Configurer l’authentification unique Google pour Procore

 Remarque

Si votre organisation utilise les produits Gestion financière du portefeuille et Planification des immobilisations de Procore, vous devrez contacter votre Point de contact Procore ou l’équipe de support technique pour configurer votre authentification unique Google.

Contexte

Pour vous aider à comprendre les termes abordés ci-dessous, voici quelques définitions :

  • Fournisseur d’identité (IdP). Il s’agit du service qui vérifie l’identité de vos utilisateurs finaux (par exemple, Okta, OneLogin ou Microsoft Azure AD).

  • URL émettrice (ID de l’entité). Chaîne unique qui identifie le fournisseur émettant une demande SAML.

  • SAML. Abréviation de Security Assertion Markup Language (langage de balisage d’assertion de sécurité).

  • Fournisseur de services (SP). Procore (en anglais seulement)

  • URL cible. L’URL du fournisseur d’identité qui recevra les requêtes SAML de Procore.

  • Certificat X.509. Il s’agit d’un certificat numérique crypté qui contient les valeurs requises qui permettent au service d’authentification unique de vérifier l’identité de vos utilisateurs.

Les configurations suivantes sont prises en charge avec l’authentification unique Google :

  • Authentification unique initiée par le fournisseur de services (initiée par le fournisseur de services). Appelée authentification unique initiée par Procore, cette option permet à vos utilisateurs finaux de se connecter à la page de connexion Procore, puis d’envoyer une demande d’autorisation à l’IdP. Une fois que l’IdP a authentifié l’identité de l’utilisateur, celui-ci est connecté à Procore.

  • authentification unique initiée par le fournisseur d’identité (initiée par l’IdP). Avec cette option, vos utilisateurs finaux doivent se connecter à la page authentification unique de votre IdP, puis cliquer sur une icône pour se connecter et ouvrir l’application Web Procore.

Éléments à prendre en compte

  • Autorisations utilisateur requises :

    • Pour ajouter Procore en tant qu’application Security Assertion Markup Language personnalisée dans Google :* Accès à un compte super-administrateur Google.

    • Pour configurer l’authentification unique de Google dans Procore :* Autorisations de niveau 'Admin' dans l’outil Niveau entreprise Admin.

Steps

  • Add Procore as a Custom SAML Application in Google

  • Configure Google SSO in Procore

Add Procore as a Custom SAML Application in Google

See Google's Set up your own custom SAML application for more information on the steps below.

  1. Navigate to the Google Identity Provider details page in Google's Admin console.

  2. Open a blank document on your computer.

  3. Copy the SSO URL from the Google Identity Provider details page and paste it into your blank document.

  4. Copy the Entity ID from the Google Identity Provider details page and paste it into your blank document.

  5. Download the Certificate from the Google Identity Provider details page.

  6. Open the Certificate and copy the text between Begin Certificate and End Certificate.

  7. Paste the Certificate text into your blank document.

  8. Complete the following in Google's Service Provider Details window:

    • ACS URL: https://login.procore.com/saml/consume

    • Entity ID: https://login.procore.com/

      Réutilisation de contenu SSO

       Optional - Unique Entity ID

      When configuring SSO for a single Procore instance, you should NOT check this box.

      If your company licenses more than one Procore instance, and you want to configure unique Procore enterprise applications within your IdP tenant for each instance, you can by enabling Unique Entity ID. If enabled, you are still limited to one (1) enterprise application per Procore company instance.

      Important: SSO for Procore targets users by email domain. An email domain can only be targeted once in all of Procore, so if you're considering setting up SSO with Unique Entity IDs across multiple Procore instances, remember that you can only target an email domain once, in a single instance.

      To generate a Unique Entity ID for an enterprise application, check the Enable Unique Entity ID box in the Procore Admin tool's SSO configuration page for the Procore instance you want to specify on an enterprise application. Checking this box will generate a unique Entity ID URL in the field below, which you will then copy and paste into the appropriate Entity ID field in your IdP's configuration page.

      Notes: You must save your configuration with the box checked to generate the Unique Entity ID. Enabling this feature does not impact user membership or access to a given instance. Access to a company in Procore is determined by a user's presence in the Directory tool, and their configured permissions within Procore. Auto-provisioning with SSO is not supported at this time.

      Sso Unique Entity Id

    • Start URL: Leave this field blank.

    • Certificate: Copy and paste the Certificate text from your blank document.

    • Signed Response: Mark this checkbox.

    • Name ID: Select Basic Information in the first drop-down menu and Primary Email in the second drop-down menu.

    • Name ID Format: Select EMAIL in the drop-down menu.

Configure Google SSO in Procore

  1. Navigate to the Company level Admin tool in Procore.

  2. Under Company Settings, click Single Sign On Configuration.

  3. Complete the following:

    • Enter the Entity ID from the Google Identity Provider details page in the Single Sign On Issuer URL field.

    • Enter the SSO URL from the Google Identity Provider details page in the Single Sign On Target URL field.

    • Enter the Certificate text in the Single Sign On x509 Certificate field.

  4. Click Save Changes.

  5. Reach out to Procore Support or your company's Point de contact Procore to request to enable SSO. Include the email domain you'd like to target for SSO in your request.

  6. After you receive confirmation that the SSO configuration is ready, mark the Enable Single Sign On checkbox on the 'Single Sign On Configuration' page.

  7. Do one of the following:

    • Select the Allow Password Login option.

    • Select the Service Provider Forward option.

  8. Click Save Changes.

Voir aussi

Chargement des articles connexes...