Skip to main content

Set up SSO

This document explains how to configure SSO settings.

Written by LegalOnサポートチーム

This document has been generated with machine translation.


What Are SSO Settings?

It is a mechanism that allows users to access multiple systems with a single authentication.

In LegalOn, SSO is enabled, allowing you to access the service through your ID provider.

*Note: Enabling SSO changes the authentication method from Email address and Password authentication to authentication via your ID provider.

Currently, LegalOn has confirmed successful integration with the following ID providers:

  • Microsoft Entra ID (formerly Azure Active Directory)

  • Okta

  • HENNGE One

*You can use SSO with ID providers other than those listed above as long as they support SAML 2.0.

Terms of Use

LegalOn Terms

  • You must have a contract for the SSO (Single Sign-On) option

  • Permissions required for configuration: IT Administrator

Requirements on the ID Provider Side

  • You have a subscription to an ID provider (SAML 2.0-compatible)

  • The email address registered with the ID provider must match the one registered with LegalOn

*If you wish to subscribe to one of the Options, please contact your sales representative.

Important Note

  • If SSO is Enabled while the settings contain errors, you will be unable to log in if you close your browser or Logout.
    After enabling SSO, please be sure to keep the SSO settings screen open and test whether you can log in successfully by following the “Test SSO Login” procedure in a different browser or in incognito mode in the same browser.

  • Users whose Email domain matches the one configured on the SSO settings screen can log in via SSO. Users logging in with other Email domains will be authenticated using their Email address and Password.

  • Currently, SAML authentication supports only SP-Initiated SSO (a method where the Service Provider begins SAML authentication), and users must log in from the LegalOn login screen each time. Please note that the authentication process will result in an error and will not complete if using the IdP-Initiated SSO method.

Set up SSO

1. Configure SSO settings on the ID Provider side

① In LegalOn, click [Admin settings] → [ SSO settings ], then select the [SSO (SAML Authentication)] tab

Note

For information on using the [Google Login] tab in the SSO settings, see " Logging In with a Google Account."

Troubleshooting

The “SSO settings” menu is not displayed:

This is a paid option and will be hidden if you have not subscribed to it. If it does not display even though you have subscribed, please contact our support team.

② Copy the “Endpoint URL” and “Entity ID(Identifier)” and configure them in your ID provider’s settings

The setup procedure varies depending on your provider. If you have any questions, please contact us for more information.

2. Configure SSO settings on the LegalOn side

① Obtain the following information from the ID provider configured in Steps 1-2

  • Endpoint URL

  • Public Key Certificate (X.509 Certificate)

② Enter the information you obtained into the "Email domain" field and the "Identity provider endpoint URL (HTTP redirect)" and "SAML signing certificate (X.509 public key certificate issued by the identity provider)" fields, as shown in the figure below

③ Click [Register]

Notes

  • For the Email domain, please enter the string following the “@” symbol.

  • The "Endpoint URL" may be labeled differently depending on the ID provider, such as "Login URL."

  • For “Public Key Certificate (X.509 Certificate),” please enter all the text contained in the file with the “.pem” extension.
    * Please copy and paste all the text, including "-----BEGINCERTIFICATE-----" and "-----END CERTIFICATE-----".

3. Enable SSO

① Go to [Admin settings] → [ SSO settings ] → Turn on [SSO (SAML Authentication) is Enabled]

② Review the message and click [Activate]

SSO will now be Enabled.

SSO log in will be applied from the next time you log in to LegalOn。

Test whether you can log in using SSO

  1. While keeping the SSO settings screen open, open
    Open " https://app.legalon-cloud.com/ "

  2. Enter your email address and click [Continue]

  3. From the login screen of your configured ID provider, follow the on-screen instructions to log in

Once the LegalOn home page displays, your SSO login is complete.

Troubleshooting

If the following error screen is displayed during your first login, click [Return to login screen], or refresh the tab or restart your browser, then open “https://app.legalon-cloud.com/” again and try logging in once more.

Deactivate SSO

① Click [Admin settings] → [ SSO settings ], then select the [SSO (SAML Authentication)] tab

② Turn off [SSO (SAML Authentication)]

③ Review the message and click [Deactivate]

SSO log in will be applied from the next time you log in to LegalOn。

Did this answer your question?