This document has been generated with machine translation.
*For instructions on how to set up SSO on the LegalOn side, see “ Set up SSO (Single Sign-On).”
Terms of Use
LegalOn Terms
Requirements on the Microsoft Entra ID side
*If you wish to sign up for Options, please contact your sales representative. |
Important Notes
SAML authentication currently supports only SP-Initiated SSO (a method where the Service Provider begins SAML authentication), so you must log in from the LegalOn login screen each time. Please note that the authentication process will result in an Error and will not complete if you use IdP-Initiated SSO.
If you enable SSO while there are errors in the configuration, you will be unable to log in if you close your browser or Logout. After enabling SSO, please be sure to keep the SSO settings screen open and test whether you can log in successfully by following the “Test SSO Login” procedure in a separate browser or in incognito mode within the same browser.
Configuring SSO settings in the Entra ID Admin Console
Configuring [Basic SAML Configuration]
1. Click [Enterprise Applications] → [+ New Application]
2. Under [Create a Custom Application], enter (or select) the following items, then click [Create]
Field | Input |
What is the name of your app? | Enter {any application name} Example: LegalOn |
What actions would you like to perform in the app? | Select [Integrate other applications not found in the Gallery (outside the Gallery)] |
3. Click [Single Sign-On], then select [SAML] from [Select Single Sign-On Method]
4. Select [Basic SAML Configuration], click [Save], and configure the following:
Identifier (Entity ID)
Paste the value from LegalOn’s [SSO settings] → [Identity provider information] → [Entity ID(Identifier)]
Response URL (Assertion Consumer Service URL)
Paste the value from LegalOn’s [SSO settings screen] → [Identity provider information] → [Endpoint URL].
After entering the values, please click [Save].
[Attributes and Claims] Settings
For LegalOn’s SAML authentication, LegalOn expects to receive the Email address used in LegalOn from Entra ID. Please refer to the following for configuration instructions.
1. Go to [Attributes and Claims] → [Add Requests]
2. Click the attribute named [emailaddress] and enter (or change) the following fields
Field | Input Value |
Name | emailaddress |
Namespace | |
Source | Attribute |
Source Attribute | Select the attribute where the Email address used with LegalOn is configured
Example: user.userprincipalname user.mail etc. |
3. After entering the value, click [Save]
4. Obtain the information required for SSO settings on the LegalOn side
Values to retrieve from Microsoft Entra ID ID | LegalOn configuration fields |
[Set up {Enterprise Application Name}] → [Login URL] | Copy and paste this into the [Identity provider endpoint URL (HTTP redirect)] field on the LegalOn SSO settings screen |
Entra ID [SAML Certificate] → [Certificate (Base64)] | Instructions: Click [Download], then paste it into the [SAML signing certificate (X.509 public key certificate issued by the identity provider)] field on the LegalOn SSO settings screen
Copy and paste the entire string from [-----BEGIN CERTIFICATE-----] ( |
Email domain Enabled for SAML authentication | Enter this in the [Email domain] field on the LegalOn SSO settings screen |
Troubleshooting
If the following error screen is displayed during Login:
An incorrect value may have been assigned to the [emailaddress] source attribute. Please review the [Attributes and Claims] settings again and try performing a Login once more.
If the issue persists, please contact the support team via " Get Support - How to Contact Us."
This completes the configuration on the Entra ID side.
Once the setup is complete, please configure SSO settings on the LegalOn side.
For instructions on SSO settings on the LegalOn side, please refer to “ Set up SSO (Single Sign-On).”



