This document has been generated with machine translation.
*For instructions on how to set up SSO on the LegalOn side, please refer to [Set up SSO (Single Sign-On)].
Terms of Use
LegalOn Terms
Requirements on the Microsoft Entra ID side
*If you wish to subscribe to one of the Options, please contact your sales representative. |
Important Notes
Current, SAML authentication only supports SP-Initiated SSO (a method where the Service Provider begins SAML authentication), so you must log in from the LegalOn login screen each time. Please note that an error will occur during the authentication process, and authentication will not be completed.
If SSO is enabled while the settings are incorrect, you will be unable to log in if you close your browser or Logout. After enabling SSO, please ensure you test whether you can log in successfully by following the " Test SSO Login " procedure in a different browser or in incognito mode of the same browser, while keeping the SSO settings screen open.
SSO settings in the Entra ID Admin Console
Configuring [Basic SAML Configuration]
1. Click [Enterprise Applications] → [+ New Application]
2. Under [Create Custom Application], enter (or select) the following items, then click [Create]
Field | Input |
What is the name of your app? | Enter {any application name} Example: LegalOn |
What actions do you want to perform in the application? | Select [Integrate other applications not found in the Gallery (outside the Gallery)] |
3. Click [Single Sign-On], then select [SAML] from [Select Single Sign-On Method]
4. Select [Basic SAML Configuration], click [Save], and configure the following
Identifier (Entity ID)
Paste the value from LegalOn’s [SSO settings screen] → [Identity provider information] → [Entity ID(Identifier)]
Response URL (Assertion Consumer Service URL)
Paste the value from LegalOn’s [SSO settings screen] → [Identity provider information] → [Endpoint URL]
After entering the values, please click [Save].
[Attributes and Claims] Settings
For LegalOn’s SAML authentication, we expect to receive the Email address used in LegalOn from Entra ID. Please refer to the following for setup instructions.
1. Check [Attributes and Claims] → [Add Requests]
2. Click the attribute named [emailaddress] and enter (or change) the following fields
Field | Input Value |
Name | emailaddress |
Namespace | |
Source | Attribute |
Source Attribute | Select the attribute where the Email address used in LegalOn is configured
Example: user.userprincipalname user.mail etc. |
3. After entering the value, click [Save]
4. Obtain the information required for SSO settings on the LegalOn side
Values to be obtained from Microsoft Entra ID | LegalOn configuration items |
[Set up {Enterprise Application Name}] → [Login URL] | Copy and paste into [Identity provider endpoint URL (HTTP redirect)] on the LegalOn SSO settings screen |
Entra ID [SAML Certificate] → [Certificate (Base64)] | Instructions: Click [Download] and paste it into the [SAML signing certificate (X.509 public key certificate issued by the identity provider)] field on the LegalOn SSO settings screen
Copy and paste all the strings from [-----BEGIN CERTIFICATE-----] to [----END CERTIFICATE-----], including |
Email domain enabled for SAML authentication | Enter this in the [Email domain] field on the LegalOn SSO settings screen |
Troubleshooting
If the following error screen is displayed during login:
An incorrect value may have been assigned to the [emailaddress] source attribute. Please review the [Attributes and Claims] settings and try performing a Login again.
If the issue persists, please contact our support team via " Get Support - How to Contact Us."
This completes the Entra ID configuration.
Once the setup is complete, please configure the SSO settings on the LegalOn side.
For instructions on how to set up SSO on the LegalOn side, please refer to "Set up SSO (Single Sign-On)."



