How to Configure SAML Authentication for InsuiteX

Item

Content

Prerequisites

  • Prior configuration on the InsuiteX side is required.

  • You must create an account in InsuiteX using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by InsuiteX.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Notes

In 2024, InsuiteX released a new SAML authentication infrastructure. If you started using the service after this release, your configuration uses the new specification, so please refer to "[New Infrastructure] How to Configure SAML Authentication for InsuiteX."

Please check the authentication settings screen to determine which version (old or new) applies to you.

[How to Check Your Version]

After logging in to InsuiteX, you can check this from "System Administration > System Information."

If "Version > Authentication Infrastructure" shows v3: New infrastructure
If "Version > Authentication Infrastructure" shows v1 or v2: Old infrastructure

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "InsuiteX (SAML)."
    InsuiteX01.png

  3. Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate from "Get Certificate."
    InsuiteX02.png

  4. In the "Service Provider Settings" section, enter the login URL issued when your InsuiteX account was registered, into the blank fields for "Login URL," "Entity ID," and "ACS URL for Service."
    Example: https://[customer domain].insuite.jpInsuiteX09.png

  5. Click the "Register" button to save.

InsuiteX Configuration

  1. Log in to the settings screen as an administrator, open "System Integration Management > Authentication Settings," and click "Add Authentication Method."InsuiteX04.png
  2. Configure the items on the SAML settings screen as follows.
    Any ID (here, trustlogin)
    Name

    Any name (here, GMO TrustLogin)

    The name you set here will be displayed on the login screen.

    Entity ID The "Issuer/Entity ID" you noted from TrustLogin
    Single Sign-on URL The "IdP URL" you noted from TrustLogin
    Single Logout URL https://portal.trustlogin.com/
    Certificate

    Open the "Certificate" you noted from TrustLogin and paste it in


    InsuiteX05.png
    InsuiteX06.png

  3. Click "Save."
    InsuiteX07.png

    Note: The name you set in the "Name" field will be displayed at login as shown below.
    InsuiteX08.png


TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "InsuiteX (SAML)" and click the "Next" button in the upper right of the screen.
  3. Enter a value if you want to change the "Display Name," then click the "Register" button.
  4. Click the app on "My Page" or the browser extension and verify that login succeeds.

② When an Administrator Adds Members

  1. On the "Admin Page > Apps" menu, search for and click the "InsuiteX (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for InsuiteX

Item

Content

Prerequisites

  • Prior configuration on the InsuiteX side is required.

  • You must create an account in InsuiteX using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by InsuiteX.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Notes

In 2024, InsuiteX released a new SAML authentication infrastructure. If you started using the service after this release, your configuration uses the new specification, so please refer to "[New Infrastructure] How to Configure SAML Authentication for InsuiteX."

Please check the authentication settings screen to determine which version (old or new) applies to you.

[How to Check Your Version]

After logging in to InsuiteX, you can check this from "System Administration > System Information."

If "Version > Authentication Infrastructure" shows v3: New infrastructure
If "Version > Authentication Infrastructure" shows v1 or v2: Old infrastructure

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "InsuiteX (SAML)."
    InsuiteX01.png

  3. Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate from "Get Certificate."
    InsuiteX02.png

  4. In the "Service Provider Settings" section, enter the login URL issued when your InsuiteX account was registered, into the blank fields for "Login URL," "Entity ID," and "ACS URL for Service."
    Example: https://[customer domain].insuite.jpInsuiteX09.png

  5. Click the "Register" button to save.

InsuiteX Configuration

  1. Log in to the settings screen as an administrator, open "System Integration Management > Authentication Settings," and click "Add Authentication Method."InsuiteX04.png
  2. Configure the items on the SAML settings screen as follows.
    Any ID (here, trustlogin)
    Name

    Any name (here, GMO TrustLogin)

    The name you set here will be displayed on the login screen.

    Entity ID The "Issuer/Entity ID" you noted from TrustLogin
    Single Sign-on URL The "IdP URL" you noted from TrustLogin
    Single Logout URL https://portal.trustlogin.com/
    Certificate

    Open the "Certificate" you noted from TrustLogin and paste it in


    InsuiteX05.png
    InsuiteX06.png

  3. Click "Save."
    InsuiteX07.png

    Note: The name you set in the "Name" field will be displayed at login as shown below.
    InsuiteX08.png


TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "InsuiteX (SAML)" and click the "Next" button in the upper right of the screen.
  3. Enter a value if you want to change the "Display Name," then click the "Register" button.
  4. Click the app on "My Page" or the browser extension and verify that login succeeds.

② When an Administrator Adds Members

  1. On the "Admin Page > Apps" menu, search for and click the "InsuiteX (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.