Overview
Legora is moving to a new authentication protocol so each user has one identity across Legora, no matter which region or organization they work in. As part of this change, your organization will use a dedicated login URL and updated authentication routes.
To prepare for rollout, admins and IT administrators need to make the following updates:
Add the new callback URLs in your identity provider and active integration settings.
Whitelist the required domains on your network.
Keep all existing URLs and settings in place. These updates should be added alongside your current configuration.
Add callback URLs
Identity provider callback URLs
If your organization uses SSO, add the following URLs as allowed callback URIs in your identity provider configuration:
https://sso.legora.com/api/oauth/samlhttps://sso.legora.com/api/oauth/oidc
Important note: All updates should be made in addition to your existing configuration. Do not remove any existing URLs or settings at any point during this process.
Where to add them depends on your provider:
Okta: Add both URLs to the Sign-in redirect URIs in the Legora application settings.
Microsoft Entra ID: Add both URLs to the Redirect URIs in the Legora app registration. Refer to Enabling the Entra ID integration.
Other identity providers: Add both URLs as allowed callback URIs following your provider’s documentation.
Integration callback URLs
For each active integration, add the relevant redirect URI in that integration’s admin settings:
Integration | URL/URI to add | Where to add it |
iManage (on-premises) |
| Add the link in your iManage configuration as an allowed callback URL. Refer to our support page on Enabling iManage integration - On-Prem setup guide. |
SharePoint |
| Add the link as a registered redirect URI in SharePoint admin. Refer to our support page on Enabling the Sharepoint integration guide. |
Google Drive |
| Add the link as a redirect URI in Google Workspace admin. Refer to our support page for Google drive integration overview. |
iManage Cloud | No action needed | Legora handles this automatically. |
Allowlist domains
Allowlist the following domains on your network, for both inbound and outbound traffic as applicable to your network setup:
Add your organization’s new dedicated domain to your network allowlist. You can find this domain at the top of Settings > Authentication migration. For instructions, see Legora network and domain requirements.
https://auth.legora.com
Portal and mobile app
Portal
If your organization invites another Legora customer to your Portal, both organizations must be on the new authentication protocol before the invitation can work. Portal invitations to clients who do not use Legora are not affected.
Mobile app
Mobile app access remains unchanged. Users may need to sign in again after migration.
Word and Outlook Add-in
After your organization completes migration to Legora’s new authentication protocol, the existing add-ins will stop working and will need to be reinstalled. Going forward there will be a single Word add-in and a single Outlook add-in, both available in Microsoft AppSource.
When you reinstall the Word or Outlook add-in, any thread history created in the existing add-in will not carry over. This history cannot be recovered. If there is anything you may need to reference, save it somewhere before reinstalling.
Review your organization’s dedicated domain
From your name in the sidebar, select Settings > Authentication migration.
Review the dedicated login URL that Legora has pre-populated for your organization.
If you need to change it, make the change before the migration.
Additional help
If you are unsure which updates apply to your organization, contact your Legora representative.
