Last date modified: 2026-Sep-04

Authentication

RelativityOne uses several industry-standard technologies, enabling versatile authentication options. It supports local (such as password related) or external (such as external identification providers) authentication methods. You can add and enable each type individually, as well as assigning at least one, and in some instances multiple methods, for each user.

Choosing your authentication setup

RelativityOne is moving to Centralized Authentication. Centralized Authentication is a unified system for managing user authentication and identities. Both setups are available during the transition, and the steps you follow depend on which one your instance uses.

  • Centralized Authentication—after onboarding, the Centralized Authentication tab appears in your instance. Users can then log in with it. For setup steps, see Centralized Authentication.
  • Legacy authentication—you create providers from the Authentication Provider tab using the New Authentication Provider button. This topic and the provider topics it links to cover that setup.
Both setups are supported until all instances complete the transition to Centralized Authentication. Customers who transitioned before the release should use the Community article for their onboarding wave. For more information, see Centralized Authentication.

Permissions

Manage permissions for this feature on the Features tab. Grant the full feature for a group, or customize access with individual actions. For an overview of features and actions, see Feature permissions.

Feature permissions actions for Authentication

Authentication overview

Review the following sections to learn more about the authentication methods, the object model, and the permissions model supported by Relativity:

Configuring legacy authentication

These steps apply to instances that use legacy authentication. System admins must assign each user at least one authentication method before that user can log in.

In Centralized Authentication, you set up password and SSO providers through the Authentication Provider tab. To assign users to these providers, use the Centralized Authentication page. For detailed steps on completing these actions, refer to the Centralized Authentication documentation.

Enabling RelativityOne Connect

Enable RelativityOne Connect to connect two or more of your Relativity instances. Use a single identity to securely connect multiple instances and let users navigate between them securely with cross-authentication using a single sign-on provider (SSO). For more information, see RelativityOne Connect.

Authentication provider settings

Authentication providers may have settings that you configure. These settings apply to all instances of that authentication provider.

Every provider instance has at least one setting, Enabled. When Enabled is set to Yes, the authentication provider is available. Both this setting and Enabled on the Authentication Provider must be set to Yes for a user to log in with that method. If either one is set to No, the method is not available.

Authentication providers that require additional settings:

  • Default Password provider
  • OpenID Connect with Microsoft Azure AD - see OpenID Connect (legacy) authentication provider flows.
  • SAML 2.0 provider - see SAML 2.0 provider (legacy).
Feedback