LSEG Authentication Service Transformation  /  Product Upgrade Workspace






Product upgrade - Important
changes to FXT/FXall login





 

Overview

As part of our efforts to continue to deliver high-quality and highly available services to our customers, we are upgrading the technology infrastructure you use to log into/authenticate yourself on the LSEG FX Trading (FXT) and LSEG FXall® graphical user interface (GUI), and all other LSEG/Refinitiv transaction products and supporting websites.

The new Customer Identity and Access Management (CIAM) system offers improves performance and resilience whilst bolstering security, allowing us to provide enhanced authentication options and improvements to password policies

This upgrade impacts users of FX Trading, FXall GUI and TPR.

This change was first communicated to customers in 2023 through PCN205973 and separate email correspondence. 

 

Action required

If you have not already migrated to the new CIAM system you are required to validate you have the necessary routing in place to facilitate access. To test, please use one of the links below. This tests if your login credentials are correctly reflected in the CIAM authentication platform and if your network can access the basic CIAM login domain. You will need to enter your FXall/FXT Production username and password to test.


Delivery Direct customers: https://logintest.ciam.refinitiv.biz 

If you are unable to successfully validate the network changes have been made, please review the below requirements and ensure they are applied to your network:

Refinitiv Managed Connections (formerly Delivery Direct) 

For Refinitiv Managed Connection (formerly Delivery Direct), FCN and CMC users, the following new Private Network IP addresse ranges must all be allowed and routed appropriately on your network infrastructure.

159.43.192.0/23 [AMERS]

159.43.200.0/23 [EMEA]

159.43.208.0/23 [APAC]

FQDN enablement

The new identity and authentication service is cloud-hosted and does not use static IP addresses. Customers who restrict access to external services will now need to manage this using the DNS names from the table below.

You need to permit the following list of Fully Qualified Domain Names (FQDNs) according to your network delivery method.

Note: You may have already allowed some of these domains as part of the rebranding changes made in 2021. Any existing whitelisted domains LSEG/Refinitiv has previously communicated should not be removed

FQDN list with wildcards

FQDN Delivery Protocol/Port Description New domain?
*.refinitiv.com
*.refinitiv.net
*.refinitiv.biz
Internet or Refinitiv Managed Connection HTTPS/443 Login Authentication Password Reset No
https://authenticator.pingone.com/ Internet HTTPS/443 Multi-Factor Ping Authenticator app Yes
https://idpxnyl3m.pingidentity.com/ Internet HTTPS/443 Multi-Factor Ping Authenticator app Yes
* Domains listed in the table are wildcard values, where a subdomain may prepend and/or append the listed domain

All FXT and FXall FQDNs
DNS Suffix Authoritative DNS FQDN Status
login.ciam.refinitiv.com Internet Introduced for CIAM
login.ciam.refinitiv.biz Private Introduced for CIAM
authenticator.pingone.com Internet Introduced for CIAM
idpxnyl3m.pingidentity.com Internet Introduced for CIAM
identity.ciam.refinitiv.net Internet / Private Introduced for CIAM
mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM
emea1.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM
apac1.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM
amers1.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM
amers2.mydetails.identity.ciam.refinitiv.net Internet / Private Introduced for CIAM
sso.platform.refinitiv.com Internet Introduced for CIAM
sso.platform.refinitiv.net Internet / Private Introduced for CIAM
amers-sso.platform.refinitiv.net Internet / Private Previously published, no longer required.
emea-sso.platform.refinitiv.net Internet / Private Previously published, no longer required.
apac-sso.platform.refinitiv.net Internet / Private Previously published, no longer required.
amers-passage.extranet.refinitiv.biz Private Introduced for CIAM
apac-passage.extranet.refinitiv.biz Private Introduced for CIAM
amers1.identity.ciam.refinitiv.net Internet / Private Current
amers2.identity.ciam.refinitiv.net Internet / Private Current
emea1.identity.ciam.refinitiv.net Internet / Private Current
apac1.identity.ciam.refinitiv.net Internet / Private Current
sts.identity.ciam.refinitiv.net Internet / Private Current
amers1.heartbeat.ciam.refinitiv.net Internet / Private Current
amers2.heartbeat.ciam.refinitiv.net Internet / Private Current
emea1.heartbeat.ciam.refinitiv.net Internet / Private Current
apac1.heartbeat.ciam.refinitiv.net Internet / Private Current
amers1.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM
amers2.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM
emea1.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM
apac1.heartbeat.ciam.refinitiv.com Internet Introduced for CIAM
amers1.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM
amers2.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM
emea1.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM
apac1.heartbeat.ciam.refinitiv.biz Private Introduced for CIAM
emea-passage.extranet.refinitiv.biz Private Introduced for CIAM
apac1-fxallweb.trading.refinitiv.com Internet Introduced for CIAM
emea1-fxallweb.trading.refinitiv.com Internet Introduced for CIAM
amers1-fxallweb.trading.refinitiv.com Internet Introduced for CIAM
amers2-fxallweb.trading.refinitiv.com Internet Introduced for CIAM
apac1-fxallweb.trading.refinitiv.biz Private Introduced for CIAM
amers1-fxallweb.trading.refinitiv.biz Private Introduced for CIAM
amers2-fxallweb.trading.refinitiv.biz Private Introduced for CIAM
emea1-fxallweb.trading.refinitiv.biz Private Introduced for CIAM
Further information is provided in the FAQs below. Your account manager will assist you with the timing of the migration of your users to mitigate any risk.

No GUI upgrade is required.

Please forward this webpage to your IT department for further review.

If you have any questions, please click the Contact Us button at the bottom of this page.
 

Frequently asked questions

What’s happening?

As part of our efforts to continue to deliver high-quality and highly available services to our customers, we are upgrading the technology infrastructure you use to log into/authenticate yourself on the FX Trading and FXall® graphical user interface (GUI) and supporting websites.

This upgrade won’t require any actions by users of FX Trading or FXall GUI who currently authenticate via the LSEG/Refinitiv AAA system (accessing the service via a corporate email address). FXall users who currently use the legacy SiteMinder system (accessing the system using an FXall ID) also need take no action at this time. SiteMinder users will be contacted later with further migration instructions.

The new identity and access management services improves performance and resilience whilst bolstering security, allowing us to provide enhanced authentication options and improvements to password policies.

The majority of customers who previously authenticated via the LSEG/Refinitiv AAA system migrated to our new CIAM system in H1 2025. Account Managers are now reaching out to customers to assist remaining customers with the migration.

Will my old password still work?

Your username will remain the same, so you’ll be able to login with your current credentials after the upgrade. When logging into FXT/FXall via the new authentication platform for the first time, you’ll will be asked to enter both your username and password. It’s important to make sure you remember your passwords or reset them in advance.

As part of the continuing password authentication policy, you’ll need to enter your password each time you sign into the product.

You’ll be able to change your password using the same options available today. These include:

  1. Forgotten password link on the login page
  2. By using Password Assistance

Will my web apps bookmarks still work?

The existing bookmarks/standard links for web apps currently remain available. These will be removed in Q4 2025. Customers will be asked to upgrade their bookmarks in Q4 when replacement links will be provided, after which the old links will be removed.

Current bookmarks:

ASIA: https://apac1-fxt.trading.refinitiv.com

EMEA: https://emea1-fxt.trading.refinitiv.com

AMERS: https://amers1-fxt.trading.refinitiv.com and https://amers2-fxt.trading.refinitiv.com

Will there be any change to Multi-Factor Authentication (MFA)

As part of the upgrade, customers that currently use Multi-Factor Authentication (MFA) will continue to be supported. Users that access the service via the Internet and have MFA enabled will receive a onetime passcode via an email, SMS text message. This can be configured for each user separately. Users that access the service via Refinitiv Managed Connection and have MFA enabled, will receive a onetime passcode via email only.

I am a Single Sign On (SSO) user. Will I be migrated?

Federated Single sign-on (SSO) customers won’t be affected by this migration. Federated SSO customers will remain on the current AAA system for the time being.

How will LSEG be upgrading the service?

The new CIAM system is already in place. The majority of customers who previously authenticated via the LSEG/Refinitiv AAA system migrated to our new CIAM system in H1 2025. Account Managers are now reaching out to the remaining AAA customers to assist remaining customers with the migration.

The requirement is for customers to validate that they have connectivity in place to access the new CIAM system and then arrange with their Account Managers for their users to be migrated.

Refer to the Action Required section if you have not successfully validated your network readiness.

What will the new login page look like?

There are minor changes to the new login screen.

1. New CIAM username/ password capture screen:
2. New CIAM MFA capture screen for Internet customers:
3. New CIAM MFA capture screen for Refinitiv Managed Connection customers:


What if I use trade performing reporting (TPR) and business objects?

If you access TPR and business objects via FXT and FXall GUI you may need to reauthenticate again. Please note that in due course all the services accessed from within the GUI will be moved to the new authentication platform and no additional authentication will be required. 

Who will support me with this change?

LSEG’s implementation management (for FXT changes) and sales success (for FXall changes) teams will support our customers in completing the required tasks to make sure you’re technically ready for the new CIAM platform.

What if I use other products like Deal tracker feed or Workspace?

Multiple LSEG/Refinitiv products will undergo the platform change independently and the fact that customers have moved to the new identity and access management platform with FXT or FXall won’t impact other products. The implementation management team will inform customers about any changes needed across all the products they consume. If they have not informed you, please be sure to ask.

I am using Eikon® administration services today. Will I continue to use it after the change?

Yes, you can continue to use EAS to administer your product. If there are any future changes to the administration service portal, we’ll inform you separately.

My users access web apps via the FXT and FXall GUI. Will they have to authenticate again?

If customers access web apps via FXT and FXall GUI, they may need to reauthenticate, please note that in due course all the services accessed from within the GUI will be moved to the new authentication platform and no additional authentication will be required.

What will happen if I don’t perform the changes in time?

If you don’t perform the necessary network changes, you’ll no longer be able to access the service after you have been migrated to the new CIAM system.

My users open the MyAccount and “Contact us” functions from within the GUI. Will they have to authenticate again to access these sites?

Yes, for a fixed timeframe customers may experience additional authentication requirement when accessing MyAccount or resetting passwords.

How will users’ experience change after the move to the new platform?

There are minor changes to the new login screen. Product functionality remains unchanged, these changes relate only to login/authentication process.

 

Ask a question

We aim to deliver a world-class customer onboarding experience for LSEG solutions by knowing our customers, engaging proactively, and ensuring swift and accurate delivery of our products and services. If you have questions, we are here to help.