[dynamic_help_sidebar root="leads"]

ADFS Integration for Signing in to LeadSquared

1. Feature Overview

LeadSquared offers sign-in integration with a self-hosted Active Directory Federation Services (ADFS) server.

ADFS is a Microsoft service that allows you to log-in to web applications using your Active Directory (AD) credentials. After integration, you won’t need to manage a separate set of credentials for LeadSquared, and can log-in directly with your AD credentials.

To integrate, you must complete the following steps –

  1. Add a Relying Party Trust to your ADFS server
  2. Obtain the Certificate Thumbprint
  3. Configure LeadSquared Authentication Provider settings

To integrate Azure AD with LeadSquared, see Integrating Azure AD with LeadSquared using ROPC Approach.

Note: When you enable ADFS integration, it is applied by default to all the users in your account. It CANNOT be disabled for specific users.

 

2. Prerequisites

  • You must be a LeadSquared administrator user.
  • You must set up an Active Directory instance, where all users have an email address attribute and the email address is the same as their LeadSquared account.
  • ADFS service must be installed and configured.
  • A Global SSL certificate and the thumbprint for that certificate.
Note: This article does not explain the process of installing and configuring ADFS. For installation details, please refer to Active Directory Federation Services.

 

3. Adding a Relying Party Trust

1. Open the ADFS Management console (Server Mangager>Tools>ADFS Management).
open adfs console

2. Under the Actions pane, click Add Relying Party Trust.
add relying party trust

3. You’ll now see the welcome page of the Add Relying Party Trust Wizard. Click Start.
add trust wizard

4. Now click Enter data about relying party manually radio button, then click Next.
adfs configs

5. Enter a display name of your choice, then click Next.
adding display name

6. Select AD FS profile and click Next.
adfs profile

7. Leave the certificate settings here as their defaults and just click Next.
default certificate settings

8. No action is required here, click Next.
config url settings

9. Add a Relying party trust identifier depending on the region your account was created –

  • https://run.leadsquared.com for accounts created in the Singapore region.
  • https://us11.leadsquared.com for accounts created in the US region.
  • https://in21.leadsquared.com for accounts created in the India (Mumbai) region.
  • https://in22.leadsquared.com for accounts created in the India (Hyderabad) region.
  • https://ir31.leadsquared.com for accounts created in the Ireland region.
  • https://ca12.leadsquared.com for accounts created in the Canada region.

Click Next.

ADFS Integration add URL

10. Select the I do not want to configure multifactor… checkbox, then click Next.
multifactor adfs settings

11. Keep the default setting (Permit all users to access…) and click Next.
ADFS auth rules

12. The configurations are now complete. Click Next to continue.
adfs trust config summary

13. The relying party trust has now been added. Click Close to proceed to the Edit Claim Rules dialog.
add claim rules

14. Click the Add Rule button.
add new claim rules to ADFS

15. Click Next to create a Send LDAP Attributes as Claims rule.
claim rules

16. Enter a name for the claim rule, select the Attribute store as Active Directory (this is where the LDAP attributes will be extracted from), then map the LDAP attributes to the outgoing claim type as shown below. Click Finish when you’re done.
configuring adfs claim rules

17. Now click OK.
continue with claim rules

18. Now navigate to ADFS Management>Relying Party Trusts, You can see all relying party trusts here. If required, you can edit claims by clicking Edit claim rules. You may also change identifiers by clicking Properties.
edit existing relying party trust

19. Navigate to ADFS>Service>Endpoints, and ensure that the following endpoint is enabled /adfs/services/trust/13/usernamemixed
enable adfs endpoints

 

4. ADFS Certificate Thumbprint

1. Navigate to ADFS>Service>Certificates.
adfs certificate

2. Right-click the certificate under Token-signing, then click View Certificate.
adfs cert

3. On the Certificate pop-up, navigate to the Details tab, then copy the Thumbprint value of the certificate. You will need to paste this value in the LeadSquared Authentication Provider wizard as instructed below.
certificate thumbprint value

 

5. LeadSquared Authentication Provider Settings

This section assumes that you’ve completed the steps described above on the ADFS server side. Now log-in to the LeadSquared application and follow these steps –

  1. Navigate to My Profile>Settings>Security>Authentication Provider.
  2. Click the slider enable authentication to Enable Third Party Authentication Provider.
  3. On the Choose Authentication Provider window, click Active Directory.
  4. Alongside ADFS URL, enter your server URL. Be sure to choose the correct protocol  – as either http:// or https://
  5. Now paste the value of the Certificate Thumbprint (see Step 3 under the ADFS Certificate Thumbprint section above).
  6. Click Test.
  7. Now enter your Active Directory password and click Next.
  8. Once the password is verified, you’ll receive a success message. Click Enable, then click Yes on the Enable Authentication Provider pop-up.

Your LeadSquared account has now been integrated with your Active Directory.

ADFS as Auth Provider

Note:

  • The next time you log in to your LeadSquared account, you must enter your AD credentials*.
  • To disable the integration, just click the slider enable authentication alongside Enable Third Party Authentication Provider on the Authentication Provider Settings page.

*The email address of your LeadSquared users may be different from the AD user. For example, you may have your employee Id as the AD login.  If this is the case, you can create a custom user field to store these login Ids.
When a LeadSquared user logs in with the regular email address, we’ll internally pick the value from the custom field and send it to your AD for authentication. Please reach out to support@leadsquared.com to enable this feature.

 

6. FAQs

1. Why are users unable to log in to the LeadSquared application when ADFS is configured?

  • Issue Description: Users are facing an error while trying to log in to the LeadSquared application, even when entering the correct credentials.
  • Root Cause: This error typically occurs when the client side’s Active Directory (AD) is failing. The login authentication is handled by ADFS (Active Directory Federation Services), not by LeadSquared.
  • Solution: Please reach out to your internal IT team, as the issue is related to your ADFS configuration.

2. Can we disable ADFS for specific users?

  • Issue Description: Can ADFS can be disabled for specific users.
  • Solution: If ADFS is enabled, it is applied to all users by default. It cannot be disabled for specific users because it is enabled at the account  level.

 

Any Questions?

Did you find the content here helpful? Leave a comment below and we’ll be happy to address your doubts.

LeadSquared Security Settings – Two-factor Authentication 2FA

1. Feature Overview

Two-factor authentication (also known as 2FA or Multi-factor authentication) lets you add an additional layer of security to your account. With 2FA, you’ll need to provide another form of authentication in addition to your username and password to access your account. It’s a great way to protect yourself against brute force attacks and hacks even when your password has been compromised.

Note:

  • This article explains how admins and users can enable 2FA for their own accounts. However, if you’re an admin and want to enforce 2FA for specific users or across your entire organization, you can do so using the Authentication Profiles feature. Alternatively, you can contact support@leadsquared.com.
  • With the Trusted Devices feature, users can log into their LeadSquared account without verifying themselves through Two-Factor Authentication (2FA) each time.

 

2. Prerequisites

  • To enable 2FA using mobile, you must ensure that the correct mobile number is saved under your user details. To edit an existing mobile number or add a new one please contact your LeadSquared administrator.
  • Likewise, 2FA can also be enabled through email. To change the email address of your LeadSquared account, contact your administrator.

 

3. How It Works

With 2FA, you’ll be required to enter –

  1. Your username and password
  2. An OTP sent to your mobile device, email, or generated through an app such as Google Authenticator*

*Other Time-based OTP (TOTP) authenticator apps on Android/iOS devices such as Microsoft Authenticator, Duo, Authy, etc. are also supported.

Note: 2FA is enabled by default for Admins, Sales Managers, and Marketing Users. For Sales Users, it can be enabled by each individual or at the account level by the admin user.

 

4. Setting Up Two Factor Authentication

Two-Factor Authentication is mandated by default for Admins, Marketing users, and Sales Managers. These users will be prompted to set up their preferred method of authentication while logging in to their accounts.

2fa login

If you choose the Google Authenticator option, you’ll see a QR code and a key. Use these to configure your LeadSquared account in the app you’re using (Google Authenticator, Microsoft Authenticator, Authy, etc.). Then enter the current OTP in the space provided and click Enable.

google auth config

Note: To remove the mandatory 2FA for your account, please get in touch with your account manager or contact support@leadsquared.com

For more details, see LeadSquared Security Settings – Login Settings.

4.1 Sales User Level

Alternatively, Sales Users can set up two-factor authentication for their own accounts –

  1. From the main menu, navigate to My Profile>Settings>Security>Two Factor Authentication.
  2. Click the slider enable authenticationto enable two-factor authentication*.
  3. Select either the SMS, Email, or Google Authenticator option.
  4. Enter the OTP received on your mobile or email, then click Enable.

Multi-factor Auth

* You can disable two-factor authentication at any time.

If you want to change the configuration from to SMS, Email or Google Authenticator at any time, click the Change link –

change 2fa config

 

5. Logging In With 2FA

After setting up 2FA, you’ll be prompted to enter your OTP the next time you log in –

OTP on login

If you don’t receive an OTP, you can re-send it after the 5-minute count-down elapses.

 

6. Reports

You can access the Two-Factor Authentication report on the UI. It gives you details of users with 2FA enabled versus those with 2FA disabled. You can also see the provider (SMS, Email) used and the list of users with details such as phone numbers and email addresses.

Note: The report can be accessed by Admins, Marketing Users and Sales Managers.

To view the report,

1. On the main menu, navigate to Reports>Reports Home.

reports home

2. Type ‘Two Factor Authentication‘ into the search bar and then select the report from the auto-suggestions –

2fa report search

3. Hover your cursor over each chart or navigate between the tabs for more details.

2fa UI report

 

7. FAQs

1. I entered the OTP incorrectly 3 times and am now locked out of my account. What do I do?
LeadSquared automatically locks you out of your account after 3 invalid attempts. However, you can retry after 30 mins.

2. I’m locked out of my account and can’t get a new OTP. What should I do?
This may happen if you’ve lost your phone or can’t access your email. Don’t worry though, just contact us at support@leadsquared.com.

3. What else can I do to strengthen my account security?
There are many ways to improve the security of your account. Here are a few basic tips –

  • Change your passwords frequently.
  • Don’t re-use passwords.
  • Don’t share your account’s password with anyone.
  • Don’t click the links on suspicious or unexpected emails.
  • Be careful of what you download from the internet.
  • Beware of phishing attempts.

4. Is 2FA enabled by default for all users?

2 Factor Authentication is enabled by default for Admins, Sales Managers, and Marketing Users. It is not enabled by default for Sales Users.

5. How can Admins and Managers disable or turn off 2FA?

You will need to contact support@leadsquared.com.

6. How can Admins enable 2FA for specific users or at the org level? 

To enable 2FA for specific users or at the org level, you can use the Authentication Profiles feature. Or, you can send a request to support@leadsquared.com.

7. Can 2FA be modified by the admin after it is set by the sales user?

The specific 2FA configuration cannot be modified by the admin, but the admin can disable 2FA for each user in the Manage Users page.

 

 

8. Troubleshooting

1. I enabled Two factor authentication (2FA), but it isn’t working for a mobile user in my organization.

Ensure you add the user’s correct mobile number in the user profile. Once added, 2FA should work as expected. If you still face issues, contact support@leadsquared.com.

 

Any Questions?

Did this article answer your question? If not, leave a comment below and we’ll get back to you ASAP.

Forms and Processes on Mobile

1. Feature Overview

Forms and Processes are now available on LeadSquared mobile.
You can set up customized forms and processes on web (loan applications, education applications, KYC collection), and then push them to your mobile users. This makes it extremely easy for your on-field teams to capture the exact information required from your leads.

 

2. Prerequisites

  • You have to be an administrator user to create forms and processes.
  • You must be running the LeadSquared Android app v8.0 or higher, or the LeadSquared iOS app v7.1 or higher.

 

3. How It Works

Firstly, you need to create one or more forms. The procedure is exactly the same as it is for web.
The only difference lies in the process designer, when you choose where you want the process to be triggered.

 

4. Procedure

Once you’ve created your forms, navigate to the Process Designer (Workflow>Process Designer) and click Create Process.

create new process

You can trigger your process  –

  • At a Specific Work Area
    Or
  • On Task Complete

 

4.1 On Task Complete

The ‘On Task Complete’ trigger allows you to choose the task types on which you want the process to be triggered.

task complete trigger

Every time a task of a selected task type is completed from the mobile app, the process will be triggered.
In the example below, the process is triggered to run when Follow-up, Meeting, and Phone Call tasks are marked complete. The form configured to be displayed is the ‘New Client’ form.

sample process

So when users complete a task (of the configured type) from the mobile app, they’ll be prompted to complete the form(s) configured in the process.

trigger process on task complete form select mobile

The task will then be marked complete –

process on mobile task completed after process

 

4.2 At a Specific Work Area

When you choose the ‘At a Specific Work Area’ trigger, you’re prompted to select the work areas where you want the process to begin.

Each work area has an icon representing its availability on web and mobile.

  • Available on Web web icon
  • Available on Mobile mobile icon
  • Not available on mobile not avilable on mobile

Use the checkboxes alongside the icons to choose the work areas on web and/or mobile, then click Save.

Note: When you hover your cursor over the icons, you’ll see an image of the screen/page where you’re process will be triggered from.

trigger processes on mobile

According to your configurations in the process designer, your form(s) will be available in the chosen work areas on mobile –

process work area on mobile process forms

Note: The Default Lead Form in the screenshot above is the default ‘Add New Lead’ form. It can be accessed offline. Forms added through the process designer will not be available offline.

 

5. Other Features

There are other features you can use in conjunction with forms and processes for a better experience.

Custom Field Sets
You can use custom field sets to upload documents to a form. To do this you need to create a custom field set and then add it to an activity. You must then include the activity in your form. For more information, see Custom Field Sets.

document upload through custom field sets

Activity Location
For activities that are location-enabled, the lead’s location will be automatically captured on form submission. For more information, see How to Add a Custom Activity.

activity location in custom forms

Iframes
You can use Iframes to display custom content on your forms. These are available as special fields in your form designer. For more information, see How to Create a Form.

add Iframe

 

6. Current Limitations

  • Activity attachments are currently not supported. However, you may use custom field sets to upload documents.
  • Help texts will be visible only for fields and not for form and section descriptions.
  • Only the ‘Default form’ will work offline.
  • If you’ve set up a process on the ‘Task Complete’ trigger, it will overwrite the ‘Task-Activity Completion’ flow. For more details, read the ‘Task-Activity Completion’ section of Mobile App Permissions.
  • Be sure to keep the Tab/Section/Field hidden by default from the web (while creating a form), if you don’t want them to appear for users on the first launch on mobile –

hide fields in form designer

For more information on hiding fields, tabs, and sections, see How to Create a Form.

 

Any Questions?

Did you find this article helpful? Leave a comment below if you have any unanswered questions.