Enterprise SSO Setup
Enterprise single sign-on (SSO) routes sign-in through your organisation's identity provider (IdP), such as Microsoft Entra ID.
When Lleverage activates SSO for a domain, it applies to all users with that email domain, including existing users. Plan the activation with your Lleverage contact and select a few key users to validate sign-in immediately. Lleverage can deactivate the connection again if needed.
1. Plan the Rollout
Before setup:
Choose an activation time with your Lleverage contact.
Select key users who represent the domains and access roles you need to test.
Make sure those users are invited to the correct Organisation and Projects.
List the primary domain and any additional domains that should use SSO.
Make sure your IT administrator can configure your IdP.
Completing the setup does not change sign-in until Lleverage activates the connection.
2. Configure the Connection
Sign in to Lleverage as an Organisation Owner.
Go to Organisation Settings → SSO, or open:
https://app.lleverage.ai/{org-slug}/settings/ssoEnter your primary email domain, such as
acme.com.Select Setup Portal and follow the WorkOS instructions.
Send your Lleverage contact the primary domain and every additional domain that should use SSO.
Agree when Lleverage should activate the connection.
Always open the Setup Portal from the SSO Settings page. Links shared by email are temporary and can expire.
3. Whitelist Users for App Access
Some identity providers only let users open an application after they are explicitly assigned to it. Microsoft Entra ID (Azure AD) commonly does this: if the enterprise application requires user assignment, or a Conditional Access policy is scoped to it, unassigned users are blocked at sign-in even though SSO is configured correctly.
To avoid a disruptive activation, whitelist your users before the connection goes live:
In Lleverage, go to Organisation Settings → SSO.
In the User Export card, select Export CSV to download all organisation users and their roles.
In your IdP, assign (whitelist) those users to the Lleverage application, or add them to the group your access policy targets.
Confirm that any Conditional Access policies allow the Lleverage application for those users.
Once your users are whitelisted, tell your Lleverage contact that you are ready. They will put the connection live.
4. Activate and Validate
Once Lleverage activates the connection, all users with a configured domain will use SSO, including existing users.
Validate immediately with your selected users:
Log out of Lleverage or open a private browser window.
Enter the company email address in the regular email login flow. Do not select the Microsoft sign-in button.
Confirm that the user is redirected to your IdP.
Complete sign-in and confirm access to the expected Organisation and Projects.
Test at least one invited user from each configured domain.
If validation fails, contact Lleverage. The connection can be corrected or deactivated.
Access Requirements
SSO changes authentication only. It does not automatically grant access or provision users.
Invite each user to the Organisation and relevant Projects.
Assign the appropriate roles before testing.
A user without an invitation cannot access the Organisation, even if their domain uses SSO.
Group-based access and SCIM provisioning are not currently supported.
See Roles and Permissions for access management.
Common Issues
The Setup Portal link expired
Open Organisation Settings → SSO and select Setup Portal again.
A user is not redirected to the IdP
Use the regular email login flow and ask Lleverage to confirm that the domain is active.
One domain does not work
Ask Lleverage to confirm that the domain is included in the connection.
Sign-in works but access is missing
Confirm that the user was invited to the Organisation and relevant Projects.
All users blocked after activation
Confirm that your users are assigned (whitelisted) to the Lleverage application in your IdP, and that Conditional Access allows it.
SSO must be rolled back
Ask Lleverage to deactivate the connection.
Last updated
Was this helpful?