Before You Start
You must be a Super Admin to configure SSO and authentication settings
Security settings are under Settings → Platform Settings
Overview
Lumofy provides two layers of access security: Single Sign-On (SSO) via SAML 2.0 for centralised identity management, and Two-Factor Authentication (2FA) for an added login verification step. Both are configured under Platform Settings.
Single Sign-On (SSO)
Supported Providers
Lumofy supports SSO via the SAML 2.0 protocol. You can integrate with:
Google Workspace
Microsoft Entra (formerly Azure AD)
Any SAML 2.0-compatible identity provider
Configuring SAML SSO
Go to Settings from your user menu (bottom left)
Click the Platform Settings tab
Select SAML SSO Configuration from the left menu
Enable Single sign-on (SSO) via SAML
Configure the following fields:
Field | What to enter |
Service Provider Metadata URL | The Lumofy metadata URL — copy this and give it to your identity provider |
Identity Provider Metadata URL | The metadata URL from your identity provider (Google Workspace or Microsoft Entra) |
Name ID Format URN | The URN format your identity provider uses for the Name ID |
Login Help Text (English) | Optional text shown on the SSO login page in English |
Login Help Text (Arabic) | Optional text shown on the SSO login page in Arabic |
Optionally enable Sign Authentication requests for added security
Optionally enable Use lowercase URL encoding if required by your identity provider
Click Save Changes
💡 Tip: Your identity provider administrator will need the Service Provider Metadata URL to complete the setup on their side. Share this URL with them before configuring the Identity Provider Metadata URL.
Two-Factor Authentication (2FA)
2FA adds a second verification step at login, reducing the risk of unauthorised access even if a password is compromised.
2FA Options
Lumofy supports two levels of 2FA enforcement:
Level | What it means |
Per-user | Individual users can enable 2FA on their own account from their profile settings |
Per-company (enforced) | The Super Admin enforces 2FA for all users in the organisation — every user must complete the 2FA setup before they can access the platform |
Configuring 2FA
Go to Settings → Platform Settings
Select Authentication from the left menu
Configure the 2FA enforcement level as needed
⚠️ Warning: Enabling company-wide 2FA enforcement will require all users to set up 2FA at their next login. Communicate this change to your users before enabling it to avoid access disruptions.
FAQs
Can we use SSO without SAML 2.0?
Can we use SSO without SAML 2.0?
Lumofy currently supports the SAML 2.0 protocol for SSO. If your identity provider supports SAML 2.0, it is compatible with Lumofy.
What happens to users who cannot complete 2FA setup?
What happens to users who cannot complete 2FA setup?
They will not be able to log in until 2FA is set up. Ensure users have access to an authenticator app or the configured 2FA method before enforcing it company-wide.
How long does the Competency Assessment take for each Talent?
How long does the Competency Assessment take for each Talent?
No. When 2FA is enforced at the company level, individual users cannot disable it.
Can individual users disable 2FA if the company has enforced it?
Can individual users disable 2FA if the company has enforced it?
Competency Assessments should be complete. Their results directly inform which content is most relevant for each Talent.
Does SSO replace the Lumofy login page?
Does SSO replace the Lumofy login page?
When SSO is enabled, users are redirected to your identity provider to authenticate. They are then returned to Lumofy automatically after successful authentication.

