> For the complete documentation index, see [llms.txt](https://docs.igenius.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.igenius.ai/crystal-console/users/invite-users-to-crystal/invite-users-via-identity-providers.md).

# Invite Users via Identity Providers

This page describes how to invite Users to Crystal via Identity Providers.

As an Admin Member, there are [**two invitation methods**](/crystal-console/users/invite-users-to-crystal.md) that you can use to invite Users to Crystal: manual or via Identity Provider.

This guide focuses on the **invitation via IDP** method (you can read about the alternative method [here](/crystal-console/users/invite-users-to-crystal/how-to-invite-users.md)).

Let's see how to do it.

{% hint style="warning" %} <mark style="color:orange;">**Remember**</mark>

As viewing [permissions](/crystal-console/users/manage-permissions.md) are inherited from Groups, after the invitation process don't forget to *also* *add the invited Users to one or more* *Groups* in order to grant them viewing permissions to data - otherwise they won’t be able to talk to Crystal on the first access.
{% endhint %}

## Choose Identity Provider

You have two possible Identity Providers (IDPs) to choose from:

* **Microsoft IDP**: this option will enable Users to log in with their company's Microsoft credentials
* **Google IDP**: this option will enable Users to log in with their company's Google credentials

{% hint style="info" %} <mark style="color:blue;">**Please Note**</mark>

Both Identity Providers can be enabled at the same time if needed.
{% endhint %}

## Set Up Identity Provider

To be able to invite Users via Identity Provider, *the Identity Provider must be enabled on Crystal first*!

Let's see how to do it in the dedicated tutorials!

***

### Jump to Section

{% content-ref url="/pages/OZGH6AfTl1m8OdR6lVdg" %}
[Enable the Microsoft Identity Provider](/crystal-console/users/invite-users-to-crystal/invite-users-via-identity-providers/microsoft-azure.md)
{% endcontent-ref %}

{% content-ref url="/pages/ojtnw3u2IjRNTOGTPwRg" %}
[Enable the Google Identity Provider](/crystal-console/users/invite-users-to-crystal/invite-users-via-identity-providers/enable-the-google-identity-provider.md)
{% endcontent-ref %}

***

## Invite Users via Identity Provider

Once the Identity Provider has been successfully enabled on Crystal, you’ll be capable to invite *Users* via the Google or Azure Workspace, like this:

1. go to the Section *"People"* and click on *"Invite People"*

<figure><img src="https://2516160394-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmAOqTQkYofJrevcpklA7%2Fuploads%2FdrPe4VsS1XuEBNV626vh%2FScreenshot%202024-03-07%20at%2016.15.23.png?alt=media&amp;token=fb4c7c6f-7fa5-4230-8e59-a29a792278d3" alt=""><figcaption><p>Invite People</p></figcaption></figure>

2. choose the option *"Import from Google Workspace"* or *"Import from Azure"* - based on which ones you have enabled

<figure><img src="https://2516160394-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmAOqTQkYofJrevcpklA7%2Fuploads%2FGkajz6jfT92461atzMMy%2FScreenshot%202024-03-07%20at%2016.13.48.png?alt=media&amp;token=5cd3e54f-0d60-456e-9bcf-1915e5905e6f" alt="" width="563"><figcaption><p>Import from IDP</p></figcaption></figure>

3. select the Users from the list that opens up

<figure><img src="https://2516160394-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmAOqTQkYofJrevcpklA7%2Fuploads%2FGHvBbaBTjKIdaErDAy63%2FScreenshot%202024-03-07%20at%2016.25.41.png?alt=media&amp;token=20ceef41-c532-4dd3-a331-26916551ab49" alt=""><figcaption><p>Select Users</p></figcaption></figure>

4. choose the role for the User

<details>

<summary>Crystal Roles</summary>

Remember that **Member Users** are the ones who can access the *Crystal Advisor only*, whereas **Admin Users** can access *both the Advisor and the Console*.

To know more about Crystal Users' roles, check [this article](/fundamentals/crystal.md).

</details>

<figure><img src="https://2516160394-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmAOqTQkYofJrevcpklA7%2Fuploads%2FO08JtlNn3yhkTCfaxHdE%2FScreenshot%202024-03-07%20at%2016.26.13.png?alt=media&amp;token=5f8ca353-e9d0-4f98-94cb-3686dfa39333" alt="" width="432"><figcaption><p>Assign Role</p></figcaption></figure>

At this point, everything is set!

The Users you invited will be capable to perform the [Login](/crystal-advisor/access-to-crystal/log-in-1.md) without creating a Crystal Account, but using their existing Google or Microsoft emails instead.

<figure><img src="https://2516160394-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FmAOqTQkYofJrevcpklA7%2Fuploads%2F7BtxZaVPDKyCbwGsveUY%2FScreenshot%202024-03-11%20at%2012.48.12.png?alt=media&amp;token=6cf17e66-f640-43d6-b7d2-fc536eea571a" alt=""><figcaption><p>Login via Identity Provider</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Please Note**</mark>

Identity Providers can also be used to [*create new Groups*](/crystal-console/users/user-groups.md).
{% endhint %}

***
