Skip to main content

How to set up single sign-on (SSO) with Legl

Learn how to set up Single Sign-On (SSO) for Legl using Azure Active Directory, including testing and supported identity providers.

Ula Moyse-White avatar
Written by Ula Moyse-White
Updated over a week ago

Overview

Single Sign-On (SSO) allows users to log into Legl using their organisation’s existing identity provider credentials.


This guide explains how to set up SAML-based SSO with Azure Active Directory and how to test the setup with Legl Support before rolling it out to all users.


Before you start

Before setting up SSO, make sure that:

  • You have admin permissions in Azure

  • You can access the Azure dashboard

  • You can download and upload XML metadata files


How to set up SSO with Azure Active Directory

Follow the steps below to configure SAML SSO for Legl using Azure AD Enterprise Applications.


Step 1: Download the Legl SAML metadata file

  1. Download the XML file.


Step 2: Create a new Enterprise application in Azure

  1. Go to Enterprise applications (or search to find it)

  2. Click New application.

  3. Select Create your own application.

  4. Name the application Legl.

  5. Make sure Integrate any other application you don’t find in the gallery (Non-gallery) is selected.


Step 3: Configure Single Sign-On

  1. Wait for the application to finish creating.

  2. Under Set up single sign on, click Get started.

  3. Select SAML.

  4. Click Upload metadata file.

  5. Upload the XML file downloaded in Step 1.


Step 4: Set the Relay State

  1. When the side panel opens, scroll to Relay State.

  2. Enter the relay state value provided by Legl Support.

  3. Click Save.

ℹ️ Note

The relay state value is your firm’s Legl subdomain.
For example, if your Legl URL is example.legl.com, enter example.


Step 5: Send the Azure metadata file to Legl

  1. Under Step 3 – SAML Signing Certificate, locate Federation Metadata XML.

  2. Click Download.

  3. Email the downloaded XML file to [email protected].


Step 6: Access your Legl account

  • The SSO setup is now complete.

  • You can invite users from the Settings > Team page in Legl.

  • Users will be redirected to log in using their Azure AD credentials.


How to test SSO with Legl Support

Before migrating all users to SSO, testing is required.

  1. After sending the XML file, Legl Support will ask you to test SSO.

  2. SSO must be tested with one user account.

  3. Let Support know which account you would like to test (your own or a colleague’s).

  4. Once testing is successful, all users can be moved to SSO.


Other supported identity management tools

Legl supports any SAML-compatible identity provider.

Legl has experience supporting setup with:

  • Microsoft Azure Active Directory (AD)

  • Okta

If you use a different identity provider, contact [email protected] and the team will assist you.


Important information

  • SSO must be tested with at least one user before full rollout.

  • Azure admin permissions are required to complete setup.

  • Relay State must match your Legl subdomain exactly.

  • User provisioning is managed through Azure once SSO is enabled.

Did this answer your question?