Open authentication settings
As an Admin, select Platform → Authentication. This page controls sign-in methods for your account. Support and Viewer users cannot change these settings.
Choose and save sign-in methods
Select the checkbox for each sign-in method your team should use.
Clear a method only when you are ready to stop offering it.
Select Save changes and wait for saving to finish.
Reopen the page to check the saved selections, then test a permitted method using your account URL in a separate browser session.
Keep a working administrator sign-in method available while testing a change. Do not remove your only working method before confirming the replacement.
Selecting a card is an unsaved edit. Cancel resets unsaved selections. If saving fails, read the error, resolve it and retry; do not assume the sign-in policy changed.
Available methods
Microsoft lets users sign in with a Microsoft account.
Google lets users sign in with a Google account.
Email login link sends a secure sign-in link to the user's email address.
For Microsoft, Google and email login links, the identity used to sign in must match a user provisioned in your Lexful account. Enabling Google or Microsoft does not give every person at that provider access to your account. Add teammates through Platform → Users and choose their role and organizations there.
For example, if you added [email protected], the person should select that identity at the provider rather than a different personal or work email address.
Set up Single Sign-On
Admins can configure Microsoft Entra SAML Single Sign-On (SSO) in Platform → Authentication → SSO connections. Follow Set up Microsoft Entra single sign-on (SAML) for the complete walkthrough, including the Entra application, claims, metadata and sign-in test.
Microsoft sign-in and an Entra SAML SSO connection are separate methods. Selecting Microsoft does not configure a SAML connection.
New SSO users receive the Viewer role with no organization access by default. Review their role and organization access in Platform → Users. Contact Lexful support for help with connection-level user-access mappings.
Once the connection is Active, enable Single Sign-On (SSO) under Sign-in methods, select Save changes and test with an assigned Entra user before turning off another working method.
When sign-in fails
Confirm you are using the correct Lexful account URL.
Ask an Admin to confirm the user exists under Platform → Users with the same email used to sign in.
Check that the chosen method is enabled and saved.
For SSO, confirm the connection is active, the person is assigned to the Entra application, and the role and organization mappings are correct.
Check Platform → IP restrictions if the account only permits approved networks.
Authentication establishes identity. Roles, organizations, groups and record access determine what a signed-in person can do and see.
If you are locked out, contact [email protected]. Include the account URL, sign-in method and visible error, but never send a password, API secret or sign-in link.
