|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure settings |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning(accounts can be managed in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verified operation status by device |
〇 |
PC - Browser |
|
〇 |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
〇 |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
〇 |
Android - Native app |
|
Configuring the TrustLogin Admin Page
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Enterprise App" screen and select "direct (SAML)".
- Note down the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
Now switch to the configuration on the direct side.
Log in to direct with the owner account in a separate window.
Configuring direct
- Log in with the owner account and open "Account Management".
- From the settings menu of the account management group you want to configure, open "Single Sign-On".
- Configure each item as follows.
Also, obtain the metadata from "Download Service Provider Metadata".
Finally, click the "Change" button to save the settings.
Use SAML authentication Check the box Identity Provider endpoint URL The "Identity Provider URL" you noted from TrustLogin
URL to redirect to after logout https://portal.trustlogin.com/ Identity Provider public key The "Certificate" obtained from TrustLogin
Now return to the TrustLogin settings again.
Configuring the TrustLogin Admin Page (continued)
- Under "Service Provider Settings", use "Select Metadata" to select and upload the metadata you obtained from direct.
- Click the "Register" button to save.
Configuring the TrustLogin User
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- Select "direct (SAML)" on the "Register App" screen and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds members
- Search for the "direct (SAML)" app in the "Admin Page > Apps" menu and click it.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
How to Log In to direct
① Logging in from the direct login page
- Open the login page and click "Single Sign-On" at the bottom.
- Enter the "Account Management Group ID" and click "Next".
- You will be redirected to the TrustLogin login screen, so please complete authentication there. If you are already logged in to TrustLogin, you will be redirected to direct directly.
② Logging in from the TrustLogin My Page or browser extension
When accessing direct via SAML authentication from the TrustLogin My Page or browser extension, authentication will not complete from the "direct (SAML)" app alone. You will be redirected to the single sign-on login page, so please enter the "Account Management Group ID" to complete login.
Alternatively, by separately registering the "direct (SSO)" app, the Account Management Group ID will be entered automatically, allowing you to perform SAML authentication from TrustLogin.