Use your Microsoft Entra SSO connection’s Access tab to choose how new users start in Lexful and map Entra groups to Lexful roles and groups.
Setting up SSO for the first time? Start with Set up Microsoft Entra single sign-on (SAML). This guide covers access after the connection is configured.
Before you begin
You need the Admin role in Lexful and an Active SSO connection.
To use Entra group rules, you need permission to edit the enterprise application’s SAML claims and view group Object IDs.
Assigning groups to an enterprise application requires Microsoft Entra ID P1 or higher. If that option is unavailable, see the Security groups alternative below.
1. Choose the default access for new users
Go to Platform → Authentication → SSO connections.
Open your connection and select Access.
Choose the Default role: Admin, Support or Viewer.
Under Organizations they start with, choose No organizations, Selected organizations or All organizations. Select the organizations if needed.
Click Save changes.
These defaults apply when Lexful creates a new user through SSO. Changing them does not reset the role or organization access of existing users. Without custom defaults, new users start as Viewers with no organization access.
For existing users, manage organization access in Platform → Users. Role and group rules can also update existing users at sign-in, depending on the Apply option you choose.
2. Send Entra group IDs to Lexful
Skip this step if you only need default access. Role and group rules need a claim in the SAML response containing the values you want to match.
In Microsoft Entra, open your Lexful enterprise application.
Go to Single sign-on → Attributes & Claims → Edit.
Click Add a group claim.
Select Groups assigned to the application to keep the claim focused on the groups relevant to Lexful.
Set Source attribute to Group ID. Leave Emit group name for cloud-only groups unchecked.
Click Save.
Assign the relevant groups under the enterprise application’s Users and groups. With Groups assigned to the application, users must be direct members of those groups; nested membership is not included.
To copy a group’s ID, open Entra → Groups → [group] → Overview and copy its Object ID. Use that value in Lexful, not the group’s display name.
If you cannot assign groups to the application
You can select Security groups in the group claim instead, keeping Group ID as the source. This sends a broader set of memberships, so take care with users who belong to many groups.
Entra includes up to 150 groups in a SAML response. Above that limit, it can send an overage reference instead of the group list. Lexful does not follow that reference to retrieve groups. Keep the emitted group list small enough for the IDs to be included.
See Microsoft’s group claims documentation for membership and token limits.
3. Map Entra groups to Lexful roles
In the connection’s Access tab, click Add rule under Role assignment rules.
Keep Matching on Entra groups for the standard Entra group claim. If you use another claim, choose Change and enter its claim name.
Paste the Entra group’s Object ID and choose the Lexful role.
Use the arrows to arrange rules in priority order.
Choose At every sign-in or On user creation, then click Save changes.
The first matching role rule wins. Put the highest-priority rule first when a user can match more than one group. Values must match exactly, including case.
At every sign-in: Lexful reevaluates the role when the user signs in through this connection. If the configured claim is present but no rule matches, the connection’s default role is used.
On user creation: rules set the role when Lexful creates the user through SSO; later sign-ins do not overwrite their role.
Missing claim: Lexful preserves an existing user’s role. New users still receive the configured default.
Lexful will not demote the account’s last Admin through a role rule.
4. Map Entra groups to Lexful groups
Under Group assignment rules, click Add rule.
Paste the Entra group’s Object ID and choose the corresponding Lexful group.
Add rules for other Entra groups as needed.
Choose At every sign-in or On user creation, then click Save changes.
Matching Entra group values can place a user in multiple Lexful groups. For example, one Entra group can map to your Support group and another to your Operations group.
With At every sign-in, Lexful updates the memberships managed by these rules: matching memberships are added, and managed memberships that no longer match are removed. Memberships outside the configured mappings are left alone. If the group claim is missing, existing memberships are preserved.
With On user creation, mappings apply only when Lexful creates the user through SSO. If a target Lexful group has been deleted, replace or remove that rule.
5. Test and inspect the result
Have a test user sign out and sign back in through the SSO connection.
Open Platform → Users. Use the SSO filter to find users who have signed in through SSO; additional filters let you narrow by connection or connection type.
Open the user and check their role, organization access and SSO connection.
Expand Claims from the latest sign-in to inspect the values Entra sent.
Check their Lexful group memberships against your mappings.
Saving a rule does not immediately update signed-in users. Rules set to At every sign-in apply on their next SSO sign-in. To test creation-only defaults or rules, use a user who does not already exist in Lexful.
Troubleshooting
A rule does not match
Inspect the latest sign-in claims. Confirm the group claim exists and contains the exact Object ID entered in the rule. Check direct membership and application assignment when using Groups assigned to the application. For role rules, also check whether an earlier rule wins.
The user’s role changes back after sign-in
A role rule set to At every sign-in can overwrite a manually assigned role. Update the mapping, or choose On user creation if you want to manage roles manually after creation.
Group changes are not reflected in Lexful
Confirm the Apply setting, save the rules and have the user sign in again. If the group claim is absent, check Entra’s claim configuration and the 150-group SAML limit. A missing claim preserves existing access rather than removing it.
A new user cannot see any organizations
Check Organizations they start with. The initial setting is No organizations. Update an existing user in Platform → Users; changing the connection’s creation defaults alone will not update them.


