|
Item |
Content |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
Notes |
In 2024, InsuiteX released a new SAML authentication infrastructure. If you started using the service after this release, your configuration uses the new specification, so please refer to "[New Infrastructure] How to Configure SAML Authentication for InsuiteX." Please check the authentication settings screen to determine which version (old or new) applies to you.
[How to Check Your Version] After logging in to InsuiteX, you can check this from "System Administration > System Information." If "Version > Authentication Infrastructure" shows v3: New infrastructure |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "InsuiteX (SAML)."
- Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate from "Get Certificate."
-
In the "Service Provider Settings" section, enter the login URL issued when your InsuiteX account was registered, into the blank fields for "Login URL," "Entity ID," and "ACS URL for Service."
Example: https://[customer domain].insuite.jp
- Click the "Register" button to save.
InsuiteX Configuration
- Log in to the settings screen as an administrator, open "System Integration Management > Authentication Settings," and click "Add Authentication Method."
- Configure the items on the SAML settings screen as follows.
Any ID (here, trustlogin) Name Any name (here, GMO TrustLogin)
The name you set here will be displayed on the login screen.
Entity ID The "Issuer/Entity ID" you noted from TrustLogin Single Sign-on URL The "IdP URL" you noted from TrustLogin Single Logout URL https://portal.trustlogin.com/ Certificate Open the "Certificate" you noted from TrustLogin and paste it in
- Click "Save."
Note: The name you set in the "Name" field will be displayed at login as shown below.
TrustLogin User Configuration
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select "InsuiteX (SAML)" and click the "Next" button in the upper right of the screen.
- Enter a value if you want to change the "Display Name," then click the "Register" button.
- Click the app on "My Page" or the browser extension and verify that login succeeds.
② When an Administrator Adds Members
- On the "Admin Page > Apps" menu, search for and click the "InsuiteX (SAML)" app.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.