> Markdown version of https://docs.laavat.io/getting-started/onboarding/identity-provider-setup/ from the LAAVAT PKI and Signing Platform documentation. All pages: https://docs.laavat.io/llms.txt

# Identity Provider Setup

Once you have configured your identity provider (Microsoft Entra ID or Google Cloud)
and created the required security groups,
request an identity provider setup link from [support@laavat.io](mailto:support@laavat.io).

The identity provider setup is a guided wizard that securely collects
your identity provider credentials and group configuration.

## How it works

1. **Request a setup link**: Contact [support@laavat.io](mailto:support@laavat.io) to request your identity provider setup invitation link.
2. **Select your identity provider**: Open the link and choose Microsoft Entra ID or Google Workspace.
3. **Enter credentials**: Provide the required credentials for your identity provider. The service validates them in real time.
4. **Configure security groups**: Enter the writer and approver group identifiers. The service verifies that the groups are accessible.
5. **Review and submit**: Confirm your configuration. The platform services pick up the new tenant configuration automatically within 15 minutes.

> **Note**
> Each setup link is single-use and expires after a limited time. Contact [support@laavat.io](mailto:support@laavat.io) if your link has expired.

## After Onboarding

After the initial setup, ongoing identity provider and truststore management is
performed in the GUI:

- **Rotating IdP secrets**: see [Identity Provider Management](https://docs.laavat.io/gui/admin/idp/).
- **Managing truststores (mTLS / EST / provisioning)**: see [Truststore Management](https://docs.laavat.io/gui/admin/truststore/).
