This page explains user management, one of the main features of Active Directory integration.
Whether you are considering this feature or are about to begin configuration, we encourage you to read this article.
If you have any questions or concerns, please feel free to contact us.
|
Contents: 2. About the Source of User Information |
1. Managing TrustLogin Users
Automatic Registration and Automatic Suspension
When an Active Directory (hereafter "AD") user meets the sync conditions,
they are automatically registered in TrustLogin.
Sync conditions can be flexibly configured, allowing for staged user registration.
For details, please refer to User Sync Condition Settings.
- When an AD user who previously met the sync conditions no longer meets them,
or is disabled in AD, the TrustLogin usage status of the corresponding user in TrustLogin
automatically changes to "Suspended," immediately preventing further use of TrustLogin. - If a user object is physically deleted in AD without first being disabled, this action cannot be
detected, and the user's status in TrustLogin will not change to "Suspended."
Therefore, to set a user's status to "Suspended" in TrustLogin,
you must first disable the user in AD. - If a member with AD integration becomes excluded from synchronization, the user's
status in TrustLogin will become "Suspended." However, by editing the user information,
you can continue to use TrustLogin. In that case, you will need to assign a login method, such as password authentication
or an external IdP integration option.
Linking Existing TrustLogin Users with AD Users
Before introducing AD integration, users registered manually or via CSV upload
can also be linked to AD users. If the email address of an existing TrustLogin user matches that of an AD user subject to synchronization,
the two will be automatically linked. If an existing user is not included among the AD users subject to synchronization,
they will not be linked to AD and will continue to be handled as before.
Note: This describes the behavior when integration is first started.
- Even with AD integration enabled, you can still create users manually or via CSV upload without linking them to AD.
- During the first synchronization with AD, if a user with the email address in AD already
exists in TrustLogin, that user will be able to log in with either their AD password or their originally configured TrustLogin
password. If you want to remove the TrustLogin password,
please remove the target user from the settings for "Password Authentication."
2. About the Source of User Information
For users registered through AD integration, or users linked to AD,
AD-side information becomes the master, and the following controls for these users
become unavailable in TrustLogin.
- Updating user attributes
- Suspending status
- Deleting users
- Controlling membership in TrustLogin groups
If any of the above controls are needed, please update the information on the AD side, or update the sync settings in the case of group membership control.
3. Controlling TrustLogin Group Membership
By linking AD security groups to TrustLogin groups through sync conditions,
you can control which TrustLogin groups a user belongs to.
When a user is added to a security group in AD, they are automatically registered in the linked TrustLogin
group. Similarly, when a user is removed from the security group in AD,
they are also removed from the linked group in TrustLogin.
Please note that, in this case, the user will lose access to applications assigned to the TrustLogin group,
and any credential information configured for those applications will be deleted.
Note: If you want to assign a user created through AD integration to a TrustLogin group that differs from their AD security group, please use the Automatic Group Assignment feature.
4. User Attribute Updates
When a user object's attributes change in AD, the corresponding attributes
are also updated in TrustLogin. The fields subject to updates are as follows.
However, updating user attributes other than first and last name is optional and can be changed in the user sync settings.
Last name, first name, department, phone number, postal code, prefecture, city, street address
5. About Synchronization Timing
Automatic registration/suspension via AD integration, TrustLogin group membership control, and user attribute updates are
not processed in real time.
Please note that this may take anywhere from several tens of minutes to several hours.
(The sync interval can be changed in the sync settings. By default, synchronization occurs every 30 minutes.)