Help Center
How can we help? 👋

Using Single Sign On (SSO) in G2G

The basics of how to get SSO for your organisation in your G2G account

Single Sign-On (SSO) lets your team log in to G2G using your organisation's own identity provider (for example, your existing Microsoft work account), instead of a separate G2G username and password. This article explains what SSO is, how it works in G2G, and how to have it enabled for your organisation.


Q: Can G2G accounts use SSO?

Yes. G2G supports Single Sign-On for your organisation's account. SSO is a fully managed feature, which means it is configured and switched on by the G2G team rather than from within your account.

To get started, reach out to your G2G account support contact and let us know you'd like SSO enabled. We'll then be in touch about what's required from your side to set it up.


Q: How do I turn SSO on or off for my account?

SSO can't be turned on or off from inside your G2G account — not even by an account administrator. It is enabled and managed entirely by the G2G team on your behalf.

If you'd like SSO switched on (or have questions about changing your existing setup), please contact your G2G account support contact and we'll take care of it with you.


Q: What happens once SSO is enabled?

Once SSO is turned on for your account, any user logging in with one of your organisation's configured email domains will be automatically routed to your organisation's own SSO login page when they sign in to the G2G Console.

From there, your users sign in using your organisation's normal identity provider, rather than a separate G2G password.


Q: Will SSO affect users who already have a G2G login?

When an existing user signs in for the first time using SSO, G2G matches them by their email address. If their email matches an existing G2G user, that user's previous username-and-password login is effectively replaced by their new SSO login going forward.

In practice this means your users move over to signing in through your organisation's identity provider, and won't continue using their old separate G2G password. Because of this, it's worth making your team aware of which users will be affected before SSO is switched on.


Q: How does login work in the G2G App (PWA)?

The G2G App will continue to offer both login options. However, as with the Console, once an existing user has logged in using SSO and their email matches an existing user, their old login is replaced by the new SSO user record.


Q: Does SSO start from G2G's side or from our identity provider?

The current SSO setup is service-provider initiated, which means the login process starts from the G2G side — your users begin at G2G and are then routed to your organisation's SSO login page.

Logging in directly from your identity provider's side (IdP-initiated login, for example launching G2G straight from Microsoft Entra) is not configured by default. If IdP-initiated login is something your team would find useful, let your G2G account support contact know and we can look into what would be required to support it.


Q: Which SSO protocols and identity providers do you support?

G2G supports both SAML and OIDC (OpenID Connect), the two standard protocols used for enterprise Single Sign-On. This means we can integrate with Microsoft Entra ID (formerly Azure AD) as well as other identity providers that support these standards.

During setup, the G2G team will work with you to confirm which protocol best suits your environment and gather the configuration details needed to connect G2G to your identity provider. If you're unsure which your organisation uses, your IT or identity team will usually be able to advise.


Q: Who should I contact to enable SSO?

Please reach out to your usual G2G account support contact. Let us know you're interested in SSO, and we'll guide you through what's needed and coordinate enabling it for your organisation.


Did this answer your question?
😞
😐
🤩