# Login methods
Control how users sign in to your workspace — allow classic password login, enable single sign-on (SSO) via Google or Microsoft, or combine both.

:::lock{title="Required rights"}
Admin
:::

![](/images/guides/login-methods/image-mqgnzi7t.png)

Find these settings under **Account settings → Security**. Changing them requires admin rights.

## Sign-in methods

Choose which methods your team can use to sign in.

| Method                  | Description                                         |
| ----------------------- | --------------------------------------------------- |
| **Username & password** | Classic sign-in with an email address and password. |
| **Google SSO**          | Sign in with an existing Google account.            |
| **Microsoft SSO**       | Sign in with an existing Microsoft account.         |

Once at least one SSO provider is active, you can disable password authentication. Users then sign in exclusively through the selected SSO providers.

:::warning
Before disabling password sign-in, make sure your team has the **latest app version** installed on every platform.
:::

![](/images/guides/login-methods/image-mqgnw5tt.png)

## Workspace-wide and per-user settings

The methods you choose here apply by default to **all users** in the workspace.

You can override them per user — for example to allow exceptions for people without access to an SSO provider (freelancers, API users, etc.).

## Benefits of SSO

* **More security** — fewer passwords mean fewer compromised accounts.
* **Easier login** — users sign in with their existing Google or Microsoft accounts.
* **Central management** — passwords and security policies are handled by your identity provider.

## Best practices

* Enable at least one SSO provider to simplify sign-in for your team.
* Make sure the email address stored in Aerion matches the one at your SSO provider.
* Before disabling password sign-in, confirm that **all** users have access to an enabled SSO provider.
* Use your SSO provider's security features (e.g. two-factor authentication) for extra protection.
* For users without SSO access (freelancers, API users), keep per-user password sign-in enabled.

## FAQ

**What happens to existing users when I enable SSO?**
Nothing. Existing sign-ins stay valid until you explicitly disable password login.

**Can individual users use a different sign-in method than everyone else?**
Yes. Per-user settings let you define exceptions to the workspace-wide rules.

**Which email address counts for SSO?**
The email address stored in Aerion must exactly match the one held by your SSO provider — otherwise sign-in will fail.
