# Sign in with Google and Microsoft

> Users sign in with their company Google Workspace or Microsoft 365 account, without a password — registered users only.

The **Sign in with Google** and **Sign in with Microsoft** buttons on the sign-in page let users start a session with their company account in one click. They're ready on Solk installations; no extra setup is needed.

## How it works {#how}

1. The user clicks a button and picks their account on Google's or Microsoft's own page.
2. The provider returns identity only (name, email) — the requested scopes are `openid`, `email`, `profile`. No access to mailboxes or files is requested.
3. If the returned **email address** matches an active user's email on the **Users** page, the session starts (case-insensitive).

A non-matching address can't sign in: *"not a registered user of this workspace — ask your admin for an invitation"*. So Google / Microsoft sign-in **doesn't create accounts**; an admin [invites](/users-and-roles) the new person, who then signs in with the same address the invitation was sent to.

## Security {#security}

- Users with **two-step verification** are still asked for a code after Google / Microsoft sign-in.
- **IP restrictions** and **license** rules apply as with password sign-in.
- Unverified Google email addresses are rejected.
- Deactivated users can't sign in with Google / Microsoft either.

## Turning it on and off {#settings}

Admins switch each provider on or off under **Settings → Security → Sign in with Google / Microsoft**. A disabled provider's button disappears from the sign-in page. Password sign-in always stays available.

On self-hosted installations the buttons appear when `GOOGLE_CLIENT_ID` / `GOOGLE_CLIENT_SECRET` or `MS_CLIENT_ID` / `MS_CLIENT_SECRET` are set in `.env`; add `https://<installation>/account/email/oauth/callback` (or the central relay address) as a redirect URI in the Google Cloud and Microsoft Entra app — the same address used for mailbox connections.