Home / Support Guides / Users & Security / Single Sign-On (SSO) with Google and Microsoft in Shape Software
Users & Security

Single Sign-On (SSO) with Google and Microsoft in Shape Software

Shape supports Single Sign-On (SSO) with Google and Microsoft accounts, giving users the option to sign in to Shape using the same account they already use for Google Workspace, Gmail, Microsoft 365, Outlook, or Microsoft Entra ID.

Once SSO is connected, users can select Sign in with Google or Sign in with Microsoft from the Shape login page instead of entering their Shape username and password.

By default, enabling SSO adds another way to log in. It does not remove the standard Shape username and password option.

SSO is also supported when signing in through the Shape mobile app.

What Is Single Sign-On (SSO)?

Single Sign-On allows a user to authenticate through an existing identity provider rather than entering a separate set of credentials for every application they use.

In Shape, SSO is available for:

  • Google accounts
  • Google Workspace accounts
  • Microsoft accounts
  • Microsoft 365 accounts
  • Microsoft Entra ID, formerly Azure Active Directory, managed accounts

The email address associated with the user’s Google or Microsoft account must match the email address configured on their Shape user profile.

For example, if a user’s Shape account is registered as john@company.com, they should authenticate using the Google or Microsoft account associated with john@company.com.

Why Use SSO with Shape?

For organizations already using Google or Microsoft for employee accounts, SSO can make accessing Shape easier for users and fit more naturally into the organization’s existing account management processes.

Instead of remembering another set of credentials, users can authenticate using an account they already use every day.

SSO can also be particularly helpful when an organization centrally manages employee access through Google Workspace or Microsoft.

If an employee’s Google or Microsoft account is disabled, they will no longer be able to authenticate to Shape using that SSO account.

Keep in mind that SSO does not replace Shape’s own user access controls. A user must still have an active Shape account and the appropriate Shape permissions to access the system.

How to Enable Google or Microsoft SSO in Shape

SSO is configured by a Shape administrator.

To get started:

  1. Log in to Shape as an administrator.
  2. Navigate to API Integrations.
  3. Locate the applicable Google or Microsoft login integration.
  4. Select Connect.
  5. Complete the authorization process.

In many cases, that’s all that’s required.

Depending on your organization’s Google or Microsoft security policies, an administrator may also need to approve Shape Software within the organization’s Google Workspace or Microsoft environment.

Google Workspace Administrator Approval

Some Google Workspace environments restrict which third-party applications users can access.

If your organization has these restrictions enabled, a Google Workspace administrator may need to locate and approve Shape Software from the Google Admin environment before users can authenticate successfully.

This approval takes place within Google, not within Shape.

Because Google Workspace security settings vary between organizations, contact your IT administrator or Shape Support if the connection is being blocked or you aren’t sure what needs to be approved.

Microsoft 365 and Microsoft Entra ID Administrator Approval

Organizations using Microsoft 365 or Microsoft Entra ID may have similar restrictions.

Depending on your Microsoft environment, an administrator may need to locate Shape Software within Microsoft and approve the application or grant the appropriate organizational consent.

This configuration takes place within your Microsoft administration environment rather than within Shape.

If Microsoft is preventing the connection, your IT administrator and Shape Support can help determine where authorization is being blocked.

How Users Sign In After SSO Is Enabled

Once the applicable integration has been connected, users will see the SSO login option when accessing Shape.

They can select Sign in with Google or Sign in with Microsoft.

The user then authenticates through Google or Microsoft using the account associated with their Shape email address.

Once authentication is successful, they are returned to Shape.

The same SSO functionality is available through the Shape mobile app.

Can Users Still Sign In With Their Shape Password?

Yes.

By default, enabling Google or Microsoft SSO does not disable Shape’s normal username and password authentication.

Users can choose between:

  • Their Shape username and password
  • Google authentication
  • Microsoft authentication

This gives organizations the flexibility to introduce SSO without immediately changing how every user accesses Shape.

Requiring SSO for Your Organization

Organizations that want to require SSO rather than simply offer it as an additional login option should contact Shape Support.

Shape can configure the applicable accounts so that standard email/password authentication is no longer available, requiring users to authenticate through the organization’s approved SSO method.

We recommend coordinating this change with your IT team before enforcing SSO across your organization.

Using Shape Two-Factor Authentication with SSO

Shape’s two-factor authentication (2FA) can still be used when Google or Microsoft SSO is enabled.

These authentication steps operate separately.

For example, a user may:

  1. Select Sign in with Google.
  2. Complete Google’s authentication process, including any authentication requirements configured by their organization.
  3. Return to Shape.
  4. Complete Shape’s own 2FA verification if it is enabled for their Shape account.

The same concept applies when using Microsoft SSO.

This means organizations do not need to choose between SSO and Shape 2FA. They can use both.

For organizations focused on protecting account access, we recommend reviewing your Shape 2FA settings in addition to your preferred login method.

SSO and Multiple Shape Branches

SSO is generally enabled at the individual Shape system or branch level.

If your organization operates multiple Shape branches, the integration may need to be enabled for each applicable branch.

For larger or multi-branch organizations, contact Shape Support. Our team can help coordinate enabling SSO across your Shape environment rather than requiring administrators to configure each branch individually.

Users will still only have access to the Shape systems, branches, records, and functionality their Shape account is authorized to access.

What Happens When a User Is Deactivated?

SSO does not override Shape user management.

If a user’s Shape account is deactivated, they cannot regain access simply because their Google or Microsoft account remains active.

Likewise, if the Google or Microsoft account being used for SSO is disabled, the user can no longer authenticate to Shape through that account.

This makes it important to maintain both your Shape user accounts and your organization’s Google or Microsoft accounts as employees join, change roles, or leave the organization.

Troubleshooting Google or Microsoft SSO

If a user cannot sign in through Google or Microsoft, start with a few basic checks:

  1. Confirm SSO is connected for the applicable Shape system or branch.
  2. Confirm the user’s Google or Microsoft email matches the email configured on their Shape user profile.
  3. Confirm the user’s Shape account is active.
  4. Confirm their Google or Microsoft account is active.
  5. Check whether your organization’s Google Workspace or Microsoft security policies require administrator approval for Shape Software.
  6. If Shape 2FA is enabled, make sure the user is completing the additional Shape verification step.

There are several places where an SSO request can be restricted, particularly in organizations with tightly controlled Google or Microsoft environments.

If you’re unable to determine the cause, contact Shape Support and your organization’s IT administrator. We can help determine whether the issue is occurring within Shape or during the Google or Microsoft authorization process.

Frequently Asked Questions

Does Shape support Single Sign-On?+

Yes. Shape supports SSO using Google and Microsoft accounts.

Does Shape support Google Workspace SSO?+

Yes. Organizations using Google Workspace can connect Google authentication to Shape. Depending on your Google Workspace security configuration, an administrator may need to approve Shape Software.

Does Shape support Microsoft 365 or Microsoft Entra ID SSO?+

Yes. Shape supports Microsoft authentication, including accounts managed through Microsoft 365 and Microsoft Entra ID. Your Microsoft administrator may need to approve Shape depending on your organization’s security policies.

Can I use a regular Gmail or Microsoft account?+

Yes, provided the account corresponds with the email address associated with your Shape user.

Does my SSO email need to match my Shape email?+

Yes. The email associated with the Google or Microsoft account should match the email configured for the Shape user.

Does enabling SSO disable my Shape password?+

No. By default, connecting SSO gives users an additional login option. Standard Shape username and password authentication remains available.

Can we require employees to use SSO?+

Yes. If your organization wants SSO to be required rather than optional, contact Shape Support. Our team can help configure the applicable accounts accordingly.

Can I use Shape 2FA and SSO together?+

Yes. Shape’s two-factor authentication can remain enabled alongside Google or Microsoft SSO.

After authenticating through Google or Microsoft, users with Shape 2FA enabled will still be prompted to complete the applicable Shape verification.

Does SSO work in the Shape mobile app?+

Yes. SSO is also supported when accessing Shape through the mobile app.

Do we need to enable SSO separately for every branch?+

SSO is generally enabled at the Shape system or branch level. Multi-branch organizations can contact Shape Support for help enabling the appropriate SSO configuration across their environment.

What happens if an employee’s Google or Microsoft account is disabled?+

The user will no longer be able to authenticate to Shape using that Google or Microsoft account.

Their Shape account and permissions are still managed separately within Shape.

What happens if a user is deactivated in Shape?+

A deactivated Shape user cannot access Shape through SSO. Authenticating successfully with Google or Microsoft does not override the user’s Shape account status or permissions.

Why is Google or Microsoft asking for administrator approval?+

Your organization may restrict access to third-party applications.

A Google Workspace or Microsoft administrator may need to approve Shape Software before the connection can be completed. This approval occurs within your organization’s Google or Microsoft administration environment.

Can Shape Support help us configure SSO?+

Yes. If you need help enabling SSO, approving the connection, configuring multiple branches, troubleshooting authentication, or requiring SSO for your users, contact Shape Support.

Dani Dunn

Senior Project Manager, Shape Software

Dani Dunn leads enterprise client management at Shape Software, where her team supports some of the platform's largest customers. She has been with Shape for over a decade, giving her deep hands-on expertise in CRM implementation and workflows.