## TL;DR
Offboarding suspended the Google account and the reversal did not fully unsuspend it. Unsuspend the user in Google Admin, confirm the organizational unit and licenses, and the SSO login works again.

## The query
```text
google workspace sso fails: "user is suspended" after offboarding reversal
```

## Use this when
- reinstated users get user is suspended on SSO
- the user exists in the IdP but Google rejects them
- offboarding was reversed but access never returned

## Not for
- new-user provisioning failures
- Google password sign-in problems
- SSO configuration errors affecting everyone

## Steps
1. In Google Admin, open the user and confirm the account shows suspended. Expected output: the suspension state is visible.
2. Unsuspend the user and confirm the status changes to active. Expected output: the account shows active.
3. Verify the user is in the correct organizational unit with SSO enabled and has the needed license. Expected output: OU, SSO setting, and license are all correct.
4. Have the user retry SSO from the IdP. Expected output: login completes into Google Workspace.
5. Confirm mail, drive, and calendar access are restored. Expected output: all core services work for the user.

## Applies to
Google Workspace with third-party SSO (Okta, Entra ID), Google Admin console, current versions.

## Variant phrasings
### Unsuspended but still fails an hour later
A scheduled offboarding workflow re-suspended them; disable or fix the workflow.

### SSO works but Gmail shows no data
Data may have been deleted or transferred during offboarding; check the transfer settings.

## Why it happens
Offboarding playbooks suspend the Google account quickly. Reversals often restore the IdP side but miss the Google suspension, and SSO then fails at Google with this message.

## Edge cases
- Suspended users may lose licenses after a grace period; reassign before unsuspending.
- Check data retention: long suspensions can trigger deletion per policy.
- Document the reversal checklist so every system gets restored, not just the IdP.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_La5s3SqIvVEvdJjelFd9mA
