Let people sign in to Medialake with their Google or Microsoft account, and control who can create an account that way.
What to expect
With SSO enabled, the login page shows a Google button, a Microsoft Azure button, or both. A user selects one, signs in with Google or Microsoft (choosing an account if they have several), and lands in Medialake. Medialake matches them to an account by email address.
There are no credentials to enter. The connection between Medialake and Google or Microsoft is provisioned as part of your Medialake environment; the Access page only controls whether each option is offered on the login page.
For Azure-specific detail — how Medialake matches Microsoft accounts to users, and what to do if your Microsoft tenant requires administrator approval — see Signing In with Microsoft Azure.
Google and Azure SSO are independent of SAML2. If you use Ping or Okta, see Setting Up SAML2 Single Sign-On with Ping or Okta instead — enabling SAML2 turns both SSO options off.
Before you begin
You need to be a Site Admin.
SAML2 must be switched off. While a SAML2 provider is enabled the SSO switches are locked and the section shows a SAML2 active tag.
Turning a provider on or off
Open the side menu and select Administration → Access.
In the SSO section, find the Google or Azure row.
Turn the Enabled switch on or off. The Status changes to Connected or Disconnected immediately.
The change applies the next time the login page loads. Users who are already signed in stay signed in.
Who can sign in with SSO
People who already have a Medialake account sign straight in, as long as the email address on their Google or Microsoft account matches the one on their Medialake account. They keep their teams, roles and content.
People without an account get one created on their first SSO sign-in only if their email address or domain is on the registration whitelist. Otherwise they are returned to the login page with Email or Domain registration not authorised. The new account uses the name from their Google or Microsoft profile, gets a personal team named after them, and is a Regular User; a Site Admin can change the account type in Manage Users.
Deactivated accounts cannot sign in with SSO.
Managing the registration whitelist
Open Administration → Manage Users, then the Settings tab (the General page).
In the Whitelist section, select Add Whitelist.
Choose DOMAIN to allow everyone with an email address at that domain, or EMAIL to allow one address, enter the value, and save.
To remove an entry, select the trash icon next to it. The whitelist governs who can create an account through SSO or self-registration; it does not affect people who already have one. Inviting someone from Administration → Invitations adds their email address to the whitelist automatically, and revoking the invitation removes it.
Using SSO alongside other methods
Email & password can stay enabled at the same time. A user with a password can use either.
Enabling SAML2 switches both SSO providers off and locks their switches. Disabling SAML2 later does not switch them back on — turn them on again yourself. If SAML2 is the only enabled method, enable Email & password before disabling it, because Medialake will not let you switch off the last sign-in method.
Troubleshooting
Symptom | What to check |
The SSO switches are grayed out and the heading shows SAML2 active | A SAML2 provider is enabled. Switch it off on the same page, then enable SSO. |
SSO is disabled because one or more SAML2 integrations are active. | Same cause as above — SAML2 must be disabled first. |
At least one sign-in method must remain enabled. | You tried to switch off the last enabled method. Enable another one first. |
The Google or Microsoft Azure button is missing from the login page | The provider is switched off, or SAML2 is enabled and has replaced the SSO buttons with its own. |
A new user is sent back to the login page with Email or Domain registration not authorised. | Their email address or domain is not on the registration whitelist. Add it, or invite them from Administration → Invitations. |
A user signs in with SSO and lands in an empty account instead of their existing one | The email address on their Google or Microsoft account differs from the one on their Medialake account. Medialake matches on the exact address. |
If the issue continues, contact [email protected] with your Medialake address, the provider (Google or Azure), and the message the user saw.
Questions about SSO? Contact [email protected].
