Single sign-on

Canary9 supports signing in with Google and Microsoft, work accounts and personal accounts alike. It always works alongside your password, never instead of it: nothing on this page can lock you or your teammates out of normal sign-in. On the Pro plan and above, provider sign-in is automatic (your account connects itself the first time you use it), and account federation extends that to your whole team through a verified email domain.

Sign in with Google or Microsoft

On Pro plans and above, just use it: choose Continue with Google or Continue with Microsoft on the sign-in page, and if the provider confirms the email address matches your Canary9 account, you're in; the account links itself on first use. Personal Microsoft accounts (live.com, hotmail.com) work the same way as work accounts.

On the Free plan, link once first: open Settings (your avatar in the top-right corner) → SecurityLinked accounts, choose Link Google or Link Microsoft, and approve the sign-in. Linking is also the way, on any plan, to connect a provider account whose email is different from your Canary9 address.

A few useful details:

  • Two-factor authentication is never bypassed: if you have 2FA enabled, you're asked for your authenticator code after the provider sign-in, exactly as with a password.
  • You can unlink at any time from the same card. If a linked account is your only way to sign in (you haven't set a password), Canary9 asks you to set one first so you can't lock yourself out.
  • To add a password to an account that signs in only with Google or Microsoft, use Forgot password from the sign-in page's Having trouble? link.

Federate your domain (Pro and above)

Account federation ties your email domain to your identity provider, so the whole team gets one-click sign-in with their work accounts. Setting it up takes two steps, both under Organization → Single sign-on (admins only).

1. Verify your domain

Add your domain (for example example.com). Canary9 shows a DNS TXT record to publish:

  • Host: _canary9-verify.example.com
  • Value: canary9-verify=<your unique token>

Create that record at your DNS host, then select Verify. DNS changes can take up to an hour to spread, so it's normal for the first check to come back empty. The record details stay visible and you can verify again any time. Keep the record published: it's your standing proof of ownership, and only one organization can hold a verified claim on a domain.

Any domain you control can be verified; the TXT record is the proof of control. (Individuals on public mailbox providers like gmail.com don't need any of this: automatic provider sign-in, as above, already covers them.)

2. Switch on your providers

On the verified domain, enable Google and/or Microsoft. Teammates at the domain can now use Continue with Google or Continue with Microsoft, and their work account connects to their Canary9 user automatically on first sign-in.

Two optional hardening controls:

  • Google Workspace domain limits sign-in to accounts from that Workspace, not any Google account that happens to hold an address at your domain.
  • Microsoft tenant ID is the same idea for Entra ID: only tokens from your directory are accepted. We recommend setting this pin; without it, Canary9 requires Microsoft to confirm the email address is verified in the directory (the xms_edov claim) before trusting it. Personal Microsoft accounts never satisfy a tenant pin.

New teammates still need an invite. Federated sign-in connects work accounts to existing Canary9 users. Someone at your domain without a Canary9 account yet is asked to contact their administrator. Invite them from Organization → Members first, and their first federated sign-in links up automatically.

When you need more control: SSO

Account federation is deliberately a convenience: it adds sign-in options and never takes any away. If your organization needs to control access (require sign-in through your identity provider, map directory groups to Canary9 permissions, and guarantee that offboarded employees can't get back in), that's SAML single sign-on, coming to the Enterprise plan on the same verified domains. It works with Okta, Microsoft Entra ID enterprise applications, Google Workspace SAML apps, and others. Contact us if you'd like early access.

Troubleshooting

  • "That account isn't in the directory your organization has connected to Canary9." The domain is pinned to a specific Google Workspace or Entra tenant, and the account used belongs to a different one. Sign in with the account from your company directory, or ask your admin to check the pin.
  • "Your identity provider didn't confirm ownership of that email address." Microsoft didn't assert the address as verified. Ask your admin to set the Microsoft tenant ID pin on the domain, which lets Canary9 trust your directory directly.
  • "You don't have a Canary9 account yet." Ask your administrator for an invite; federated sign-in doesn't create accounts on its own.
  • "No Canary9 account is linked to that account." Automatic connection is part of Pro and above, or the provider couldn't confirm your email address. Sign in with your password and link the account under Settings → Security; that works on every plan.
  • "We couldn't find that TXT record yet." The verification record hasn't propagated. Check the host and value match exactly (including the canary9-verify= prefix) and try again after your DNS TTL.
  • "Your organization's plan no longer includes account federation." Federation is part of Pro and above; password sign-in keeps working, and an admin can upgrade from Organization → Billing.

Still stuck? Email support@canary9.com and we'll help you get signed in.