Security, Privacy, and Trust
August 23, 2026

Signing in: password, Google, and Microsoft

Three ways to sign in, which to standardize on, and how access is removed.

Synthelio offers three ways to sign in: an email address and password, your Google account, or your Microsoft account.

All three lead to the same place. Your identity in Synthelio is your email address, and the sign-in method is how you prove that the address is yours. Choosing Google over a password does not create a different account or grant different permissions.

Password

The straightforward option, and the right one for people outside your corporate identity system: contractors, advisors, and anyone whose email is not on a domain you control.

The tradeoff is that it is one more credential your team has to manage, and one more that leaves with them if you forget to deactivate their account.

Google

Sign in with the Google account attached to your work email. Synthelio verifies the identity with Google and no separate password exists.

The real advantage is not convenience, it is offboarding. When somebody leaves and you suspend their Google account, the path they used to reach Synthelio is gone at the source. With a password, deactivating the Google account does nothing to the Synthelio password, and you are relying on somebody remembering to close the second door.

Microsoft

The same arrangement for organizations on Microsoft 365 or Entra ID. Sign in with your work Microsoft account, no separate password, and the same offboarding benefit through your Microsoft tenant.

If your firm already runs on Microsoft 365, this is the natural choice, and it keeps Synthelio access inside the same account lifecycle as email and files.

Choosing one for your firm

Pick whichever matches where your accounts already live, and try to keep it consistent.

Consistency is worth more than it sounds. A firm where some people signed in with Google, some with Microsoft, and some with a password has no single place to check who can still get in. Uniformity turns access review into one list instead of three.

The practical rule: employees use whichever identity provider your firm runs on, and external people use passwords, because you cannot deprovision an identity you do not control.

Switching methods

Because your account is your email address, using a different sign-in method with the same address gets you into the same account with the same permissions and history.

The exception is a change of email address. That is a change of identity, not a change of method, and it needs an admin.

Removing access

Deactivate the user in Synthelio. That is the authoritative action and it works regardless of how the person signed in.

Deactivation is immediate and it covers every route into the workspace, including any AI assistant they connected through the MCP connector. The next request that assistant makes fails and prompts a sign-in that will not succeed.

Suspending someone's Google or Microsoft account is a good second layer, but treat it as a second layer rather than the whole answer. Deactivate in Synthelio first.

Common questions

Does the sign-in method affect what I can see? No. Permissions come from your role, and row-level security in the database enforces them regardless of how you authenticated.

Can one person use more than one method? The account is the email address, so signing in a different way with the same address reaches the same account.

What if my work email changes? Ask an admin to update it. Changing the address is what moves the identity; the sign-in method follows it.

Is single sign-on with SAML available? The three methods above are what exists today. If you have a specific identity provider requirement, raise it, because those decisions are driven by what customers actually need.

Can’t find what you’re looking for?

Tell us what you need. We will point you to the answer or write the article.

Contact Support