Skip to content

OpenID Connect

OpenID Connect (OIDC) is an identity layer built on OAuth 2.0 that provides authentication and single sign-on (SSO) capabilities. With OpenID Connect, users can sign in to multiple applications and services using a single set of credentials managed by an external identity provider (IdP).

Sophos Firewall supports OpenID Connect authentication through external identity providers, allowing organizations to use existing cloud-based identity services for user and administrator authentication. This simplifies account management and provides a consistent sign-in experience across supported firewall services.

OpenID Connect identity providers

The OpenID Connect supports the following IdPs:

  • Microsoft Entra ID
  • Google Workspace

When adding an authentication server, select OpenID Connect as the server type and then choose the appropriate IdP.

Although both IdPs are configured through the OpenID Connect server type, the authentication requirements differ.

  • Microsoft Entra ID


    Microsoft Entra ID supports OpenID Connect (OIDC) authentication and continues to work with existing Microsoft Entra ID authentication deployments.

    Microsoft Entra ID

  • Google Workspace


    Google Workspace authentication supports user authentication and group-based authorization. Since Google Workspace doesn't provide group membership information in standard OpenID Connect authentication responses, additional Google Workspace configuration is required to retrieve user group information.

    Google Workspace

Note

You can select only one IdP server for each firewall service. See Services.

Supported services

You can use OpenID Connect SSO authentication with the following Sophos Firewall services:

  • Web Admin Console
  • Captive Portal
  • VPN Portal
  • Remote access SSL VPN
  • Remote access IPsec VPN

How OpenID Connect authentication works

When a user attempts to access a protected service, the firewall redirects the user to the configured IdP for authentication. After the user's identity is verified, the IdP returns authentication information to the firewall, which then grants access to the requested service.

OIDC uses standardized authentication endpoints and token formats, allowing the firewall to integrate with supported identity providers through a consistent framework. The key OIDC capabilities are as follows:

  • SSO authentication.
  • Integration with supported cloud IdPs.
  • Automatic discovery of identity provider settings.
  • Standardized user identity and attribute mapping.
  • Secure authentication using industry-standard OpenID Connect protocols.

User and administrator mapping

The firewall can use IdP attributes to determine user identity and administrator access.

You can map IdP groups or roles to:

  • Firewall groups
  • User policies
  • Administrator access profiles

This allows the firewall to apply administrator permissions based on information provided by the IdP during authentication.