This page explains user authentication, one of the main features of Active Directory integration.
Whether you are considering this feature or are about to begin configuration, we encourage you to read this article.
If you have any questions or concerns, please feel free to contact us.
|
Contents: 2. Using TrustLogin Password Together with AD Authentication |
1. Logging in to TrustLogin
Logging in with Your AD Password
Users utilizing AD integration can log in to TrustLogin using their AD email address
and AD password.
Your AD password is never stored in TrustLogin at all; an authentication request is sent to AD
each time you log in, so you will always be logging in with your current AD password.
Authentication Flow
① Enter your AD ID and password in the TrustLogin login form
② TrustLogin sends an authentication request to Active Directory via the AD Connector (this occurs each time)
③ Active Directory returns a successful authentication response to TrustLogin via the AD Connector
④ Login to TrustLogin succeeds
2. Using TrustLogin Password Together with AD Authentication
About Setting a TrustLogin Password
In addition to logging in with your AD password, you can also configure a separate TrustLogin password.
This helps prevent you from being locked out of TrustLogin if your organization loses connectivity to AD.
For example, the following operational approach is possible.
- Allow administrators to log in with either their TrustLogin password or their AD password
- Allow general users to log in only with their AD password
Even under this kind of operation, if logging in with an AD password becomes unavailable,
you can allow all users to set a TrustLogin password.
Note: For information on how to assign password authentication to users, please read here.
[Important] Setting to Prevent Sending Emails to Members During Synchronization
By default, password authentication is assigned at the same time a member is created through AD synchronization,
and a "Register Your TrustLogin Password" email is sent automatically.
Therefore, in the cases described below, please turn off the
"Automatically assign password authentication when a member is registered" setting under "Settings > Password Authentication"
before performing synchronization.
- If you are still configuring synchronization and have not yet shared TrustLogin information with members
- If you want to allow members to log in only with their AD password