SSO and Onboarding

Leapwork Go currently uses enterprise Single Sign-On (SSO). Before users can access Leapwork Go, a Microsoft Entra ID or Google Workspace administrator must complete the initial SSO setup. Once configured, users can sign in with their existing organisational accounts without maintaining a separate Leapwork Go password.

Getting started

Is SSO required to use Leapwork Go?

Yes. SSO is currently required to access Leapwork Go. Standalone Leapwork Go usernames and passwords are not currently supported.

Which identity providers does Leapwork Go support?

Leapwork Go currently supports:

  • Microsoft Entra ID

  • Google Workspace

Other identity providers and standalone login methods are not currently supported.

What if our organisation does not use Microsoft Entra ID or Google Workspace?

Customers currently need Microsoft Entra ID or Google Workspace to access Leapwork Go. Leapwork plans to introduce additional login options and support for more identity providers in the future.

Will Leapwork Go support additional login options in the future?

Yes. Leapwork plans to introduce additional login options and support for more identity providers. The specific login options and availability dates will be communicated once confirmed.

Until then, Microsoft Entra ID or Google Workspace SSO is required to access Leapwork Go.

Can a Go user configure SSO independently?

Usually not. The initial configuration requires someone with the appropriate administrative permissions in Microsoft Entra ID or Google Workspace.

A Go user who does not have these permissions will need assistance from the organisation’s IT, security, or identity-management team.

Can I evaluate or start using Go before SSO is configured?

No. Since SSO is currently the only supported authentication model, users cannot access Go until the organisation’s SSO configuration has been completed.

Customers should identify the appropriate IT or identity administrator before beginning the onboarding process.

Why Leapwork Go uses SSO

Why does Leapwork Go require SSO?

SSO allows the customer’s organisation to retain control over authentication. Existing security policies can continue to apply, including:

  • Multi-Factor Authentication (MFA)

  • Conditional Access

  • Password security policies

  • User lifecycle management

  • Account disabling

  • Application access policies

SSO also means that users do not need to create and maintain a separate Leapwork Go password.

What support does Leapwork provide for SSO setup?

Leapwork provides the required settings and onboarding support to help the customer complete the configuration. However, the initial configuration still depends on the customer’s IT or identity-management team.

Onboarding to Go

Who needs to be involved in the setup?

The customer should identify:

  • A Microsoft Entra ID or Google Workspace administrator

  • The person who will become the first Leapwork Go administrator

  • A security or compliance contact, if the organisation requires an internal application review

These responsibilities may be handled by the same person in some organisations.

What does Leapwork provide during onboarding?

Leapwork provides:

  • The required application and configuration settings

  • A secure onboarding process for submitting the required information

  • Guidance for the customer’s identity administrator

  • Support during configuration and sign-in validation

  • Initial onboarding of the customer’s first Go administrator

What does the customer’s administrator need to do?

Depending on the identity provider and the organisation’s security policies, the administrator may need to:

  • Review or approve the Leapwork Go application

  • Provide the required tenant or domain information

  • Review and approve the requested identity permissions

  • Configure or approve the SSO application

  • Assign authorised users or groups

  • Participate in testing the sign-in process

How long does SSO setup take?

The technical configuration can be completed once the appropriate customer administrator is available. The total onboarding time depends on the customer’s internal security, application approval, and identity-management processes.

To avoid delays, customers should involve their Microsoft Entra ID or Google Workspace administrator at the beginning of the Go onboarding process.

What if we cannot obtain support from our IT administrator?

Leapwork can provide configuration guidance and onboarding support, but Leapwork cannot make changes inside the customer’s identity environment.

Go access cannot currently be activated until an authorised customer administrator completes the required configuration.

Microsoft Entra ID setup

What information is required for Microsoft Entra ID SSO?

The following information is required:

  • Microsoft Entra ID Tenant ID

  • Microsoft Entra ID Tenant Name

  • SSO domain

  • Contact details for the relevant administrator

Leapwork provides the application settings and onboarding instructions required to complete the configuration.

An Entra ID administrator is required to support the initial configuration. Whether a separate tenant-wide administrator consent action is required depends on the customer’s Entra ID policies and the final application configuration.

Leapwork limits its requested permissions to the identity information required for sign-in.

What Microsoft Graph permissions does Leapwork Go request?

Leapwork Go currently requests only the delegated Microsoft Graph permission User.Read. This permission is used during sign-in to retrieve basic information about the authenticated user.

Does User.Read allow Leapwork Go to access emails or files?

No. User.Read does not provide access to:

  • Emails or mailboxes

  • Files

  • SharePoint content

  • Calendars

  • Contacts

  • Other Microsoft 365 business data

It is limited to the basic user-profile information required to identify the authenticated user.

Is User.Read a delegated or application permission?

User.Read is a delegated Microsoft Graph permission. It is used in the context of the signed-in user.

It does not give Leapwork Go unrestricted access to the organisation’s directory or Microsoft 365 environment.

Does Leapwork Go require directory-wide access?

No. Leapwork Go does not currently require directory-wide Microsoft Graph access. The integration is limited to the identity information required to authenticate and identify the user.

Will Leapwork Go request additional Microsoft Graph permissions in the future?

Leapwork Go does not automatically receive additional Microsoft Graph permissions. If a future capability requires additional permissions, Leapwork will document the purpose and scope of the requested permissions.

Any required consent will remain subject to the customer’s normal Microsoft Entra ID review and approval process.

Can the customer review or revoke the Microsoft permission?

Yes. An Entra ID administrator can:

  • Review the Leapwork Go Enterprise Application

  • Inspect its permissions

  • Review consent status

  • Revoke consent

  • Remove application assignments

  • Remove the application

Revoking the required permission or removing the application may prevent users from signing in to Leapwork Go.

Google Workspace setup

What is required for Google Workspace SSO?

The customer’s Google Workspace administrator must:

  1. Create a new OAuth application in Google Workspace or the associated Google Cloud project.

  2. Open the secure onboarding URL provided by Leapwork.

  3. Provide the required information, including the Google Workspace domain, Client ID, and Client Secret.

  4. Save the SSO configuration.

  5. Complete any required user or group assignment.

  6. Validate the sign-in process with Leapwork.

How should the Google Client Secret be shared?

The Client Secret is confidential and should only be entered through the secure onboarding URL provided by Leapwork.

It should not be:

  • Sent by email

  • Shared through an unsecured messaging service

  • Included in publicly accessible documentation

Can Google Workspace policies be applied to Leapwork Go?

Yes. Authentication continues to be handled by Google Workspace. The organisation can apply its existing authentication, MFA, application-access, and account-management policies to users signing in to Leapwork Go.

Authentication and data security

Does Leapwork Go store user passwords?

No. Authentication is performed by Microsoft Entra ID or Google Workspace. Leapwork Go does not receive or store the user’s Microsoft Entra ID or Google Workspace password.

What identity information does Leapwork Go receive?

Leapwork Go receives the identity information required to authenticate and identify the user. Depending on the identity provider, this can include:

  • Name

  • Email address or User Principal Name

  • Unique user identifier

  • Tenant or organisational identifier

Leapwork Go does not receive the user’s identity-provider password.

Can Leapwork Go access Microsoft 365 emails, files, or other business data?

No. Using Microsoft Entra ID for SSO does not provide Leapwork Go with access to:

  • Emails

  • Files

  • SharePoint content

  • Calendars

  • Contacts

  • Mailboxes

  • Other Microsoft 365 business data

A separate integration and additional approved permissions would be required for any functionality that needed access to such data.

Does SSO support MFA and Conditional Access?

Yes. Authentication is handled by Microsoft Entra ID or Google Workspace rather than by Leapwork Go.

The customer can therefore apply its existing MFA, Conditional Access, and other identity-provider policies to Go sign-ins, subject to the capabilities and configuration of its identity provider.

What authentication protocols are used?

Leapwork Go uses standard identity federation protocols. The applicable protocol and configuration depend on the selected identity provider.

Leapwork provides the relevant protocol details, redirect information, and application settings during onboarding.

User and access management

How are users created in Leapwork Go?

Leapwork initially onboards an administrator from the customer’s organisation. The customer administrator can then add additional users from the same organisation through the Leapwork Go administration portal.

Users must also satisfy any application assignment and access requirements configured in Microsoft Entra ID or Google Workspace.

Does IT need to be involved every time a Go user is added?

Not necessarily. Once SSO has been configured, the Go administrator can add users through the Go administration portal.

However, if the organisation restricts the SSO application to selected users or groups, its normal IT or identity-management process may also need to assign the user to the application.

Can access be restricted to specific users or groups?

Yes. The customer can use its identity-provider configuration to restrict application access to approved users or groups. The user must also be authorised within Leapwork Go.

Successful authentication through SSO does not automatically grant the user unrestricted access to Go.

Who controls user access?

Access is controlled at two levels:

Customer organisation

  • Authentication

  • MFA

  • Conditional Access

  • Application assignments

  • Group membership

  • Account disabling

  • Identity-provider security policies

Leapwork Go

  • User permissions

  • Roles

  • Authorised activities within the platform

What happens when an employee leaves the organisation?

The customer can revoke authentication access by:

  • Disabling the user’s organisational account

  • Removing the user from an authorised group

  • Removing the application assignment

The user should also be removed or disabled within Leapwork Go according to the organisation’s user-management process.

What happens if the identity provider is unavailable?

Users may be unable to sign in while Microsoft Entra ID, Google Workspace, or the configured SSO service is unavailable.

Because SSO is currently the only authentication model, there is no separate Leapwork Go password-based fallback.

Benefits of SSO

What are the benefits of SSO compared with separate Go passwords?

SSO provides several enterprise security and administration benefits:

  • Users do not need another password.

  • Existing MFA and access policies can be applied.

  • Access can be managed centrally.

  • Employee onboarding and offboarding can follow existing organisational processes.

  • The customer retains visibility and control over authentication.

  • Leapwork Go does not need to store customer passwords.

The initial setup requires support from the customer’s IT or identity administrator, but once configured, users can access Go through their existing organisational accounts.