> For the complete documentation index, see [llms.txt](https://docs.e6data.com/product-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.e6data.com/product-documentation/~/changes/0iCkDjvnPldS7yucryRX/access-control/single-sign-on-sso/google-sso.md).

# Google SSO

* [Enable SSO via Google IdP](#enable-google-sso)
* [Login via Google IdP](#login-via-google-sso)
* [Add Users to e6data via Google IdP](#add-users-to-e6data-via-google-sso)
* [Remove Users from e6data via Google IdP](#remove-users-from-e6data-via-google-sso)
* [Disable Google IdP](#disable-google-sso)

## Enable SSO via Google IdP

1. Navigate to **Access Control > SSO** from the left side menu.
2. Click on **Add Identity Provider**
3. Provide a name for your Identity Provider
4. Select **Google**
5. Click **Next**
6. Follow these steps to [add and configure a custom SAML 2.0 application](https://support.google.com/a/answer/6087519?hl=en) in Google Workspace.
   1. In Google Workspace, when asked for an **ACS URL & Entity ID**, copy & paste the **ACS URL & Entity ID** shown on the e6data SSO page.
   2. Select EMAIL as the **Name ID Format**.
   3. Match the Attributes in Google Workspace to those shown on the e6data SSO page.
7. Under IdP details, click **Choose File** & upload the **Metadata file** previously downloaded from Google Workspace in step 4.
8. Click **Save**
9. Users can now log in to e6data using Google IdP.

## Login via Google SSO

Users can log in by:&#x20;

* Clicking the **Single Sign-On (SSO)** button in the e6data platform login page.
* Clicking the newly created custom SAML app inside Google Workspace.

SuperAdmin will be able to log in using both SSO and username/password authentication.

## Add Users to e6data via Google IdP

Please follow [this guide from Google to enable user in your Workspace organization](https://docs.aws.amazon.com/singlesignon/latest/userguide/assignuserstoapp.html)[ ](https://support.google.com/a/answer/6087519?hl=en)to use the custom SAML 2.0 application created during SSO setup.

[Follow this guide to provide access on based on groups.](https://support.google.com/a/answer/9050643)

Once a user is added they will be able to [log in using Google IdP](#login-via-google-sso).

By default, new users are assigned the Viewer role (least privilege). The user's role [should be changed](/product-documentation/~/changes/0iCkDjvnPldS7yucryRX/access-control/users.md) by the SuperAdmin or AccessAdmin after the first login.

## Remove Users from e6data via Google IdP

Users can be removed by either removing them from Google IdP or moving them to a group or organization that doesn't have access to e6data.

## Disable SSO via Google IdP

1. Navigate to **Access Control > SSO** from the left side menu.
2. Toggle **Integrate SSO** to the disabled position.

*<mark style="color:blue;">**Important: When SSO is disabled, each user added using SSO will need to reset their password.**</mark>*
