Overview
This guide is for Admin or IT administrators responsible for completing the migration to Legora's new authentication protocol. You’ll need work through these migration tasks in order.
All updates should be made in addition to your existing configuration. Do not remove any existing URLs or settings at any point during this process.
Migration
How to complete the migration
This section walks you through the required updates before rollout, including identity provider settings, integration callback URLs, your dedicated domain, firewall rules, testing, user rollout, and add-in reinstall steps.
Important Note: All updates should be made in addition to your existing configuration. Do not remove any existing URLs or settings at any point during this process.
Update your identity provider (SSO only)
Add the following URLs as allowed callback URIs in your identity provider configuration:
https://sso.legora.com/api/oauth/samlhttps://sso.legora.com/api/oauth/oidc
Add the URLs in the correct place for your provider:
Okta: Add both URLs to the Sign-in redirect URIs in the Legora application settings.
Microsoft Entra ID: Add them to the Redirect URIs in the Legora app registration. Refer to Enabling the Entra ID integration.
Other identity providers: Add them as allowed callback URIs following your provider’s documentation.
SAML as Identity Provider requires an additional step:
Because a SAML app registration is tied to the service provider’s Entity ID, the existing app registration can’t simply be repointed at the new platform.
Create a new SAML app registration in your identity provider.
Add the following values to the new SAML app registration in your identity provider’s administration console:
Entity ID/Audience URI/Identifier: sso.legora.com
ACS URL/Single Sign-On/Reply URL: https://sso.legora.com/api/oauth/saml
Keep your existing SAML app untouched. It will continue to serve logins exactly as it does today until you enable the self-serve migration.
Update integration callback URLs
For each active integration, add the new URL as an allowed redirect URI in that integration's admin settings. Keep all existing URLs in place.
Integration | URL/URI to add | Where to add it |
iManage (on-premises) |
| Add the link in your iManage configuration as an allowed callback URL. Refer to our support page on Enabling iManage integration - On-Prem setup guide. |
SharePoint |
| Add the link as a registered redirect URI in SharePoint admin. Refer to our support page on Enabling the Sharepoint integration guide. |
Google Drive |
| Add the link as a redirect URI in Google Workspace admin. Refer to our support page for Google drive integration overview. |
iManage Cloud | No action needed | Legora handles this automatically. |
Review your organization's dedicated domain
From your name in the sidebar, select Settings > Authentication migration.
Review the dedicated login URL that Legora has pre-populated for your organization.
If you need to change it, make the change before the migration.
Update firewall rules
Allowlist the following domains on your network. Apply to both inbound and outbound traffic as applicable to your network setup:
Your organization's new dedicated domain is visible in Settings > Authentication migration
https://auth.legora.com
Test before rolling out
If you have multiple Legora organizations, repeat these steps to test the roll out for all of them.
Once the setup is complete, from your name in the sidebar, select Settings > Authentication migration and run these pre-migration checks.
On the Authentication migration page, confirm:
Your organization’s dedicated login URL is set.
For each SSO connection listed, click Run test and confirm the status shows Passed.
For each integration listed (iManage, SharePoint, Google Drive, where applicable), click Run test and confirm Passed.
We recommend that an Admin or IT administrator uses the new dedicated login URL with a small user test group to validate day-to-day workflows before you communicate the URL to the wider organization. To do this:
The Admin or IT administrator should sign in using the new dedicated login URL and confirm:
The URL loads correctly.
Sign-in completes end to end using the configured sign-in method, such as SSO or username and password.
Integrations work in real use: iManage, SharePoint, and Google Drive where applicable.
Download the new Global Add-ins for Word and Outlook from the AppSource store, or install them using the available manifests.
Share the URL to the small group so they can complete the same checks.
Roll out to all users
If you have multiple Legora organizations, repeat these steps to roll out for all of them.
Once you have confirmed the Enable Legora’s authentication (organization-wide cutover)
We recommend informing your organization before hand and doing the migration outside of working hours.
Inform your users how to access the new Global Add-ins for Word and Outlook, and that they will loose their history in the Add-ins.
When all pre-migration checks pass, click Enable on the Migration Authentication page.
This switches your entire organization to the new dedicated login URL. It cannot be undone. After this, old regional URLs stop working for all users.
Share the new dedicated login URL with your users.
Follow the relevant guidance for each sign-in method:
SSO users: Continue signing in through SSO. The main change is that they should use the new dedicated login URL.
Email, password, and multi-factor authentication users: Will have to reset their password the first time they log in after migration. They will receive a password reset email from Legora and should follow the instructions promptly.
Note that the minimum password length has changed from 12 to 15 characters. New passwords must be at least 15 characters long.
Reinstall Word and Outlook add-ins
After migration, users need to use the new Global Legora Word and Outlook add-ins.
Choose the relevant installation method for your organization:
Centrally managed by IT: Install the Global Word and Outlook add-ins from Microsoft AppSource. Refer to Outlook add-in for admins and How do I install the Word add-in? for more information.
User-installed: Ask users to install the new Global Word and Outlook add-ins from Microsoft AppSource.
On-premises Legora Global Outlook and Word: Reinstall the add-ins using the manifest files provided by your Legora representative.
When you reinstall the Global Word or Outlook add-in, any thread history created in the existing add-in will not carry over. This history cannot be recovered. If there is anything you may need to reference, save it somewhere before reinstalling.
Mobile app access
Access to the mobile app will remain unchanged, but you may see a Global option in the regional dropdown menu during migration. Users will only need to log in again after the migration.
If you have questions at any stage, contact your Legora representative. They can:
Provide manifest files for the add-ins
Arrange a walkthrough with your team if needed
You can also reach Legora at [email protected].
