Can I switch from one SSO provider to another (for example, Google to Microsoft) while keeping the same email?
Yes. If you originally signed up using one SSO provider (such as Google) and want to log in with another (such as Microsoft) using the same email address, you do not need to recreate your account.
You would need to proceed by connecting the new provider to your existing account, which adds it as an additional login option.
- While you are logged in (using your current ex. Google SSO), go to your Settings >My Calendars and connect your Outlook calendar.
- Once Outlook calendar is connected, it is added as an additional authentication option on the same account. You can then log in with either Google or Microsoft.
Why can't a user log in with SSO after they were invited to our workspace?
The most common cause is that the user registered with the wrong method. When a workspace has SSO (Microsoft, Google) set up, invited users must create their account by choosing Sign up with Microsoft or Sign up with Google, not the standard Sign up button with email and password.
If a user signs up with email and password while workspace has SSO login only enabled it creates a loop. The account exists as an email-and-password account, but the security policy blocks that method, and the SSO button does not recognize the account. The user then sees an error when trying to log in via SSO.
How do we fix a user who is stuck in this loop?
There are two ways to resolve it. The first is recommended because it preserves the user's meeting history.
Option 1 - Temporary access (recommended)
- A workspace admin needs to temporarily enable the Email + Password login method in the workspace security settings.
- The user then logs in using their original email and password.
- Once inside, the needs to go to their settings and connects their Microsoft or Google calendar depending on the workspace SSO.
- Once that connection is made, the Admin turns the Email + Password restriction back on. The user can now log in successfully via SSO going forward.
Option 2 - Account reset
If you prefer not to change your workspace security settings, you can delete the user from the workspace, they will need to delete their account, and them sign up again with the workspace invite link from scratch. When they rejoin, they must select Sign up with Microsoft or Sign up with Google immediately.
|
|
Please note that this option results in the loss of any personal meeting history currently associated with that user's profile. |
How do we prevent this from happening to new users?
When you invite users to an SSO-enabled workspace, let them know upfront that they must accept the invitation and register using the Sign up with Microsoft or Sign up with Google button that matches your SSO provider. They should not use the standard email-and-password option, even though it appears on the screen.
Can we just re-send the invitation to fix it?
Re-sending the invitation alone does not resolve the loop, because the incorrectly created account already exists. You will need to use Option 1 or Option 2 above. Option 1 keeps the user's history intact, while Option 2 starts the account fresh.
Comments
0 comments
Please sign in to leave a comment.