Getting Started

This page explains the overview, benefits, and important notes of the Active Directory integration feature.
We recommend reading this page whether you are considering the integration or are about to proceed with setup.

If you have any questions or concerns, please feel free to contact us.

Table of Contents:

1. Overview of the Active Directory Integration Feature

2. Benefits

3. Key Features

4. About the AD Environment Required to Use AD Integration

5. Notes on Verifying AD Integration

1. Overview of the Active Directory Integration Feature

Feature Overview

1) Account Sync Feature

This feature uses the user information in your organization's Active Directory (hereafter, AD) to easily manage TrustLogin users, including creation, updates, deactivation, and control over TrustLogin group membership.

2) Authentication via AD Password

This authentication feature, provided through our proprietary connector, lets users log in to TrustLogin using their AD email address and password.

img_function02.svg

When a new user is registered in or deactivated from AD, this information is automatically synced
to TrustLogin, significantly reducing the effort required for TrustLogin operations and ID management.

2. Benefits

Benefits for Administrators

By syncing user information registered in Active Directory, you can centralize TrustLogin
user management (adding, updating, deactivating, and controlling group membership), reducing administrative overhead.

Benefits for Users

Users only need to remember their Active Directory password to log in to TrustLogin
and single sign-on to the various connected applications beyond it, improving both convenience and security.

3. Key Features

The AD integration feature is designed and implemented with the goal of providing the easiest
possible deployment and operation for our customers. The key features of TrustLogin's AD integration are as follows.

  • No external connections are made into your network environment
  • The AD connector uses outbound communication only; no inbound communication is required
  • Only read operations are performed against AD; no write operations are ever performed. Administrator privileges are not required
  • AD passwords are never stored in TrustLogin. Since an authentication request is sent to AD
    every time a user logs in, authentication is always performed against the current AD password

  • No specialized knowledge is required for deployment (an AD administrator can typically deploy it within a few hours)

4. About the AD Environment Required to Use AD Integration

The AD integration feature syncs to TrustLogin based on the user information in your AD environment.Setup and use of the AD integration feature will go more smoothly
if the source user information meets the following conditions.

  • First name, last name, and email address are set for the users to be synced (required)
  • A unique email address is set for the users to be synced(required)
  • Sync targets can be selected by security group
  • The connector has a stable connection to AD
    (no issues with DNS name resolution or firewall settings, and network communication is stable)

Note: Sync conditions can currently be configured by security group, but a feature to sync by OU is also planned for release.

In addition, TrustLogin supports integration with multiple domains.
However, please note the following.

  1. The AD connector must be able to run LDAP queries against all target domain controllers.
    If a firewall blocks communication from the AD connector, or if DNS cannot
    resolve the domain or domain controller names, the sync will fail.
  2. When integrating with multiple domains, the sync will not succeed unless integration
    results are returned successfully from all domains. If even one domain fails to return
    an integration result, the entire sync will fail.

5. Notes on Verifying AD Integration

If members are allowed to use TrustLogin password authentication, a TrustLogin password
registration email will be sent to each member's email address at the same time as the sync.

If you are still in the process of setting up sync and have not yet disclosed TrustLogin information to members,
or if you do not want members to log in using anything other than their AD password, change the setting
"Automatically assign password authentication when a member is registered" under "Settings > Password Authentication"
from the default On to Off
before syncing.

2-2.png

Getting Started

This page explains the overview, benefits, and important notes of the Active Directory integration feature.
We recommend reading this page whether you are considering the integration or are about to proceed with setup.

If you have any questions or concerns, please feel free to contact us.

Table of Contents:

1. Overview of the Active Directory Integration Feature

2. Benefits

3. Key Features

4. About the AD Environment Required to Use AD Integration

5. Notes on Verifying AD Integration

1. Overview of the Active Directory Integration Feature

Feature Overview

1) Account Sync Feature

This feature uses the user information in your organization's Active Directory (hereafter, AD) to easily manage TrustLogin users, including creation, updates, deactivation, and control over TrustLogin group membership.

2) Authentication via AD Password

This authentication feature, provided through our proprietary connector, lets users log in to TrustLogin using their AD email address and password.

img_function02.svg

When a new user is registered in or deactivated from AD, this information is automatically synced
to TrustLogin, significantly reducing the effort required for TrustLogin operations and ID management.

2. Benefits

Benefits for Administrators

By syncing user information registered in Active Directory, you can centralize TrustLogin
user management (adding, updating, deactivating, and controlling group membership), reducing administrative overhead.

Benefits for Users

Users only need to remember their Active Directory password to log in to TrustLogin
and single sign-on to the various connected applications beyond it, improving both convenience and security.

3. Key Features

The AD integration feature is designed and implemented with the goal of providing the easiest
possible deployment and operation for our customers. The key features of TrustLogin's AD integration are as follows.

  • No external connections are made into your network environment
  • The AD connector uses outbound communication only; no inbound communication is required
  • Only read operations are performed against AD; no write operations are ever performed. Administrator privileges are not required
  • AD passwords are never stored in TrustLogin. Since an authentication request is sent to AD
    every time a user logs in, authentication is always performed against the current AD password

  • No specialized knowledge is required for deployment (an AD administrator can typically deploy it within a few hours)

4. About the AD Environment Required to Use AD Integration

The AD integration feature syncs to TrustLogin based on the user information in your AD environment.Setup and use of the AD integration feature will go more smoothly
if the source user information meets the following conditions.

  • First name, last name, and email address are set for the users to be synced (required)
  • A unique email address is set for the users to be synced(required)
  • Sync targets can be selected by security group
  • The connector has a stable connection to AD
    (no issues with DNS name resolution or firewall settings, and network communication is stable)

Note: Sync conditions can currently be configured by security group, but a feature to sync by OU is also planned for release.

In addition, TrustLogin supports integration with multiple domains.
However, please note the following.

  1. The AD connector must be able to run LDAP queries against all target domain controllers.
    If a firewall blocks communication from the AD connector, or if DNS cannot
    resolve the domain or domain controller names, the sync will fail.
  2. When integrating with multiple domains, the sync will not succeed unless integration
    results are returned successfully from all domains. If even one domain fails to return
    an integration result, the entire sync will fail.

5. Notes on Verifying AD Integration

If members are allowed to use TrustLogin password authentication, a TrustLogin password
registration email will be sent to each member's email address at the same time as the sync.

If you are still in the process of setting up sync and have not yet disclosed TrustLogin information to members,
or if you do not want members to log in using anything other than their AD password, change the setting
"Automatically assign password authentication when a member is registered" under "Settings > Password Authentication"
from the default On to Off
before syncing.

2-2.png