Set Up SSO (Single Sign-On)
What is SSO?
SSO (Single Sign-On) allows users to log into the platform using their corporate Identity Provider. This enables them to use the same credentials they use to access their other professional tools, without having to create or manage an additional password for the platform.
This authentication method offers several benefits:
- Simplified login: A single account to access multiple applications.
- Enhanced security: Authentication is managed by your Identity Provider, which can enforce security policies (multi-factor authentication, password policies, etc.).
Prerequisites
Before enabling SSO, make sure you have the following:
- An Identity Provider compatible with the OpenID protocol used by the platform (for example: Microsoft Entra ID, Okta, Google Workspace, or any other compatible provider).
- The configuration details provided by your Identity Provider:
Issuer URL
Client ID
Client Secret - Administrator rights for your company on the platform to access the configuration settings.
How to Enable SSO?
Enabling SSO is restricted to the company's admin manager.
To configure this feature:
- Log in to your manager space.
- Click on the Company tab.
- Scroll down to the SSO section.
- Enable the feature by checking the SSO option.
- Enter the required information:
Issuer URL
Client ID
Client Secret

Tip: We recommend testing that the configuration is set up correctly by clicking the blue button at the bottom left of the screen to avoid any connection issues.

Remember to save your changes.
Once the configuration is saved, users will be able to authenticate via your Identity Provider using the SSO login URL.
Configuration URLs
Above the configuration fields, two URLs are displayed:
- SSO Login URL (to be provided to company learners and managers)
- Redirect URL (must be communicated to your Identity Provider when configuring your SSO application)
These two URLs are automatically generated and pre-filled.

Managing Departing Employees
Enabling SSO does not handle automatic account desynchronization (deprovisioning).
If an employee leaves your company, disabling them in your Identity Provider is not enough: you must also manually disable or delete their account on the lux-Airport Academy platform.
Related Articles
Create a company account
1) Click on Sign Up 2) Fill out the registration form and click "Continue". 3) Create your administrator account and click "Sign Up" 4) Your company account has been successfully created. To finalize your registration, our teams need to check your ...
What is the Two-factor authentication ?
Strengthening Your Account Security Two-factor authentication enhances the security of your account by preventing unauthorized access. Even if a malicious individual manages to obtain your password, they will not be able to log in without the second ...