> ## Knowledge Base Index
> Fetch the complete knowledge base index at: https://help.superpath.io/sitemap.xml
> Use this file to discover available pages before exploring further.
> Pure-Markdown content can be obtained by appending a '.md' suffix to the content URLs listed in the sitemap (without the trailing slash).

# Configuring Google SSO

# Configuring Google SSO

**In this article:**
* Overview
* How to enforce Google sign-in
* Things to keep in mind
* FAQs
* Who can do this

## Overview
Enforcing Google sign-in means everyone in your organisation must access SuperPath using their Google login. It removes the need for separate email and password credentials and lets you piggyback on your organisation's own Google security policies (such as two-factor authentication and account provisioning).

You do this from the **Enforce authentication type** setting, which lets you restrict your account to one or more sign-in methods. To require Google, you select **Google Login** as the enforced method.

## How to enforce Google sign-in
1. Make sure you are currently signed in to SuperPath using your Google login. You can only enforce a sign-in method that you yourself are using.
2. Go to **Settings → Security**.
3. Find the **Enforce authentication type** section and turn its toggle on.
4. In the method selector, choose **Google Login**.
5. Click **Save changes** in the bar at the top of the page.

> **Note:** Once enforced, everyone in your organisation will only be able to sign in with Google. Team members will not be able to sign in using any other method, so make sure your people have Google accounts on the same email addresses they use in SuperPath before you turn this on.

## Things to keep in mind
* **Enforce authentication type** is only available on paid plans.
* You can only enforce a method you are currently signed in with — so to enforce Google, sign in with your Google login first. SuperPath will block the change otherwise.
* You can enforce more than one method at once (for example Google Login and Microsoft Login) by selecting each one in the same setting.
* This setting controls *how* people sign in. It is separate from **Custom SSO (SAML)**, which connects your own SAML identity provider, and from the domain-based **Auto approve new registrations** setting.

## FAQs
**Where did the old "Enforce Google SSO" toggle go?**
Google enforcement now lives inside the **Enforce authentication type** setting on **Settings → Security**. Turn the toggle on and select **Google Login** to get the same result.

**Can I require both Google and Microsoft logins?**
Yes. Select each method you want to allow in the **Enforce authentication type** selector — team members must then use one of the methods you've chosen.

**Why can't I select Google Login?**
You can only enforce the method you're currently signed in with. If you're signed in with email and password, the enforcement section won't let you require Google — sign in with Google first.

## Who can do this
Only **Owners** and **Admins** can open **Settings** and change security settings — the whole `/settings` area is restricted to these two roles, so **Managers**, **People Managers**, **Content Managers**, **Instructors**, **Employees** and **Restricted** users cannot reach it. Enforcing Google sign-in also requires a paid plan and that you are signed in with Google yourself.