SSO Invitation button does not disable existing logins — "Switch to Only SSO" is required to enforce SSO-only access
Android
When setting up Single Sign-On (SSO) for your Esper tenant, sending the SSO invitation email does not disable existing login methods — users can still sign in with their email and password until you explicitly switch the tenant to SSO-only mode.
Why this happens
Esper SSO setup has two independent stages: invitation and enforcement. The invitation step only asks users to link their accounts to your Identity Provider (IdP) — it does not change how anyone authenticates. SSO-only authentication is enforced separately, when you click Switch to Only SSO. These two actions must both be completed to fully migrate your tenant to SSO.
Stage 1 — Invite users to link their accounts
- In the Esper Console, go to Settings → Single Sign-On.
- Click Ask Users to accept Esper SSO Invitation. This sends an invitation email to all users in your tenant asking them to link their Esper account to your IdP. Existing email and password logins remain fully active at this point.
- Instruct each user to open the invitation email and click the link to complete account linking in both Esper and your IdP.
- Verify that all users have completed account linking before proceeding to Stage 2. Check Settings → Single Sign-On for per-user linking status, and confirm each user exists in your IdP with a matching email address.
Stage 2 — Enforce SSO-only authentication
Warning: Any user who has not completed account linking in both Esper and your IdP before this step will lose Esper Console access immediately. Complete the checklist below before proceeding.
- All users have received, opened, and acted on the SSO invitation email.
- All users exist in your IdP with the exact email address used in Esper.
- At least one SSO login has been tested end-to-end and confirmed working.
- In the Esper Console, go to Settings → Single Sign-On.
- Click Switch to Only SSO. This disables email and password authentication for all users in your tenant. From this point, every user must authenticate through your IdP.
Troubleshooting
Users are not receiving the invitation email
- Ask affected users to check their spam and junk folders.
- Confirm each user's email address is correct in Settings → User Management.
- Return to Settings → Single Sign-On and resend the invitation.
A user lost access after switching to SSO-only mode
- Add or verify the user in your IdP using the exact email address registered in Esper.
- Have the user attempt to sign in again using SSO. If the IdP account is correctly configured, access is restored on the next login attempt.
The Single Sign-On option is not visible in the Esper Console
SSO is a plan-level feature. Confirm that your Esper subscription includes SSO. If it should be available but is not visible, contact Esper Support.
If this doesn't resolve it
If users are still unable to authenticate after following these steps, or if you need help configuring a specific Identity Provider, contact Esper Support. When reaching out, include:
- The name and type of IdP you are using (for example, Okta, Azure AD, Google Workspace)
- The email addresses of any affected users
- Screenshots of any error messages displayed during login
- Whether the affected users completed the invitation step before SSO-only mode was enabled
Still need help?
If you're still seeing existing logins after clicking the SSO Invitation button, submit a support ticket and include details about which user accounts remain active and whether you've enabled "Switch to Only SSO" to enforce SSO-only access.
Please sign in to leave a comment.
Comments
0 comments