Skip to main content

Overview

This guide is for Admin or IT administrators responsible for completing the migration to Legora’s new authentication protocol. You’ll need work through these migration tasks in order. All updates should be made in addition to your existing configuration. Do not remove any existing URLs or settings at any point during this process.

Migration

How to complete the migration

This section walks you through the required updates before rollout, including identity provider settings, integration callback URLs, your dedicated domain, firewall rules, testing, user rollout, and add-in reinstall steps. Important Note: All updates should be made in addition to your existing configuration. Do not remove any existing URLs or settings at any point during this process.

Update your identity provider (SSO only)

  1. Legora uses two separate callback URLs, one for each sign-in protocol. Add the one that matches your protocol (or both, if you’re not sure which your organization will use):
    • https://sso.legora.com/api/oauth/saml — used only for SAML connections
    • https://sso.legora.com/api/oauth/oidc — used only for OIDC connections (this is what Microsoft Entra ID uses)
  2. Add the URLs in the correct place for your provider:
    • Okta: Okta can be set up for either SAML or OIDC. Add the URL matching the protocol you’re configuring for Legora (add both if you’re unsure which one you’ll end up using).
    • Microsoft Entra ID: Entra ID connections should use OIDC. Add the OIDC callback URL to the Redirect URIs in the Legora app registration. See Enabling the Entra ID integration. Legora does not support multiple SAML app registrations in the same Microsoft Entra tenant. If your organization currently uses multiple SAML apps in Entra, you’ll need to move those connections to OIDC as part of the migration.
    • Other identity providers: Add the callback URL matching your provider’s protocol (SAML or OIDC), following your provider’s documentation.
  3. SAML as Identity Provider requires an additional step: Because a SAML app registration is tied to the service provider’s Entity ID, the existing app registration can’t simply be repointed at the new platform.
    1. Create a new SAML app registration in your identity provider.
    2. Add the following values to the new SAML app registration in your identity provider’s administration console:
      1. Entity ID/Audience URI/Identifier: https://sso.legora.com/
      2. ACS URL/Single Sign-On/Reply URL: https://sso.legora.com/api/oauth/saml
    3. Keep your existing SAML app untouched. It will continue to serve logins exactly as it does today until you enable the self-serve migration.
    4. If you use Microsoft Entra ID and have more than one SAML app registration for Legora in the same Entra tenant, do not create additional SAML app registrations for the migration. Move these connections to OIDC instead.

Update integration callback URLs

  1. For each active integration, add the new URL as an allowed redirect URI in that integration’s admin settings. Keep all existing URLs in place.

Review your organization’s dedicated domain

  1. From your name in the sidebar, select Settings > Authentication migration.
  2. Review the dedicated login URL that Legora has pre-populated for your organization.
  3. If you need to change it, make the change before the migration.

Update firewall rules

  1. Allowlist the following domains on your network. Apply to both inbound and outbound traffic as applicable to your network setup:
    1. Your organization’s new dedicated domain is visible in Settings > Authentication migration
    2. https://auth.legora.com

Test before rolling out

If you have multiple Legora organizations, repeat these steps to test the roll out for all of them.
  1. Once the setup is complete, from your name in the sidebar, select Settings > Authentication migration and run these pre-migration checks.
  2. On the Authentication migration page, confirm:
    • Your organization’s dedicated login URL is set.
    • For each SSO connection listed, click Run test and confirm the status shows Passed.
    • For each integration listed (iManage, SharePoint, Google Drive, where applicable), click Run test and confirm Passed.
  3. We recommend that an Admin or IT administrator uses the new dedicated login URL with a small user test group to validate day-to-day workflows before you communicate the URL to the wider organization. To do this:
    • The Admin or IT administrator should sign in using the new dedicated login URL and confirm:
      • The URL loads correctly.
      • Sign-in completes end to end using the configured sign-in method, such as SSO or username and password.
      • Integrations work in real use: iManage, SharePoint, and Google Drive where applicable.
      • Download the new Global Add-ins for Word and Outlook from the AppSource store, or install them using the available manifests:
      • Share the URL to the small group so they can complete the same checks.

Roll out to all users

If you have multiple Legora organizations, repeat these steps to roll out for all of them.
  1. Once you have confirmed to Enable Legora’s authentication (organization-wide cutover):
    1. Inform your organization before hand and complete the migration outside of working hours.
    2. Tell your users how to access the new Global Add-ins for Word and Outlook (See below). Before the cutover, Word Add-in users must export their Assistant history to their local device and keep the downloaded file somewhere secure. See How to move your Word Add-in Assistant history to the Global Add-in for step-by-step instructions.
    3. Any Assistant history not exported cannot be recovered after the migration.
    4. This switches your entire organization to the new dedicated login URL and can’t be undone. Once it’s done, old regional URLs will stop working for everyone.
    5. Share the new dedicated login URL with your users.
Agent chats are not part of this export and do not need to be. They are stored in Legora, so they are preserved through the migration and remain available after your users switch to the new add-in.
  1. Follow the relevant guidance for each sign-in method:
    1. SSO users: Continue signing in through SSO. The main change is that they should use the new dedicated login URL.
    2. Email, password, and multi-factor authentication users: Will have to reset their password the first time they log in after migration. They will receive a password reset email from Legora with a subject along the lines of Reset your Legora password. That email contains a one-time code. Users enter the code, then set a password of at least 15 characters on Set a new password. If they see Invalid recovery link or Could not reset password., they should start Forgot password? again and finish promptly. For the full user steps, see Why can I not log in to Legora?.
  2. Note that the minimum password length has changed from 12 to 15 characters. New passwords must be at least 15 characters long.

Reinstall Word and Outlook add-ins

  1. After migration, users need to use the new Global Legora Word and Outlook add-ins.
  2. Choose the relevant installation method for your organization:
    1. Centrally managed by IT: Install the Global Word and Outlook add-ins from Microsoft AppSource. Refer to Outlook add-in for admins and How do I enable the Word Add-in for users in my Legora org? for more information.
    2. User-installed: Ask users to install the new Global Word and Outlook add-ins from Microsoft AppSource.
    3. On-premises Legora Global Outlook and Word: Reinstall the add-ins using the manifest files provided by your Legora representative.
  3. When you reinstall the Global Word or Outlook add-in, any thread history created in the existing add-in will not carry over. This history cannot be recovered. If there is anything you may need to reference, save it somewhere before reinstalling.

Mobile app access

  1. Access to the mobile app will remain unchanged, but you may see a Global option in the regional dropdown menu during migration. Users will only need to log in again after the migration.

If you have questions at any stage, contact your Legora representative. They can:
  • Provide manifest files for the add-ins
  • Arrange a walkthrough with your team if needed
You can also reach Legora at support@legora.com.