LSEG Authentication Service Transformation  /  Product Upgrade Workspace






Product upgrade - Important
changes to FXT/FXall login





 

Overview

As part of our efforts to continue to deliver high-quality and highly available services to our customers, we’ll be upgrading the technology infrastructure you use to log into/authenticate yourself on the LSEG FX Trading (FXT) and LSEG FXall® graphical user interface (GUI), and all other LSEG/Refinitiv transaction products and supporting websites.

The new Customer Identity and Access Management (CIAM) system will improve performance and resilience while bolstering security, allowing us to provide enhanced authentication options and improvements to password policies. 

This upgrade impacts users of FX Trading, FXall GUI, Deal Tracker, TPR and any LSEG/Refinitiv product that currently authenticates via the LSEG/Refinitiv AAA system (accessing the service via a corporate email address).

The project has been split into two phases:

  • Phase 1 – Mandatory Client actions: Client’s test and, if required, update their local network to access the new services. No GUI upgrade is required for this project. This phase should have already been completed by customers per earlier communications. Customers that fail to complete the required network changes in advance of the migration will see service issues when LSEG switches to the new CIAM system.

  • Phase 2 – LSEG will switch clients and users from the current AAA (users that access the system via an email address) system to the new CIAM system. No further client action is expected as part of phase 2. Phase 2 is scheduled to commence in November continuing into Q1 2025. Users will be migrated in batches. Affected users will be emailed in advance notifying them of the exact date of their migration.

For the majority of users, end user credentials will not be changing. Note: a small number of end users may be required to reset their password ahead of the normal 90 day reset process.

FXall users who currently use the legacy SiteMinder system (accessing the system using an FXall ID) and customers that currently use federation Single Sign On (SSO) do not need to take action at this time. SiteMinder and SSO users will be contacted later with further migration instructions.

Please forward this communication to your IT department for further review.

If you have any questions, please see the contact information at the end of this document.

 

Frequently asked questions

What’s happening?

As part of our efforts to continue to deliver high-quality and highly available services to our customers, we’ll be upgrading the technology infrastructure you use to log into/authenticate yourself on the FX Trading and FXall® graphical user interface (GUI) and supporting websites.

This upgrade won’t require any actions by users of FX Trading or FXall GUI who currently authenticate via the LSEG/Refinitiv AAA system (accessing the service via a corporate email address). FXall users who currently use the legacy SiteMinder system (accessing the system using an FXall ID) also need take no action at this time. SiteMinder users will be contacted later with further migration instructions.

The new identity and access management services will improve performance and resilience while bolstering security, allowing us to provide enhanced authentication options and improvements to password policies.

The migration to the new CIAM system is scheduled to commence in November continuing into Q1 2025.

We recommend that you review the frequently asked questions below to ensure that you are familiar with any changes required for this upgrade.

Please forward this communication to your IT department for further review.

If you have any questions, please see the contact information at the end of this document.

Customers should have already ensured that they are technically ready for this upgrade.

Do I need to do anything?

FXT/FXall GUI USERS

Please follow the obsolescence policy to ensure that you are running a supported version of the GUI. Obsolescence policy FXT and FXall.

LOGIN USING USERNAME AND PASSWORD

Remember your username & password

Your username will remain the same, so you’ll be able to login with your current credentials after the upgrade. When logging into FXT/FXall via the new authentication platform for the first time, you’ll will be asked to enter both your username and password. It’s important to make sure you remember your passwords or reset them in advance.

As part of the continuing password authentication policy, you’ll need to enter your password each time you sign into the product.

Advice for customers accessing the internet and Refinitiv Managed Connection (Delivery Direct) networks

The new identity and authentication service is cloud-hosted and does not use static IP addresses. Customers who restrict access to external services will now need to manage this using the DNS names from the table below.

Delivery Direct has been renamed to Refinitiv Managed Connection.

Internet & Refinitiv Managed Connection (Delivery Direct)

You need to permit the following list of Fully Qualified Domain Names (FQDNs) according to your network delivery method.

Note: You may have already allowed some of these domains as part of the rebranding changes made in 2021. Any existing whitelisted domains LSEG/Refinitiv has previously communicated should not be removed.

FQDN Delivery Protocol/Port Description New domain?
*.refinitiv.com
*.refinitiv.net
*.refinitiv.biz
Internet or Refinitiv Managed Connection HTTPS/443 Login Authentication Password Reset No
https://authenticator.pingone.com/ Internet HTTPS/443 Multi-Factor Ping Authenticator app Yes
https://idpxnyl3m.pingidentity.com/ Internet HTTPS/443 Multi-Factor Ping Authenticator app Yes

* Domains listed in the table are wildcard values, where a subdomain may prepend and/or append the listed domain

Refinitiv Managed Connection (Delivery Direct)

To access new AWS service endpoints, customers using a private network must whitelist the following new IP addresses, which will impact Refinitiv Managed Connection, FCN and CMC users.

  • 159.43.192.0/23 [AMERS]
  • 159.43.200.0/23 [EMEA]
  • 159.43.208.0/23 [APAC]

All FXT and FXall FQDNs

DNS Suffix Authoritative DNS FQDN Status PING Migration Test tool line number
login.ciam.refinitiv.com Internet Introduced for CIAM 1
login.ciam.refinitiv.biz Private Introduced for CIAM 2
authenticator.pingone.com Internet Introduced for CIAM 3
idpxnyl3m.pingidentity.com Internet Introduced for CIAM 4
identity.ciam.refinitiv.net Internet / Private Introduced for CIAM 5
mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM 6
emea1.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM 7
apac1.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM 8
amers1.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM 9
amers2.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM 10
sso.platform.refinitiv.com Internet Introduced for CIAM 11
sso.platform.refinitiv.net Internet / Private Introduced for CIAM 12
amers-sso.platform.refinitiv.net Internet / Private Previously published, no longer required. 13
emea-sso.platform.refinitiv.net Internet / Private Previously published, no longer required. 14
apac-sso.platform.refinitiv.net Internet / Private Previously published, no longer required. 15
amers-passage.extranet.refinitiv.biz Private Introduced for CIAM 16
apac-passage.extranet.refinitiv.biz Private Introduced for CIAM 17
amers1.identity.ciam.refinitiv.net Internet / Private Current 18
amers2.identity.ciam.refinitiv.net Internet / Private Current 19
emea1.identity.ciam.refinitiv.net Internet / Private Current 20
apac1.identity.ciam.refinitiv.net Internet / Private Current 21
sts.identity.ciam.refinitiv.net Internet / Private Current 22
amers1.heartbeat.ciam.refinitiv.net Internet / Private Current 23
amers2.heartbeat.ciam.refinitiv.net Internet / Private Current 24
emea1.heartbeat.ciam.refinitiv.net Internet / Private Current 25
apac1.heartbeat.ciam.refinitiv.net Internet / Private Current 26
amers1.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM 27
amers2.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM 28
emea1.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM 29
apac1.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM 30
amers1.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM 31
amers2.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM 32
emea1.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM 33
apac1.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM 34
emea-passage.extranet.refinitiv.biz Private Introduced for CIAM 35
apac1-fxallweb.trading.refinitiv.com Internet Introduced for CIAM and not live (for future use) N/A
emea1-fxallweb.trading.refinitiv.com Internet Introduced for CIAM and not live (for future use) N/A
amers1-fxallweb.trading.refinitiv.com Internet Introduced for CIAM and not live (for future use) N/A
amers2-fxallweb.trading.refinitiv.com Internet Introduced for CIAM and not live (for future use) N/A
apac1-fxallweb.trading.refinitiv.biz Private Introduced for CIAM and not live (for future use) N/A
amers1-fxallweb.trading.refinitiv.biz Private Introduced for CIAM and not live (for future use) N/A
amers2-fxallweb.trading.refinitiv.biz Private Introduced for CIAM and not live (for future use) N/A
amea1-fxallweb.trading.refinitiv.biz Private Introduced for CIAM and not live (for future use) N/A
 

BOOKMARKS

The bookmarks/standard links for webservices remain the same. If these are going to change we’ll update you when the time comes.

ASIA: https://apac1-fxt.trading.refinitiv.com

EMEA: https://emea1-fxt.trading.refinitiv.com

AMERS: https://amers1-fxt.trading.refinitiv.com and https://amers2-fxt.trading.refinitiv.com

PASSWORD POLICY RULES

We’ll communicate the new password policy in January 2023. If you need to change your password after the upgrade, you’ll be given instructions on how to update it and any special password requirements. Your existing passwords are compliant with the new password policy and can be kept as they are.

You’ll be able to change your password using the same options available today. These include:

  1. Forgotten password link on the login page
  2. By using Password Assistance

MULTIFACTOR AUTHENTICATION (MFA)

As part of the upgrade, customers that currently use Multi-Factor Authentication (MFA) will continue to be supported. Users that access the service via the Internet and have MFA enabled will receive a onetime passcode via an email, SMS text message. In the future and as an enhancement we will be introducing a Push notification Ping app. This can be configured for each user separately. Users that access the service via Refinitiv Managed Connection and have MFA enabled, will receive a onetime passcode via email only.

SINGLE SIGN ON (SSO)

Federated Single sign-on (SSO) customers won’t be affected by this migration. Federated SSO customers will remain on the current AAA system for the time being.

How will LSEG be upgrading the service?

On the assumption customers have made all the required changes listed above, the upgrade to the new service should be completely transparent and should not impact your access to FXT and FXall.

The migration is scheduled to commence in November continuing into Q1 2025. Users will be migrated in batches. Affected users will be emailed in advance notifying them of the exact date of their migration.

Customers should already be technically ready for additional network flows per earlier communications.

When can I test the new service?

You will have a variety of testing options available:

Testing technical readiness:

Network system test for Windows: click here

Network system test for Mac click here

Ping to HTML test here

Validation tool (refinitiv.com) enter you valid Workspace login credentials. This simple test checks if your login credentials are correctly reflected in the CIAM authentication platform and if your network can access the basic CIAM login domain. PLEASE NOTE TO USE IT FOR INTERNET ONLY CONNECTION

What will the new login page look like?

There are minor changes to the new login screen.

1. New CIAM username/ password capture screen:
2. New CIAM MFA capture screen for Internet customers:
3. New CIAM MFA capture screen for Refinitiv Managed Connection customers:


What if I use trade performing reporting (TPR) and business objects?

If you access TPR and business objects via FXT and FXall GUI you may need to reauthenticate again. Please note that in due course all the services accessed from within the GUI will be moved to the new authentication platform and no additional authentication will be required. 

Who will support me with this change?

LSEG’s implementation management (for FXT changes) and sales success (for FXall changes) teams will support our customers in completing the required tasks to make sure you’re technically ready for the new CIAM platform.

What if I use other products like Deal tracker feed or Workspace?

Multiple LSEG/Refinitiv products will undergo the platform change independently and the fact that customers have moved to the new identity and access management platform with FXT or FXall won’t impact other products. The implementation management team will inform customers about any changes needed across all the products they consume. If they have not informed you, please be sure to ask.

I am using Eikon® administration services today. Will I continue to use it after the change?

Yes, you can continue to use EAS to administer your product. If there are any future changes to the administration service portal, we’ll inform you separately.

My users access web services via the FXT and FXall GUI. Will they have to authenticate again?

If customers access Web services via FXT and FXall GUI, they may need to reauthenticate, please note that in due course all the services accessed from within the GUI will be moved to the new authentication platform and no additional authentication will be required.

What will happen if I don’t perform the changes in time?

If you don’t perform the necessary network changes, you’ll no longer be able to access the service after you have been migrated to the new CIAM system.

My users open the MyAccount and “Contact us” functions from within the GUI. Will they have to authenticate again to access these sites?

Yes, for a fixed timeframe customers may experience additional authentication requirement when accessing MyAccount or resetting passwords.

How will users’ experience change after the move to the new platform?

There are minor changes to the new login screen. Product functionality remains unchanged, these changes relate only to login/authentication process.

I use Eikon and FXT. Will I retain the same password?

Yes.

Where can I get more help?

Click here to contact our customer service team for further assistance.


The following table summarises various FXall use cases and the changes required:

Use cases Use case definition Network changes Mandatory software upgrade Optional changes to single sign on Obsolescence policy compliance software upgrade
FXall GUI Desktop users accessing FXall via an installed GUI Yes No Yes Yes
FXall Web Services (Web apps) Admin, Settlement Center, BA reports, TPR, FX IOptions Settlements and Trade Blotter Web users launching FXall via a browser Yes No Yes Yes
FXall Web Services (Web Apps) via FXall GUI Desktop users launching the web service via a build in browser in the GUI Yes No Yes Yes
FXall SSO Customers accessing FXall via the single sign on service Yes Yes N/A Yes

The following table summarises all the changes required for FXT clients:

Use cases Use case definition Network changes Mandatory software upgrade Optional changes to single sign on Obsolescence policy compliance software upgrade
FXT GUI Dealing Desktop users accessing FXT via an installed GUI – dealing only. Yes No Yes Yes
FXT GUI Matching Desktop users accessing FXT via installed GUI with matching enabled Yes No Yes Mandatory for matching users
Treasury Centre via FXT GUI Desktop users launching both GUIs – FXT and Treasury Centre – in parallel Yes No TBC Yes
Electronic Trading via FXT GUI Desktop users launching FXT and accessing Electronic Trading via the GUI Yes No TBC Yes
 
Additional resources
 

Ask a question

We aim to deliver a world-class customer onboarding experience for LSEG solutions by knowing our customers, engaging proactively, and ensuring swift and accurate delivery of our products and services. If you have questions, we are here to help.