# Google OIDC SSO with Mapping (Google) Groups onto (Kibana) Roles

**URL:** <https://discuss.elastic.co/t/google-oidc-sso-with-mapping-google-groups-onto-kibana-roles/271762>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-security\
**Created:** [April 30, 2021, 10:23am UTC](https://discuss.elastic.co/t/google-oidc-sso-with-mapping-google-groups-onto-kibana-roles/271762 "2021-04-30T10:23:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![MartynF](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martynf/32/87998_2.png) [@MartynF](https://discuss.elastic.co/u/MartynF)\
**Post date:** [April 30, 2021, 10:23am UTC](https://discuss.elastic.co/t/google-oidc-sso-with-mapping-google-groups-onto-kibana-roles/271762/1 "2021-04-30T10:23:08Z")

</div>

Hi

We're using Elastic Cloud hosted version of the Elastic stack and attempting to integration Google SSO with OIDC.

I have the authentication working and can use role mapping with usernames to map specific users onto Roles in Kibana.

To make this more manageable and consistent with our other systems using Google OIDC, I want to manage role assignment with Google Groups e.g. assign people to 'engineers' group in Google Workplace and have them pick up the equivalent Engineers role in Kibana.

In Google Cloud Console we have the permissions set up correctly to allow the OIDC integration to pull through the groups (and this is working with Pritunl/Hashicorp Vault OK) but I'm struggling to map the groups.

I can find instructions for mapping Azure AD groups but not Google.

In elasticsearch.yml I have this:

```auto
    xpack:
      security:
        authc:
          realms:
            oidc:
              oidc1:
                order: 2
                rp.client_id: "REDACTED.apps.googleusercontent.com"
                rp.response_type: "code"
                rp.requested_scopes: ["openid", "email", "https://www.googleapis.com/auth/admin.directory.group.readonly"]
                rp.redirect_uri: "https://REDACTED.eu-west-1.aws.found.io:9243/api/security/v1/oidc"
                op.issuer: "https://accounts.google.com"
                op.authorization_endpoint: "https://accounts.google.com/o/oauth2/v2/auth"
                op.token_endpoint: "https://oauth2.googleapis.com/token"
                op.userinfo_endpoint: "https://openidconnect.googleapis.com/v1/userinfo"
                op.jwkset_path: "https://www.googleapis.com/oauth2/v3/certs"
                claims.principal: email
                claims.groups: groups
                claim_patterns.principal: "^([^@]+)@ourdomain\\.tld$"

```

I've then tried mapping the groups onto roles with this:

```auto
    PUT /_xpack/security/role_mapping/oidc_kibana
    {
        "enabled": true,
        "roles": ["engineers"],
        "rules" : {
          "all" : [
            {"field" : { "realm.name" : "oidc1" }},
            {"field": { "groups": ["engineers"] } }
          ]
        },
        "metadata": { "version": 1 }
    }

```

However the role doesn't appear to be assigned.

If I swap out the groups line to a list of explicit users it works as expected and assigns the Role:

```auto
{"field": { "username": ["user1","user2"] } }

```

Any ideas? Is there a change I need to make in elasticsearch.yml to map the groups returned by Google in the JWT?

---

<div class="post-metadata">

**Author:** ![ikakavas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ikakavas/32/34430_2.png) [@ikakavas](https://discuss.elastic.co/u/ikakavas)\
**Post date:** [May 4, 2021, 8:05am UTC](https://discuss.elastic.co/t/google-oidc-sso-with-mapping-google-groups-onto-kibana-roles/271762/2 "2021-05-04T08:05:45Z")

</div>

The missing part here is _how_ and _if_ Google returns the group memberships in the JWT.

```auto
                claims.groups: groups

```

This configuration tells Elasticsearch that it should try and find a `claim` that is named `groups` in the ID Token or in the Userinfo response and get all the values from it and assign it to the `groups` property of the user representation in elasticsearch, so that you can later do things like

```auto
{"field": { "groups": ["engineers"] } }

```

in your role mappings.

From what I see in [https://accounts.google.com/.well-known/openid-configuration](https://accounts.google.com/.well-known/openid-configuration) , Google's OIDC implementation doesn't support a claim by which it conveys the users group memberships in the context of OpenID Connect, so it appears that you won't be able to do what you're after as groups are not even returned in the IDToken JWT.

---

<div class="post-metadata">

**Author:** ![MartynF](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/martynf/32/87998_2.png) [@MartynF](https://discuss.elastic.co/u/MartynF)\
**Post date:** [May 4, 2021, 1:05pm UTC](https://discuss.elastic.co/t/google-oidc-sso-with-mapping-google-groups-onto-kibana-roles/271762/3 "2021-05-04T13:05:07Z")

</div>

Hi Ioannis,

I had assumed Google did return the Groups in their JWT as we got this functionality working ok with Hashicorp Vault product (see [OIDC Provider Setup - Auth Methods | Vault by HashiCorp](https://www.vaultproject.io/docs/auth/jwt_oidc_providers#google)) however. if I'm reading their source code correctly. it looks like they had to write a specific plug-in to pull the Groups via the Google API)  
[https://github.com/hashicorp/vault-plugin-auth-jwt/commit/5815ce50fbffaddcc9d197d2ace3779ed6742c8d#diff-630ba09448af522154f38ef7685ef1f44b0f3e9430f80829a03ce24f400f3754](https://github.com/hashicorp/vault-plugin-auth-jwt/commit/5815ce50fbffaddcc9d197d2ace3779ed6742c8d#diff-630ba09448af522154f38ef7685ef1f44b0f3e9430f80829a03ce24f400f3754)

Pritunl also handles Google Groups nicely, mapping these onto their concept of Organisations: [Google](https://docs.pritunl.com/docs/google)

So while it is technically possible, it would require more work on Elastic's side to more tightly support Google Workplace. For now I'll have to handle the mapping manually based on username rather than Groups.

Thanks for your help/investigation.

Martyn

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2021, 1:05pm UTC](https://discuss.elastic.co/t/google-oidc-sso-with-mapping-google-groups-onto-kibana-roles/271762/4 "2021-06-01T13:05:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
