
The most common cause is that the user registered with the wrong method. When a workspace has SSO (Microsoft, Google, custom) set up, invited users must create their account by choosing Sign up with (Microsoft, Google, custom), not the standard Sign up button with email and password.
If a user signs up with email and password while the workspace has SSO login only enabled, it creates a loop. The account exists as an email-and-password account, but the security policy blocks that method, and the SSO button does not recognize the account. The user then sees an error when trying to log in via SSO.
There are two ways to resolve it. The first is recommended because it preserves the user's meeting history.
Option 1 - Temporary access (recommended)
A workspace admin needs to temporarily enable the Email + Password login method in the workspace security settings.
The user then logs in using their original email and password.
Once inside, they need to go to their settings and connect their Microsoft or Google calendar depending on the workspace SSO.
Once that connection is made, the Admin turns the Email + Password restriction back on. The user can now log in successfully via SSO going forward.
Option 2 - Account reset
If the admin prefers not to change your workspace security settings, they can delete the user from the workspace. After the userβs account is removed, they can sign up again using the workspace invite link the admin re-sends. When they rejoin, they must select Sign up with Microsoft or Sign up with Google immediately.
When you invite users to an SSO-enabled workspace, let them know upfront that they must accept the invitation and register using the Sign up with Microsoft, Google, or custom button that matches your SSO provider. They should not use the standard email-and-password option, even though it appears on the screen.
Re-sending the invitation alone won't resolve the loop because the incorrectly created account already exists. You will need to use Option 1 or Option 2 above. Option 1 keeps the user's history intact, while Option 2 starts the account fresh.