Single Sign-On (SSO) allows your team to securely log in to Lengow using your company's existing credentials. By routing authentication through your own Identity Provider (IDP), you can enforce your organization’s security policies, including Multi-Factor Authentication (MFA), and streamline access management for your Lengow account.
This guide outlines the steps required to configure and validate SSO for your workspace.
1. Preparation: What your IT Team needs to do
To initiate the SSO onboarding process, your IT team will need to prepare a few details and create an authentication app. Lengow supports major SAML 2.0 and OIDC Identity Providers, including Google Workspace, Microsoft Entra ID (Azure AD), and Okta.
Please gather the following information to share with our team:
- Your Identity Provider (IDP): Let us know which system you use (e.g., Okta, Entra ID, Google).
- Your Authentication Domain(s): Provide the domain(s) used for your users' email addresses (e.g., @yourcompany.com). We can support multiple domains for a single SSO connection.
Create the Authentication App:
Your IT team must create a new authentication app for Lengow on your IDP tenant. Once you contact our support team with your IDP and domain details, we will securely provide you with the necessary Lengow configuration details (such as our callback URLs and identifiers) required to complete the app setup on your end.
If this procedure is unfamiliar to your team, you can refer to the official documentation for the three main Identity Providers here:
- Okta doc: Create OpenID Connect app integrations
- Microsoft Azure doc: How to Register an App in Microsoft Entra ID - Microsoft identity platform
- Google Workspace doc: Get started with the Google Auth Platform - Google Cloud Platform Console Help
2. Configuring the connection
Once your IT team has set up the Lengow authentication app in your IDP, you will generate a Client ID and Secret ID.
- Provide Credentials: Securely share the generated Client ID and Secret ID with the Lengow team.
- Lengow Configuration: Our engineering team will use these credentials to establish and map the enterprise connection directly to your Lengow account.
Multi-Factor Authentication (MFA)
MFA is handled entirely by your Identity Provider. Lengow does not configure or enforce MFA directly; instead, we rely on the security protocols and MFA requirements you have established within your own IDP configuration.
3. Validating and testing the setup
Before rolling out SSO to your entire team, we must validate the end-to-end connection.
- Test User Account: We request that you provide us with a test user account (using an email address that matches your approved domain). This allows our team to autonomously test the full authentication flow and make any necessary adjustments.
- Live Testing: If providing a test account is not possible, we will schedule a brief meeting between your IT point of contact and our engineering team to test the login flow together.
4. User preparation and first login expectations
The experience for your users depends on the specific combination of Lengow products active in your workspace.
- User Preparation: Depending on your setup, users may need to be manually invited to your Lengow workspace before their first login, or their accounts may be provisioned automatically on the fly during authentication. The Lengow team will confirm which method applies to your account during the setup phase.
- The First Login: When a user navigates to the Lengow login page and enters their email address, they will be seamlessly redirected to your company's Identity Provider. Once they successfully authenticate (including any MFA prompts your IDP requires), they will be redirected back to the appropriate Lengow product.
5. Troubleshooting and Support
While the SSO login process is designed to be seamless, users might occasionally experience a short delay or an access issue during their first setup.
Synchronization Delays
When a new user is authenticating for the first time or when user details are updated, the synchronization process with your workspace may take up to a minute. If a user cannot immediately access the product after their first successful login, please wait a moment and have them refresh the page.
| Common Issue | Recommended Action |
|---|---|
| Authentication fails at login | Verify that the user's email domain strictly matches your approved SSO configuration and that they are actively assigned to the Lengow app within your Identity Provider. |
| User logs in but cannot access the expected product | Ensure the user has been properly invited to the workspace and assigned the correct permissions prior to logging in. Additionally, verify that their email address is not already tied to a different Lengow account, as this will prevent successful access. |
Reaching Out to Support
If a user continues to experience failed logins or access issues after verifying the steps above, our automated system may have paused their synchronization after multiple failed attempts.
Please contact Lengow Support and provide the affected user's email address, the exact timestamp of their login attempt, and a brief description of the issue. Our team will investigate the authentication flow and manually re-trigger the account synchronization for you.