ITPS CRM

Help › Team & security

Signing in with your work account

Let your team use the Google or Microsoft account they already have.

Single sign-on means your team signs in with the work account they already

have — Google Workspace or Microsoft 365 — instead of another password to

remember and reset.

There is nothing to register and no developer console to visit. Switch on

the provider you use and tell us which email domains are yours.

Setting it up

  1. Go to Settings → Single Sign-On. You need to be an account owner.
  2. Tick Google Workspace or Microsoft 365 / Entra ID — whichever your

company uses. You can tick both.

  1. Under Your email domains, type the domains you own, separated by

commas: acme.com, acme.co.uk. Subdomains are included automatically, so

acme.com also covers sales.acme.com.

  1. Save. A Sign in with Google button now appears on the login page.

Only people whose address is at one of your domains can sign in this way,

and only if the provider has verified that address. A personal Microsoft

account is never accepted, even at a domain you have listed.

Who can actually get in

Listing a domain does not create accounts. Your team still needs to be

invited on Settings → Team & Roles first — single sign-on changes how

they prove who they are, not whether they belong here.

If you would rather not invite people one at a time, tick **Anyone at a

trusted domain can join** and choose the role they should get. Then a

colleague signs in with their work account and has a seat straight away.

Leave it off unless everyone with an address at those domains should be

able to see this workspace.

Turning passwords off

Require single sign-on stops your team using a password at all, so

access follows whatever your IT department does with the work account —

when they disable someone's Google account, that person is out of here too.

Account owners always keep their password. That is deliberate: if single

sign-on ever stops working, an owner can still get in and switch this off.

When somebody's account changes

If a person's work account is deleted and recreated, or their email address

is handed to a colleague, your provider now treats them as a different

person and they will not be let in — deliberately, because otherwise the

new holder of an old address would walk straight into somebody else's

records.

Fix it on Settings → Single Sign-On: find them under Who's connected

and press Disconnect. The next work account they sign in with becomes

the linked one.

If a sign-in is refused

The message is the same whatever went wrong, on purpose — a login page that

explained which addresses exist here would be telling strangers. Check, in

order:

  • the address is at a domain listed on this page
  • the person has been invited, and their invitation was accepted
  • the provider they are using is ticked above
  • for Microsoft: they are using a work or school account, not a personal one
← All guides Still stuck? Open a support ticket