Skip to main content

Set up Google or Microsoft single sign-on (SSO)

Turn on Google or Microsoft SSO under Account Settings > Authentication, decide whether to require it, and understand what changes for sign-in and invitations.

Written by MaryGrace Flores

Account administrators turn on single sign-on under Account Settings > Authentication. Switch on Google or Microsoft under SSO Providers and the matching Sign in with Google or Sign in with Microsoft button appears on the sign-in page and on invitation pages for everyone in the account. Switch on Require SSO Login and select Save if password sign-in should be hidden as well. Equip supports Google and Microsoft only. There is no SAML, Okta, or other identity provider option, and there is nothing to configure on the Google or Microsoft side before you start.

Who can do this, and where

  • Web only, under Account Settings > Authentication.

  • The page opens for anyone whose role can see Account Settings. Saving needs the Account Settings module at the Administrator level, which the default Super Admin and General Admin roles have. A role with Account Settings at the Viewer level sees the provider switches and the Require SSO Login toggle disabled, and no Save button.

  • The setting applies to every team member and participant in the account. It cannot be limited to some roles or people.

Turn SSO on

  1. Select your profile photo or initials in the top-right corner and choose Account Settings.

  2. Select Authentication in the settings menu. The page is titled Authentication Settings.

  3. Under SSO Providers, switch on Google, Microsoft, or both. Each switch saves on its own the moment you change it; there is no confirmation message.

  4. If everyone must use SSO, switch on Require SSO Login (the toggle asks "Would you like to require all users to use Single-Sign-On?") and select Save. Equip confirms with "Authentication information updated successfully."

What changes for your users

  • Sign-in page. After a person enters their email and selects Next, Equip shows a button for each provider you enabled. With Require SSO Login off, the email and password form still appears below an Or divider. With it on, only the provider buttons appear and the Forgot your password? link is gone.

  • Invitations. With Require SSO Login on, the invitation page is titled Accept Invitation and offers only the provider buttons. Accepting with Google or Microsoft activates the person without setting a password. With Require SSO Login off, the Set up your profile page shows the provider buttons above the usual name, time zone, and password form, and the person can use either.

  • Email matching. Equip matches the signed-in Google or Microsoft identity to the person's Equip login email, ignoring capitalization. For Google it uses the account's email address. For Microsoft it accepts the email address, the user principal name, or the preferred username. If none of them match an Equip login, sign-in fails with "We couldn't find an account with that email address."

  • Mobile app. The Equip mobile app looks up the account by email the same way and offers the same providers. Require SSO Login applies there too.

  • Calendar Settings. Once any provider is on, a Calendar Settings entry appears in Account Settings for calendar sync.

  • Existing users. Nothing changes for them until they next sign in, and no one is signed out. Password users keep their passwords unless you require SSO. After a person signs in with a provider once, Equip treats them as an SSO user: typing a password sends them to a page saying "Your account requires SSO to login." until they reset their password, which switches them back.

Make SSO optional again or turn it off

  • To make SSO optional, switch off Require SSO Login and select Save. People who last signed in with a provider keep being sent to it until they reset their password.

  • To remove a provider, switch it off under SSO Providers. This also deletes every calendar connection team members made with that provider.

  • Switch off Require SSO Login before you remove the last provider. With Require SSO Login on and no provider enabled, the sign-in page shows no sign-in option at all after the email step, and nobody in the account can sign in.

Limits and what the errors mean

  • "No account exists for [email protected]." on the sign-in page means no Equip login uses that address. Check the Team Members or Participants list.

  • "We couldn't find an account with that email address." after the provider returns means the provider's email does not match any Equip login, or matches more than one. Correct the Equip email (see Update a User's Login Email) or have the person choose the right provider account.

  • "We encountered a problem. Please try again!" means the provider did not complete the sign-in: the person cancelled, denied access, or their Microsoft organization has not approved the Equip application yet.

  • "Invalid email or password." immediately after a successful Google or Microsoft sign-in means the person is Inactive in Equip. Reactivate them from the Access tab of their profile.

  • "Please download the Equip mobile app to manage your account." means the sign-in worked but the person is a participant, or a team member whose role does not include web access.

  • Two providers only. Google and Microsoft are the only options, and Equip uses its own application registration with each; you do not enter client IDs or secrets.

FAQ

Do I need to register Equip in Google Workspace or Microsoft 365 first?
No. There is nothing to configure on the provider side. Switch the provider on under Account Settings > Authentication and the button appears on the sign-in page. The one exception is a Microsoft organization that blocks users from approving new applications; there, a Microsoft administrator must grant consent to the Equip application before staff can finish signing in.

What does Require SSO Login do?
It hides the email and password form on the sign-in page and on invitation pages for everyone in the account, leaving only the Google and Microsoft buttons you enabled. It does not delete anyone's password and it does not sign anyone out; it stops passwords from being offered. Turn it off and select Save to bring the password form back.

Can people keep using their password if I turn on Google or Microsoft but not Require SSO Login?
Yes. The sign-in page shows the provider buttons and the password form together, separated by "Or". Each person chooses. Someone who signs in with a provider is routed to that provider on later sign-ins until they reset their password.

Which email address do my users need?
The email on their Equip profile must be the address of the Google or Microsoft account they sign in with. Equip ignores capitalization but otherwise needs an exact match; for Microsoft the user principal name or preferred username also counts. If a person's provider address is different, update their Equip email first (see Update a User's Login Email).

Does SSO work in the Equip mobile app?
Yes. The app asks for the email address, finds the account, and offers the same Google or Microsoft options that are enabled for the account. If Require SSO Login is on, the app does not offer password sign-in either.

Why does Microsoft show "Need admin approval" to my staff?
That page comes from your organization's Microsoft settings, not from Equip. Some Microsoft 365 organizations do not allow individual users to approve sign-in applications, so a Microsoft administrator must grant consent to the Equip application once for the whole organization. Until then, Equip shows "We encountered a problem. Please try again!" after the Microsoft step. See "Sign in with Google or Microsoft, and what to do when it fails" for what to tell your Microsoft administrator.

Can I require SSO for team members but let participants use passwords?
No. Require SSO Login is one setting for the whole account, on the web and in the mobile app. If some people cannot use Google or Microsoft, leave Require SSO Login off; everyone then chooses between the provider button and a password.

Will turning on SSO sign everyone out or change their passwords?
No. Enabling a provider or requiring SSO does not end any session and does not change any password. People see the new options the next time they reach the sign-in page.

Related

  • Sign in with Google or Microsoft, and what to do when it fails

  • Reset your password

  • Update a User's Login Email

  • Managing Account Settings

  • Managing Event Settings

  • Inviting Your Team

Did this answer your question?