Integrating OpenID Connect with Security Center SaaS for SSO

2026-07-22Last updated

To enable single sign-on (SSO) throughout your organization, you can integrate your OpenID Connect (OIDC) compliant corporate identity provider with Security Center SaaS with help from the Genetec™ Technical Assistance Center (GTAC).

Before you begin

  • Learn about third-party authentication in Security Center SaaS.
  • Ensure you have administrator access to your Microsoft Entra ID tenant and permission to manage consent for enterprise applications.
  • Refer to your identity provider's documentation for the details on applying the generic instructions detailed here.

What you should know

Genetec schedules a collaborative setup call to configure and test your SSO integration. This typically lasts around 15 minutes.
After the integration is completed, SSO authentication is enabled for most Genetec cloud-based products and online services. Using the new integration, your users can sign in to the following:
  • Security Center SaaS
  • Genetec™ Airport Badging Solution (ABS)
  • Genetec ClearID™
  • Genetec Clearance™
  • Genetec Cloudrunner™
  • Genetec Operations Center
  • Genetec Portal (genetec.com)

Procedure

  1. Your integrator creates a new case with GTAC and includes the necessary information:
    • Email contact for the identity provider administrator. They must have sufficient privileges and expertise to set up an application integration for their identity provider.
    • Identity provider URL. For example, https://yourtenant.okta.com.
    • Domains used by the users during sign-in. For example, for users who sign in with myuser@company.com, the domain is company.com.

      This list of domains must include the domains for your users' emails and usernames. Corporate SSO does not work properly if the email and username domains are not configured for your integration.

  2. Genetec verifies the information in the case and schedules a call with the IT administrator to configure the setup together.
  3. Attend the setup call.
    Genetec provides the following parameters to configure a new OIDC application integration for your identity provider:
    Redirect URL
    After a user authenticates, your identity provider sends this URL back in the following format: https://login.genetec.com/signin-oidc-xxxxxxxxxxxx.
    Required scopes
    During the authentication request, these parameters specify what kind of information login.genetec.com is allowed to request for your users. Genetec provides the expected values during the setup call so they can be authorized by your identity provider.
    Grant type
    Specifies how an application requests an access token.
    Response type
    Determines the outcome of an authorization request.
  4. Configure user access for your new OIDC application integration.
    When configuring user access, consider that this integration is effective for the following:
    • Security Center SaaS
    • Genetec ClearID™
    • Genetec Clearance™
    • Genetec Cloudrunner™
    • Genetec Operations Center
    • Genetec Portal (genetec.com)
    Genetec collects the following parameters from your recently configured OIDC application to configure integration into our services:
    • Client ID
    • Client secret
  5. Test your SSO integration.
    Genetec provides a link to a sign-in test sandbox. Signing in with the test link confirms that your identity provider is returning the expected responses.
  6. Genetec moves the server configuration out of the test sandbox to enable third-party authentication for all users. This means that users can sign in using the new OIDC integration for all Genetec customer service portals and cloud-based products mentioned in step 4.
    Note:
    Users must still be manually invited to your Security Center SaaS system.

After you finish

Transfer existing users to your new corporate SSO login service.
Important:
To ensure that user access is not disrupted, you must periodically review your client secret expiration date. Your identity provider administrator is responsible for contacting Genetec to update the client secret before it expires by creating a case in GTAC with the following information:
  • Email contact for the identity provider administrator.
  • Domains used by the users during sign-in.

Once the ticket is received, Genetec schedules a call with the IT administrator to renew the client secret together.