> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/features/external-openid-providers/external-oidc-secure-enrollment.md).

# External OIDC secure enrollment

{% hint style="warning" %}
**Availability**

This feature is available Business and Enterprise plan.
{% endhint %}

When [External OIDC is enabled,](/features/external-openid-providers.md) users have the possibility to [securely enroll (automatically create a Defguard account) and very easily configure their desktop client](/using-defguard-for-end-users/enrollment/with-external-sso-google-microsoft-custom.md) just by logging in with the SSO provider.

## Step-by-step guide

1. Go to **Edge** site

<figure><img src="/files/rSpn5u7yRdJcMtKR9yH0" alt=""><figcaption></figcaption></figure>

2. Click "**Launch enrollment**"

<figure><img src="/files/6lrwIjRcWpcoZCCnyxfF" alt=""><figcaption></figcaption></figure>

3. Click "**Sign in with Google**" (in this example)

For this to work, see [External SSO/OpenID providers](/features/external-openid-providers.md#openid-enrollment).

## Troubleshooting

### Sign in with External SSO section not visible after configuring the external SSO

Make sure the External SSO is configured properly and reachable from the Defguard Core service.&#x20;

After clicking the **Launch enrollment** button check the Core service logs. Look for error messages similar to:

```
ERROR defguard_proxy_manager::handler: message=Failed to setup external OIDC provider client: Authorization error: Failed to discover provider metadata, make sure the URL is correct: http://example.com/realms/master. Error details: Request failed [2.0.1 Debian 13.0.0 x86_64]
```
