Sign in with Google and Microsoft
Users sign in with their company Google Workspace or Microsoft 365 account, without a password — registered users only.
The Sign in with Google and Sign in with Microsoft buttons on the sign-in page let users start a session with their company account in one click. They're ready on Solk installations; no extra setup is needed.
How it works
- The user clicks a button and picks their account on Google's or Microsoft's own page.
- The provider returns identity only (name, email) — the requested scopes are
openid,email,profile. No access to mailboxes or files is requested. - If the returned email address matches an active user's email on the Users page, the session starts (case-insensitive).
A non-matching address can't sign in: "not a registered user of this workspace — ask your admin for an invitation". So Google / Microsoft sign-in doesn't create accounts; an admin invites the new person, who then signs in with the same address the invitation was sent to.
Security
- Users with two-step verification are still asked for a code after Google / Microsoft sign-in.
- IP restrictions and license rules apply as with password sign-in.
- Unverified Google email addresses are rejected.
- Deactivated users can't sign in with Google / Microsoft either.
Turning it on and off
Admins switch each provider on or off under Settings → Security → Sign in with Google / Microsoft. A disabled provider's button disappears from the sign-in page. Password sign-in always stays available.
On self-hosted installations the buttons appear when GOOGLE_CLIENT_ID / GOOGLE_CLIENT_SECRET or MS_CLIENT_ID / MS_CLIENT_SECRET are set in .env; add https://<installation>/account/email/oauth/callback (or the central relay address) as a redirect URI in the Google Cloud and Microsoft Entra app — the same address used for mailbox connections.