An SSO connection lets your team sign in to Lexful with their Microsoft Entra accounts over SAML. Admins set it up in Platform → Authentication → SSO connections, then turn on SSO as a sign-in method.
Setup has two sides: you create the connection in Lexful, then create a matching enterprise application in Microsoft Entra. Each side needs a few values from the other.
New connection? Follow the steps below to configure SAML, choose access defaults and test sign-in.
Already connected? For the connection’s Access tab, group mappings and sign-in claims, see Assign roles, organizations and groups with Microsoft Entra SSO.
Before you begin
You need the Admin role in Lexful.
You need permission to create enterprise applications in your Microsoft Entra tenant, such as the Cloud Application Administrator role.
Every user who will sign in with SSO needs an email address in Entra. Accounts without one can't sign in.
Keep another sign-in method turned on until you have tested SSO.
Step 1: Create the connection in Lexful
Go to Platform → Authentication and open the SSO connections tab.
Click Add SAML connection.
Enter a Name, such as Microsoft Entra. Users see this name on the sign-in button.
Click Create connection.
The connection opens with the status Setup incomplete. Open the Connection tab and keep this panel open: the Add Lexful to Entra section shows two values you need in the next step.
Identifier (Entity ID)
Reply URL (ACS URL)
Use the copy button to avoid typing mistakes. When both values are identical, Lexful shows one box labelled for both fields; paste that value into both fields in Entra. If they differ, Lexful shows each value separately.
Step 2: Create the enterprise application in Microsoft Entra
In the Microsoft Entra admin center, go to Enterprise applications and click New application.
Click Create your own application, enter a name such as Lexful, and choose Integrate any other application you don't find in the gallery (Non-gallery). Click Create.
In the new application, open Users and groups and click Add user/group. Assign the users or groups who should sign in to Lexful.
Open Single sign-on and choose SAML.
In Basic SAML Configuration, click Edit and enter the values from Lexful:
Identifier (Entity ID): paste the Lexful Identifier (Entity ID).
Reply URL (Assertion Consumer Service URL): paste the Lexful Reply URL (ACS URL).
Leave the other fields blank and click Save.
To show Lexful in your users' My Apps portal, open the application's Properties, set Assignment required? and Visible to users? to Yes, and click Save. With assignment required, only assigned users and groups can sign in to Lexful with SSO.
Step 3: Check Attributes & Claims
Lexful reads each user's email and name from Entra's standard claims. Entra adds these claims to new applications by default, so you usually don't need to change anything.
All three claim names use the prefix http://schemas.xmlsoap.org/ws/2005/05/identity/claims/.
Lexful field | Entra claim | Default source in Entra |
emailaddress | user.mail | |
First name | givenname | user.givenname |
Last name | surname | user.surname |
In Single sign-on → Attributes & Claims, confirm the three claims are listed. Then set a stable identifier for each user:
Click Unique User Identifier (Name ID).
Set Name identifier format to Persistent.
Set Source attribute to user.objectid, then click Save.
Use user.objectid as the stable identifier instead of a name or email address.
Every assigned user needs an email address. The email claim comes from the user's Email field in Entra, which may be empty. To fix an account, open the user in Entra, click Edit properties, and set Email under Contact information.
Lexful matches users by email. Someone who already has a Lexful user with the same email signs in to that existing account.
Step 4: Finish the connection in Lexful
In Entra, on the application's Single sign-on page, go to SAML Certificates and download Federation Metadata XML.
Back in Lexful, on the connection’s Connection tab, in the Import Entra configuration section, drop the downloaded file onto Drop your metadata XML here, or click browse files.
Lexful fills in Microsoft Entra Identifier, Login URL and Signing certificate. Expand Enter details manually or review settings to review the values.
Leave the mappings under Claims · Entra defaults at their defaults unless you changed the claims in Entra.
Click Save changes.
The connection's status changes to Active once all three values are saved. This confirms that the configuration is complete; test an assigned user's sign-in before relying on it.
Prefer to enter the values by hand? Expand Enter details manually or review settings. Copy Login URL and Microsoft Entra Identifier from the Set up section of the Entra single sign-on page. Download Certificate (Base64) from SAML Certificates and paste its contents into Signing certificate. The Login URL must start with https://.
Step 5: Choose how users get access
Open the connection’s Access tab.
Choose the Default role for users created through this connection: Admin, Support or Viewer.
Under Organizations they start with, choose No organizations, Selected organizations or All organizations.
Click Save changes.
These defaults apply when Lexful creates a new user through SSO. They do not reset existing users’ roles or organization access. Without custom defaults, new users start as Viewers with no organization access.
Want access based on Entra groups? You can add role and group assignment rules here and choose whether they apply at every sign-in or only on user creation. Follow Assign roles, organizations and groups with Microsoft Entra SSO to configure the Entra group claim and mappings.
Step 6: Turn on SSO and test sign-in
Go to Platform → Authentication → Sign-in methods.
Under Company single sign-on, select Allow SSO sign-in. Leave your other methods selected for now.
Click Save changes.
In a private browser window, open your Lexful sign-in page and click Continue with [your connection name] SSO. Sign in as a user assigned to the Entra application.
The setting becomes available once a connection is Active. While setup is incomplete, it stays disabled as shown below.
Assigned users can also open Lexful from My Apps.
After sign-in, check the user’s role, organizations and group memberships. In Platform → Users, open the user to see their SSO connection and Claims from the latest sign-in. If access is unexpected, follow the checks in Assign roles, organizations and groups with Microsoft Entra SSO.
Once SSO works, you can turn off the other sign-in methods. Lexful won't let SSO be the only method unless at least one SSO connection is Active.
Manage SSO connections
The SSO connections tab lists each connection with its type and status.
Active: the required configuration is saved. Enable SSO and test sign-in to confirm it works.
Setup incomplete: the Entra identifier, login URL or signing certificate is missing. Open it to finish setup.
Edit a connection. Click its name, change the values, and click Save changes. If you close the panel with unsaved changes, Lexful asks before discarding them.
Replace the signing certificate. When Entra issues a new certificate, upload the new Federation Metadata XML or paste the new certificate, then click Save changes. Leave Signing certificate blank to keep the current one.
Delete a connection. Open it, open Connection actions (⋯), click Delete connection, and confirm. Users who signed in through it can no longer use it. You can't delete the only Active connection while SSO is the only sign-in method. Turn on another method first.
Existing OIDC connections appear in the list but can't be edited here. Contact Lexful support to change them.
Troubleshooting
"Unable to find a valid email in the SAML response"
The user has no email address in Entra, or the email claim is missing. Set Email on the user in Entra. Confirm the emailaddress claim is listed in Attributes & Claims.
"Email format is invalid"
The email claim holds something that isn't an email address. Make sure the emailaddress claim's source is user.mail, and that the user has an email set.
Entra says the user isn't assigned to the application
The user or their group isn't assigned. Add them in the application's Users and groups.
No SSO button on the Lexful sign-in page
SSO isn't turned on, or no connection is Active. Select Allow SSO sign-in in Sign-in methods, and finish setup on the connection.
Sign-in works but the user sees no organizations
Check the connection’s Access → Organizations they start with setting. The initial default is No organizations. Creation defaults do not update existing users; change their access in Platform → Users.
Sign-in stops working after Entra renews its certificate
Lexful still has only the old certificate. Upload the new Federation Metadata XML to the connection and save.
You can't save SSO as the only sign-in method, or can't delete a connection
Lexful prevents changes that would lock everyone out. Keep at least one Active connection, or turn on another sign-in method first.








