Skip to main content

Security & Compliance

Learn how to configure Single Sign-On and two-factor authentication to keep your Lumofy environment secure.

Written by Mohamed Shantory

Before You Start

  • You must be a Super Admin to configure SSO and authentication settings

  • Security settings are under Settings → Platform Settings


Overview

Lumofy provides two layers of access security: Single Sign-On (SSO) via SAML 2.0 for centralised identity management, and Two-Factor Authentication (2FA) for an added login verification step. Both are configured under Platform Settings.


Single Sign-On (SSO)

Supported Providers

Lumofy supports SSO via the SAML 2.0 protocol. You can integrate with:

  • Google Workspace

  • Microsoft Entra (formerly Azure AD)

  • Any SAML 2.0-compatible identity provider

Configuring SAML SSO

  1. Go to Settings from your user menu (bottom left)

  2. Click the Platform Settings tab

  3. Select SAML SSO Configuration from the left menu

  4. Enable Single sign-on (SSO) via SAML

  5. Configure the following fields:

Field

What to enter

Service Provider Metadata URL

The Lumofy metadata URL — copy this and give it to your identity provider

Identity Provider Metadata URL

The metadata URL from your identity provider (Google Workspace or Microsoft Entra)

Name ID Format URN

The URN format your identity provider uses for the Name ID

Login Help Text (English)

Optional text shown on the SSO login page in English

Login Help Text (Arabic)

Optional text shown on the SSO login page in Arabic

  1. Optionally enable Sign Authentication requests for added security

  2. Optionally enable Use lowercase URL encoding if required by your identity provider

  3. Click Save Changes

💡 Tip: Your identity provider administrator will need the Service Provider Metadata URL to complete the setup on their side. Share this URL with them before configuring the Identity Provider Metadata URL.


Two-Factor Authentication (2FA)

2FA adds a second verification step at login, reducing the risk of unauthorised access even if a password is compromised.

2FA Options

Lumofy supports two levels of 2FA enforcement:

Level

What it means

Per-user

Individual users can enable 2FA on their own account from their profile settings

Per-company (enforced)

The Super Admin enforces 2FA for all users in the organisation — every user must complete the 2FA setup before they can access the platform

Configuring 2FA

  1. Go to Settings → Platform Settings

  2. Select Authentication from the left menu

  3. Configure the 2FA enforcement level as needed

⚠️ Warning: Enabling company-wide 2FA enforcement will require all users to set up 2FA at their next login. Communicate this change to your users before enabling it to avoid access disruptions.


FAQs

Can we use SSO without SAML 2.0?

Lumofy currently supports the SAML 2.0 protocol for SSO. If your identity provider supports SAML 2.0, it is compatible with Lumofy.

What happens to users who cannot complete 2FA setup?

They will not be able to log in until 2FA is set up. Ensure users have access to an authenticator app or the configured 2FA method before enforcing it company-wide.

How long does the Competency Assessment take for each Talent?

No. When 2FA is enforced at the company level, individual users cannot disable it.

Can individual users disable 2FA if the company has enforced it?

Competency Assessments should be complete. Their results directly inform which content is most relevant for each Talent.

Does SSO replace the Lumofy login page?

When SSO is enabled, users are redirected to your identity provider to authenticate. They are then returned to Lumofy automatically after successful authentication.

Did this answer your question?