Table of contents
In a company without its own server, every employee carries two identities: a local Windows account on the laptop and a Google Workspace account for everything else. Two passwords to reset, two places to forget when somebody leaves, and no connection between them: suspend the Google account and the laptop still opens with the local password for as long as nobody touches it.
GCPW, the Google Credential Provider for Windows, links the two. Employees sign in to Windows with their Google Workspace account, and the laptop becomes part of the same identity system that already protects mail and files. No server, no Active Directory, no separate Microsoft 365 licence just for sign-in (you still need a valid Windows licence, of course).
Checked against Google’s GCPW documentation on 9 September 2026.
What GCPW actually does
It is a small Google tool installed on each Windows PC. After installation the Windows sign-in screen gets an extra option: sign in with Google. The first sign-in either creates a local Windows profile linked to the Google account or, if you configure it, links an existing local profile so that documents and settings survive. From then on the password is the Google password and 2-step verification is enforced when the user authenticates with Google (not on every screen unlock). When the password is changed in Google, the laptop picks it up at the next online sign-in.
The part to understand before you promise anything: offline sign-in works with the cached credential, and by default it keeps working until the user next signs in online. Suspending a Google account therefore stops the next online sign-in; it does not lock a laptop that is sitting offline. The Admin console lets you limit how many days a user may stay signed in offline before Google re-authentication is required; set it deliberately.
| Without GCPW | With GCPW | |
|---|---|---|
| Passwords | Two: Windows and Google | One: Google |
| 2-step verification at sign-in | Only if you run another identity solution | Yes, whenever the Google sign-in happens |
| Forgotten password | Reset at the machine, in person | Reset in Google, the PC follows |
| Employee leaves | Local account stays active until IT visits the machine | Suspend the Google account: the next online sign-in fails; offline access ends when the configured offline period expires |
| Lost laptop | Depends entirely on whether BitLocker was on | Same, unless you also enrol it in Windows device management, which can enforce BitLocker and wipe remotely |
Requirements
- Windows 11 (or Windows 10, but note that mainstream Windows 10 support ended on 14 October 2025, so a 10 machine also needs an extended-support plan or a replacement date) in the Pro, Enterprise or Education edition. Windows Home is not supported, which matters for laptops bought at a consumer shop. Upgrading Home to Pro is a licence key, not a reinstall.
- A Google Workspace or Cloud Identity account for every user. GCPW itself is included in every edition.
- Remote management of the Windows device (policies, wipe, BitLocker status) is a separate feature, Windows device management, included only in certain editions (Business Plus, Enterprise and some Education editions at the time of writing). Google’s edition matrix is not a simple ladder, so check the feature’s own support page against your edition before promising anyone remote wipe.
Setup in four steps
- Allow your domain. Admin console: Devices, Mobile and endpoints, Settings, Windows. Under the GCPW setup, enter the domains whose accounts may sign in to company PCs. This step is not optional: if no allowed domain is configured, GCPW refuses every sign-in, and the error users see is unhelpful. List only your own domains, never gmail.com.
- Download and install GCPW. It is an MSI, which means it can be pushed silently with any deployment tool, or installed by hand on five laptops in an afternoon. Google’s guide is titled “Install GCPW”.
- First sign-in. Each employee signs out of Windows, chooses “Add work account” on the sign-in screen and signs in with their Google account, including 2-step verification. By default a new Windows profile is created; if you want to keep the existing profile with its documents and settings, configure the existing-profile association before rollout. Either way, review the old local accounts afterwards and disable the ones nobody needs, keeping one documented local administrator for emergencies.
- Set the offline limit and, if your edition has it, turn on Windows device management in the same settings area. The PC then appears in the Admin console under Devices, and policies (screen lock, BitLocker, password rules) apply from there. This is what we deliver as part of managed IT services.
If you already have Active Directory
GCPW works alongside AD, but then the directories should agree with each other. Google Cloud Directory Sync (GCDS) keeps the user list in sync from AD to Google, and Password Sync pushes password changes from AD to Google. For a small company without its own server this step does not apply. For a company thinking about leaving AD, GCPW handles sign-in, but it does not replace group policy, file servers or applications that authenticate against the domain; audit those dependencies before switching the last server off.
What GCPW does not do
It is not a full device management product. GCPW is responsible for sign-in and nothing else. Disk encryption, screen-lock policies, application control and remote wipe come from Windows device management and the Workspace security settings, so plan both together. Suspending a Google account is not encryption and not a remote wipe. And it does not turn a Windows PC into a ChromeOS device: local software, printers and Windows updates are still yours to manage, or ours.
The three mistakes we see most
- Rolling out GCPW before the allowed domains are configured. Nobody can sign in, the helpdesk phone rings, and the project gets a bad name on day one. Configure the domain first, test on one machine, then install everywhere.
- Leaving the old local Windows accounts active and the offline period unlimited. When the employee leaves, the Google account is suspended, but the local account still opens the laptop and the cached Google credential still works offline. Disable unneeded local accounts, set an offline limit, and treat collecting the laptop as part of offboarding.
- GCPW without device management. Sign-in is sorted, but a lost laptop’s data still cannot be wiped and there is no proof it was encrypted. If your edition lacks Windows device management, at least enable BitLocker on every machine and store the recovery keys somewhere that survives the laptop.
Frequently asked questions
Does GCPW work with Windows Home?
No. It requires Windows 10 or 11 Pro, Enterprise or Education. A Home-to-Pro upgrade key solves it without reinstalling.
Can employees still sign in without internet?
Yes. After the first online sign-in, the credential is cached and works offline, by default indefinitely. The Admin console lets you require an online Google sign-in after a set number of offline days; set it, because this also decides how long a suspended account can keep using an offline laptop.
Is GCPW the same as Windows device management in Google Workspace?
No. GCPW handles sign-in and is included in every edition. Windows device management adds policies, inventory and remote wipe and is included only in certain editions; check its support page against yours.
Related articles
- Google Workspace account suspended. What now?
- Managed IT services for Google Workspace companies
- Google Workspace setup
If your staff work on Windows laptops, your company lives in Google Workspace and you have no Active Directory to keep, GCPW is usually the right call. We roll it out together with device management, with a pilot on two or three machines first.
Want Windows sign-in tied to Google accounts? We assess your PCs and profiles, pilot GCPW on one machine, then configure allowed domains, offline limits and device management. Book a free 30-minute audit or call +371 22 30 50 90.


