How to Configure SAML Authentication for direct

Item

Details

Prerequisites

  • Prior configuration on the direct side is required.

  • You must add an account using the same email address as your TrustLogin account to the target account management group in direct.

  • For the latest setup instructions, please refer to the manual provided by direct.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Enterprise App" screen and select "direct (SAML)".
    02.png

  3. Note down the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
    03.png

Now switch to the configuration on the direct side.
Log in to direct with the owner account in a separate window.

Configuring direct

  1. Log in with the owner account and open "Account Management".
    04.png

  2. From the settings menu of the account management group you want to configure, open "Single Sign-On".
    05.png

  3. Configure each item as follows.
    Also, obtain the metadata from "Download Service Provider Metadata".
    Finally, click the "Change" button to save the settings.
    Use SAML authentication Check the box
    Identity Provider endpoint URL

    The "Identity Provider URL" you noted from TrustLogin

    URL to redirect to after logout https://portal.trustlogin.com/
    Identity Provider public key The "Certificate" obtained from TrustLogin

    06.png

Now return to the TrustLogin settings again.

Configuring the TrustLogin Admin Page (continued)

  1. Under "Service Provider Settings", use "Select Metadata" to select and upload the metadata you obtained from direct.
    07.png

  2. Click the "Register" button to save.

Configuring the TrustLogin User

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "direct (SAML)" on the "Register App" screen and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for the "direct (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Log In to direct

① Logging in from the direct login page

  1. Open the login page and click "Single Sign-On" at the bottom.
    08.png

  2. Enter the "Account Management Group ID" and click "Next".
    09.png

  3. You will be redirected to the TrustLogin login screen, so please complete authentication there. If you are already logged in to TrustLogin, you will be redirected to direct directly.

② Logging in from the TrustLogin My Page or browser extension

When accessing direct via SAML authentication from the TrustLogin My Page or browser extension, authentication will not complete from the "direct (SAML)" app alone. You will be redirected to the single sign-on login page, so please enter the "Account Management Group ID" to complete login.

09.png

Alternatively, by separately registering the "direct (SSO)" app, the Account Management Group ID will be entered automatically, allowing you to perform SAML authentication from TrustLogin.
10.png

How to Configure SAML Authentication for direct

Item

Details

Prerequisites

  • Prior configuration on the direct side is required.

  • You must add an account using the same email address as your TrustLogin account to the target account management group in direct.

  • For the latest setup instructions, please refer to the manual provided by direct.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Enterprise App" screen and select "direct (SAML)".
    02.png

  3. Note down the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
    03.png

Now switch to the configuration on the direct side.
Log in to direct with the owner account in a separate window.

Configuring direct

  1. Log in with the owner account and open "Account Management".
    04.png

  2. From the settings menu of the account management group you want to configure, open "Single Sign-On".
    05.png

  3. Configure each item as follows.
    Also, obtain the metadata from "Download Service Provider Metadata".
    Finally, click the "Change" button to save the settings.
    Use SAML authentication Check the box
    Identity Provider endpoint URL

    The "Identity Provider URL" you noted from TrustLogin

    URL to redirect to after logout https://portal.trustlogin.com/
    Identity Provider public key The "Certificate" obtained from TrustLogin

    06.png

Now return to the TrustLogin settings again.

Configuring the TrustLogin Admin Page (continued)

  1. Under "Service Provider Settings", use "Select Metadata" to select and upload the metadata you obtained from direct.
    07.png

  2. Click the "Register" button to save.

Configuring the TrustLogin User

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "direct (SAML)" on the "Register App" screen and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. Search for the "direct (SAML)" app in the "Admin Page > Apps" menu and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

How to Log In to direct

① Logging in from the direct login page

  1. Open the login page and click "Single Sign-On" at the bottom.
    08.png

  2. Enter the "Account Management Group ID" and click "Next".
    09.png

  3. You will be redirected to the TrustLogin login screen, so please complete authentication there. If you are already logged in to TrustLogin, you will be redirected to direct directly.

② Logging in from the TrustLogin My Page or browser extension

When accessing direct via SAML authentication from the TrustLogin My Page or browser extension, authentication will not complete from the "direct (SAML)" app alone. You will be redirected to the single sign-on login page, so please enter the "Account Management Group ID" to complete login.

09.png

Alternatively, by separately registering the "direct (SSO)" app, the Account Management Group ID will be entered automatically, allowing you to perform SAML authentication from TrustLogin.
10.png