Implementing SSO with Google
Google SSO lets your team sign in to Manifestly with their Google Workspace accounts, so there is no separate Manifestly password to manage, and removing someone from Google removes their access here too.
SSO is an Enterprise feature. If the SSO tab tells you it is available for Enterprise plan customers, it is not enabled for your account.
Set it up
- Open your account settings and go to the SSO tab.
- Click Set up Google Sign On.
- Enter a name. Letters and numbers only, no spaces, because it becomes part of your sign-in URL.
- Enter your domain, the Google Workspace domain your people's email addresses use.
- Save.
After setup
The SSO tab then shows the configuration's status, your Sign in URL and the domain, with Edit and Delete alongside.
The sign-in URL is the one to give your team, and the one to put in your intranet or password manager. Bookmarking it saves people having to find the SSO route from the ordinary sign-in page.
One method at a time
An account has a single SSO configuration: Google or SAML, not both. If you set up Google and later move to an identity provider like Okta or Azure AD, delete the Google configuration first. See SAML based SSO.
Before you turn it on
- Check the domain matches the addresses people actually sign in with. A mismatch locks out the people it was meant to admit.
- Keep one admin who can still get in by another route while you test, so a misconfiguration does not lock everyone out at once.
- Tell people before you switch, since their sign-in flow changes.
This is not the same as "Sign In with Google"
Individual users can add Google as a personal sign-in method without any account-level SSO. That is a convenience for one person; this is a policy for the organisation. See Adding Sign In with Google.