Single sign-on in the Workspace side rail opens /workspace/sso. Organization owners and admins administer single sign-on for the active organization; members and viewers see a permission message and cannot read or change any of it.
Single sign-on lets the people at your Google Workspace domain reach your organization through their existing Google account instead of a Probara password — and, once you turn on enforcement, lets you require it.
Not available on every plan
Single sign-on is an entitlement. If your plan does not include it, the screen shows a not available on your plan notice instead of the management form. Any domain you already verified, and any connection you already configured, stay visible and readable — losing the entitlement never hides or deletes your configuration, it only pauses the ability to change it and stops enforcement from being honored until the entitlement returns.
Prove you own a domain
Before Probara will let people from example.com sign in through your organization, you have to prove you control example.com.
- Enter the domain and select Claim domain. It appears in the list with status Pending and a TXT value.
- Publish that value as a
TXTrecord on the domain, through your DNS provider. Any hostname works, as long as the record’s content is exactly the published value. - Once the record is live, select Verify. When Probara reads it back successfully, the claim moves to Verified.
Two domains cannot both hold the Verified status for the same name — whichever organization proves it first keeps it, and a second claim from anyone else stays Pending with no further detail about who holds it.
Verifying a domain does not touch existing accounts
This is worth stating plainly, because it is the natural fear: verifying a domain gives your organization no power over any account that already exists on it. It does not absorb, move, merge, or automatically join anyone. It does not make any existing Probara account visible to you, and it does not change how anyone signs in outside your organization. Verification only unlocks the connection step below — nothing happens to any account until someone actually signs in through it.
Connect Google Workspace
Once you hold at least one verified domain, select Connect Google Workspace to create the connection. No per-organization Google credentials are needed — Probara’s own Google client serves every organization.
The connection carries two toggles:
| Toggle | Effect |
|---|---|
| Automatically add new sign-ins as viewers | When on, a Google Workspace user on a verified domain who signs in for the first time is added to your organization as a viewer automatically. When off, they must be invited first. |
| Require SSO for this organization | When on, everyone must reach this organization through its own SSO flow — see Requiring SSO below. |
Requiring SSO
Turning on Require SSO for this organization is the strongest setting on this screen: from then on, a password-authenticated session cannot reach this organization at all, only a session minted by signing in through this organization’s own SSO flow. Sign-in to your account, and to any other organization you belong to, is completely unaffected — this setting only governs access to this organization.
You cannot lock yourself out. Turning enforcement on is refused unless your own current session was itself created by signing in through this organization’s SSO — so the platform will not let you enable it from a plain password session. The onboarding order is therefore:
- Verify a domain.
- Connect Google Workspace with enforcement off.
- Sign in through this organization’s own SSO flow at least once.
- Now turn enforcement on from that SSO-authenticated session.
If the toggle is refused, the screen shows the reason and reverts the switch to its previous value — it never silently ignores the refusal.
Turning enforcement off is never refused, from any owner or admin session, by design: it is your in-place rollback lever. If you ever need it and cannot use the toggle for some reason, Probara staff can also revoke a verified domain or restore your access as a break-glass measure — contact support.
Existing API tokens and other machine credentials issued before enforcement was turned on keep working; enforcement governs interactive sign-in, not those credentials.