Overview
Single Sign-On (SSO) allows users to log into Legl using their organisation’s existing identity provider credentials.
This guide explains how to set up SAML-based SSO with Azure Active Directory and how to test the setup with Legl Support before rolling it out to all users.
Before you start
Before setting up SSO, make sure that:
You have admin permissions in Azure
You can access the Azure dashboard
You can download and upload XML metadata files
How to set up SSO with Azure Active Directory
Follow the steps below to configure SAML SSO for Legl using Azure AD Enterprise Applications.
Step 1: Download the Legl SAML metadata file
Download the XML file.
Step 2: Create a new Enterprise application in Azure
Open the Azure dashboard
Go to Enterprise applications (or search to find it)
Click New application.
Select Create your own application.
Name the application Legl.
Make sure Integrate any other application you don’t find in the gallery (Non-gallery) is selected.
Step 3: Configure Single Sign-On
Wait for the application to finish creating.
Under Set up single sign on, click Get started.
Select SAML.
Click Upload metadata file.
Upload the XML file downloaded in Step 1.
Step 4: Set the Relay State
When the side panel opens, scroll to Relay State.
Enter the relay state value provided by Legl Support.
Click Save.
ℹ️ Note
The relay state value is your firm’s Legl subdomain.
For example, if your Legl URL is example.legl.com, enter example.
Step 5: Send the Azure metadata file to Legl
Under Step 3 – SAML Signing Certificate, locate Federation Metadata XML.
Click Download.
Email the downloaded XML file to [email protected].
Step 6: Access your Legl account
The SSO setup is now complete.
You can invite users from the Settings > Team page in Legl.
Users will be redirected to log in using their Azure AD credentials.
How to test SSO with Legl Support
Before migrating all users to SSO, testing is required.
After sending the XML file, Legl Support will ask you to test SSO.
SSO must be tested with one user account.
Let Support know which account you would like to test (your own or a colleague’s).
Once testing is successful, all users can be moved to SSO.
Other supported identity management tools
Legl supports any SAML-compatible identity provider.
Legl has experience supporting setup with:
Microsoft Azure Active Directory (AD)
Okta
If you use a different identity provider, contact [email protected] and the team will assist you.
Important information
SSO must be tested with at least one user before full rollout.
Azure admin permissions are required to complete setup.
Relay State must match your Legl subdomain exactly.
User provisioning is managed through Azure once SSO is enabled.
