A Google SSO failure that results in a 403 error usually shows that the application you're trying to access isn't set up correctly for your user account or organization. It might also indicate an issue with how the application is configured in Google Admin. Additionally, this error could be caused by a problem with the user's account or the application's setup.
USM Content
Symptom
After configuring SAML with Google as the Identity Provider (IdP), a user sees the following error when trying to sign in to Smartsheet:
403 Error: app_not_enabled_for_user
What this error means
This error means Google blocked the sign-in attempt because the Smartsheet SAML app isn't enabled for that user in Google Workspace Admin. The user's credentials are fine, but the problem is on the app configuration side.
Common causes
There are two typical reasons this happens:
- The app isn't enabled for the user's Organizational Unit (OU): In Google Workspace, SAML apps can be enabled for everyone or restricted to specific OUs. If the user belongs to an OU that doesn't have Smartsheet enabled, they get this error even if other users in the organization can sign in without issue.
- The app isn't enabled at all: If Smartsheet was recently added as a SAML app in Google Workspace Admin but hasn't been turned on yet, all users see this error.
Resolution (for Admins)
A Google Workspace Admin needs to enable the Smartsheet SAML app for the affected user or their OU. Here's how:
- Sign in to the Google Workspace Admin Console.
- Navigate to Apps > Web and mobile apps.
- Find and select the Smartsheet SAML app.
- Select User access.
- Check which OUs have the app enabled. If the affected user belongs to an OU where the app is OFF, turn it on for that OU, or switch to On for everyone if all users should have access.
- Select Save.
Changes can take up to 24 hours to propagate across Google Workspace, though they typically take effect within a few minutes.
For full details on enabling and troubleshooting SAML apps in Google Workspace, see Google's SAML app error messages guide.
Not sure which OU the affected user belongs to? In the Google Admin Console, go to Directory > Users, find the user, and check their Organizational unit field. Then return to the Smartsheet SAML app and confirm access is enabled for that OU.
What end users can do
If you're not a Google Workspace Admin, you can't resolve this directly, but you can help speed it up. When you contact your IT department or Smartsheet System Admin, share the following:
- The exact error message you see (403 Error: app_not_enabled_for_user)
- The Google account email address you're using to sign in
- Whether you've been able to sign in before, or if this is your first attempt
- Whether other users at your organization are experiencing the same issue
This information helps your Admin identify whether it's an individual OU issue or an organization-wide configuration problem.
If the steps above don't resolve it
If your admin has confirmed the app is enabled for the correct OU and users are still seeing the 403 error:
- Clear the browser cache and cookies, then try signing in again.
- Try signing in from a different browser or an incognito/private window.
- Confirm the SAML configuration in Smartsheet Admin Center matches what's set up in Google Workspace. Mismatched entity IDs or ACS URLs can produce this error even when app access is enabled.
If none of the above works, contact Smartsheet Support and include the Admin steps already taken and the SAML configuration details from both sides.