Skip to main content

Sign in with Google or Microsoft, and what to do when it fails

Sign in to Equip on the web or in the mobile app with Google or Microsoft, accept an invitation with SSO, and fix the common failures including Microsoft's admin approval prompt.

Written by Trent Kocurek

On the Equip sign-in page, enter the email address on your Equip profile, select Next, then select Sign in with Google or Sign in with Microsoft and choose the account that uses that same email address. Equip matches you by email, so the Google or Microsoft account must carry the address Equip knows you by. When sign-in fails, the cause is almost always one of five things: a different email at the provider, an invitation that was never accepted, an Inactive status in Equip, a role without web access, or a Microsoft organization that has not yet approved the Equip application.

Who can do this, and where

  • Any team member or participant in an account where an administrator has switched on Google or Microsoft under Account Settings > Authentication. If no provider button appears after you enter your email, the provider is not enabled for your account; ask an administrator.

  • Web: team members whose role includes web access. Mobile app: participants, and team members with mobile access enabled. Both use the same providers and the same email matching.

Sign in on the web

  1. Go to the Equip sign-in page, titled Find your account. Enter your email address and select Next.

  2. The page now shows your organization's name and its sign-in options. Select Sign in with Google or Sign in with Microsoft.

  3. If the provider asks which account to use, pick the one whose email matches your Equip email. Google may also show a permissions screen; approve it to continue.

  4. Equip signs you in and shows "Signed in successfully!". Any other message is explained below.

To start over with a different email, select Not your account? Click here. under the sign-in options.

Accept an invitation with Google or Microsoft

  1. Open your invitation email and select Accept Invitation.

  2. If your organization requires SSO, the page is titled Accept Invitation and shows only the provider buttons. Otherwise the Set up your profile page shows the buttons above the name, time zone, and password form, and you can use either.

  3. Select the provider and sign in with the account whose email matches the address the invitation was sent to. A different address fails with "We couldn't find an account with that email address."

  4. Equip confirms with "Invitation accepted!". Team members whose role has web access land in the web app. Participants, and team members whose role has no web access, are sent to the mobile app download page; install or open the app and sign in there with the same provider.

Sign in in the mobile app

  1. Enter your email address. The app finds your organization.

  2. Choose Google or Microsoft from the options shown. Password sign-in appears only when your organization allows it.

  3. Sign in with the matching account. If the app cannot find your account or blocks access, see the errors below and "Equip: Independence sign-in troubleshooting".

Microsoft says "Need admin approval"

Some Microsoft 365 organizations do not let individual users approve sign-in applications. Microsoft then shows a Need admin approval page before Equip hears back, and Equip shows "We encountered a problem. Please try again!" when you return. Equip cannot grant this approval. A Microsoft administrator for your organization has to grant consent to the Equip application once for everyone, either through the request link Microsoft offers on that page or from the Microsoft Entra admin center. When several colleagues are blocked at the same time, this is the cause; there is nothing to fix on the individual Equip profiles. If your Microsoft administrator needs details about the Equip application, contact Equip Support.

Limits and what the errors mean

  • "No account exists for [email protected]." on the email step: no Equip login uses that address. Check the address in your invitation email or with an administrator.

  • "We couldn't find an account with that email address." after the provider returns: the Google or Microsoft account you chose does not carry your Equip email, or the same address belongs to more than one Equip login. Try again and pick the right account, or ask an administrator to update your Equip email (see Update a User's Login Email).

  • "We encountered a problem. Please try again!": the provider did not finish the sign-in. You cancelled, denied a permission, or Microsoft stopped at admin approval.

  • "Invalid email or password." right after the provider signs you in: you are Inactive in Equip. An administrator reactivates you from the Access tab of your profile.

  • "Please download the Equip mobile app to manage your account.": sign-in worked, but you are a participant or a team member without web access, so the web app is not available to you. Use the mobile app.

  • "Your account requires SSO to login.": you entered a password, but your last sign-in was with Google or Microsoft. Use the provider button on that page.

  • "You already have an account. Please sign in!": you used an Equip sign-up link instead of the sign-in page. Go to the sign-in page.

  • "Your session has expired due to inactivity. Please sign in again.": your organization's inactivity limit was reached. Sign in again; Equip returns you to the page you were on.

  • Matching is by email address only. Equip does not read group membership or roles from Google or Microsoft. Your Equip role decides what you can do after sign-in.

FAQ

Which email address do I use with Google or Microsoft?
The address on your Equip profile, which is the one your invitation was sent to. Equip ignores capitalization but otherwise needs an exact match. For Microsoft, the user principal name or preferred username on your Microsoft account also counts. If your Google or Microsoft address is different, ask an administrator to update your Equip email before you try again.

I picked the wrong Google or Microsoft account. How do I switch?
On the sign-in page select "Not your account? Click here." to clear the lookup, enter your email, and select Next again. Equip passes that email to Google or Microsoft as a hint, and asks Microsoft to show its account chooser rather than reuse the last account. If the provider still signs you in with the wrong account, sign out of that provider in your browser first, then try again.

Why does Microsoft ask for admin approval, and who fixes it?
Your Microsoft 365 organization blocks users from approving applications on their own. Only a Microsoft administrator in your organization can grant consent to the Equip application, after which the prompt disappears for everyone. Equip cannot approve it for you, and resetting your Equip password does not help. Send your Microsoft administrator the request from the Need admin approval page, or ask Equip Support for the application details they need.

Why does Google ask me to allow access every time I sign in?
Equip asks Google for ongoing access, which is what lets calendar sync keep working after you sign in, and Google shows its permission screen for that on each sign-in. Approve it to continue; declining ends with "We encountered a problem. Please try again!".

Can I use a password instead of Google or Microsoft?
Only when your organization has not turned on Require SSO Login. If the sign-in page shows a password form under "Or", you can request a password reset with Forgot your password?, set a password, and Equip switches your login back to email and password. If the page shows only provider buttons, passwords are not accepted for your account.

I signed in with Microsoft, but Equip sent me to a page about downloading the app. Why?
Your sign-in succeeded, but the web app is not available to you. Participants always use the mobile app. Team members in a supporter role can use the web app only when an administrator switched on Web Access Enabled for them under the Access tab of their profile. Ask an administrator to turn it on, or use the mobile app.

My organization just turned on Require SSO Login. Do I need to do anything?
No. The next time you reach the sign-in page, enter your email, select Next, and use the Google or Microsoft button. Your old password is no longer offered, and nothing on your profile changes. If you were already signed in, your session continues until it expires.

Related

  • Set up Google or Microsoft single sign-on (SSO)

  • Reset your password

  • Update a User's Login Email

  • Understanding Team Member Statuses

  • Enabling Web Access for Multiple Team Members

  • Equip: Independence sign-in troubleshooting

  • Team member access in the Equip mobile app

Did this answer your question?