

  7. Click Save at the bottom of the page to update the new provider.

  8. Verify that you can sign in to Google SecOps.

Migrate from third-party identity provider to Cloud Identity

This section describes how to change the SSO configuration from using a third-party identity provider to Google Cloud Identity. Complete the following steps:

  1. Make sure you configure either Cloud Identity or Google Workspace as the identity provider.
  2. Grant the predefined Chronicle IAM roles and custom roles to users and groups in the Google SecOps-bound project.
  3. Grant the Chronicle SOAR Admin role to the relevant users or groups.
  4. In Google SecOps, under Settings > SOAR settings > Advanced > IDP group mapping, add the Chronicle SOAR Admin. For more information, see IdP group mapping.

  5. Open the Google Cloud console, and then select the Google Cloud project is linked to Google SecOps.

  6. Go to Security > Chronicle SecOps.

  7. On the Overview page, click the Single Sign-On tab. This page displays the IdPs you configured when Configuring a third-party identity provider for Google SecOps.

  8. Select the Google Cloud Identity checkbox.

  9. Right-click the Test SSO setup link, and then open a private or incognito window.

    • If you see a login screen, then SSO setup is successful. Continue with the next step.
    • If you don't see a login screen, check the configuration of the identity provider.
  10. Return to Google Cloud console, and then click Security > Chronicle SecOps > Overview page > Single Sign-On tab.

  11. Click Save at the bottom of the page to update the new provider.

  12. Verify that you can sign in to Google SecOps.

Need more help? Get answers from Community members and Google SecOps professionals.