How to Configure SAML Authentication for Discoveriez

Item

Description

Prerequisites

  • Prior configuration in Discoveriez is required.

  • You need to create an account in Discoveriez using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Discoveriez.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-Side Configuration

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on how to configure provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

  1. Admin Page Settings in TrustLogin

    1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
      01.png

    2. Register the "Application Name" and "Icon" (optional).
      Discoveriez01.png

    3. Download the metadata from "Identity Provider Information", and make a note of the "Issuer/Entity ID."
      Discoveriez02.png

    Now, switch to the configuration on the Discoveriez side. Please open Discoveriez in a separate window.

Discoveriez Configuration

  1. Log in with an administrator account, and select "Maintenance" from the hamburger menu.
    Discoveriez07.png

  2. Open Development > Login Settings.
    Discoveriez08.png
  3. From the Login Method dropdown, select "SSO Login (SAML Authentication)".
    Discoveriez09.png

  4. For "Login Mode Selection", please choose according to your company's policy.
    Note: If you select "SAML SSO Only", normal login using a username and password will no longer be possible. When configuring SAML, we recommend selecting "Use Normal Login and SAML SSO Together".
  5. From "Step 1: Register Discoveriez information with the IdP", make a note of the "SSO URL", "ACS URL", and "Logout URL". (You will set these in TrustLogin later.)
    Discoveriez10.png

  6. In "Step 2: Enter IdP information in Discoveriez", under the "Upload Authentication File" item, upload the metadata you noted from TrustLogin.
    Discoveriez11.png

  7. After the upload is complete, confirm that all fields except "Entity ID" and "Label" are populated.Discoveriez03.png

  8. Enter the following into the "Entity ID", "Label", and "Single Logout URL" fields, and click the "Save" button.
    "Entity ID" The "Issuer/Entity ID" you noted from TrustLogin
    "Label"

    Enter the Discoveriez login URL changed as follows:
    Example: Login URL https://●●●●.xxxxxxxx.cloud
    ●●●●.xxxxxxxx.cloud SAML SSO

    Note: Be sure to enter a half-width space between "cloud" and "SAML SSO".

    "Single Logout URL" https://portal.trustlogin.com/


Discoveriez04.png


Admin Page Settings in TrustLogin (Continued)

  1. Set each item in "Service Provider Settings" with the Discoveriez information as follows.
    Login URL The "SSO URL" you noted from Discoveriez
    Sign SAML Response Check this box
    Redirect URL After SP Authentication

    Enter the Discoveriez login URL

    Example: Login URL https://●●●●.xxxxxxxx.cloud

    Value for Name ID

    Select "Member" - "email" (leave as default)

    Entity ID

    From the Discoveriez login URL (https://●●●●.xxxxxxxx.cloud)

    extract and enter the ●●●● portion

    Name ID Format Select "emailAddress"
    ACS URL to Service The "ACS URL" you noted from Discoveriez
    Logout URL

    The "Logout URL" you noted from Discoveriez


    Discoveriez06.png

  2. Using the "Add SAML Attribute" button in "SAML Attribute Settings", add rows (attributes) and configure as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Specified Attribute Name Attribute Type Attribute Name Attribute Value
    name Email name Member Member - Email Address
    identityprovider Basic Fixed Value Enter the "Issuer/Entity ID" of TrustLogin

    Discoveriez05.png

  3. Click the "Register" button to save the settings.

User Settings in TrustLogin

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, and click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for the custom SAML app you created and click it.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Discoveriez

Item

Description

Prerequisites

  • Prior configuration in Discoveriez is required.

  • You need to create an account in Discoveriez using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Discoveriez.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-Side Configuration

Configured by the administrator

Request the SP to configure settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on how to configure provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

  1. Admin Page Settings in TrustLogin

    1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
      01.png

    2. Register the "Application Name" and "Icon" (optional).
      Discoveriez01.png

    3. Download the metadata from "Identity Provider Information", and make a note of the "Issuer/Entity ID."
      Discoveriez02.png

    Now, switch to the configuration on the Discoveriez side. Please open Discoveriez in a separate window.

Discoveriez Configuration

  1. Log in with an administrator account, and select "Maintenance" from the hamburger menu.
    Discoveriez07.png

  2. Open Development > Login Settings.
    Discoveriez08.png
  3. From the Login Method dropdown, select "SSO Login (SAML Authentication)".
    Discoveriez09.png

  4. For "Login Mode Selection", please choose according to your company's policy.
    Note: If you select "SAML SSO Only", normal login using a username and password will no longer be possible. When configuring SAML, we recommend selecting "Use Normal Login and SAML SSO Together".
  5. From "Step 1: Register Discoveriez information with the IdP", make a note of the "SSO URL", "ACS URL", and "Logout URL". (You will set these in TrustLogin later.)
    Discoveriez10.png

  6. In "Step 2: Enter IdP information in Discoveriez", under the "Upload Authentication File" item, upload the metadata you noted from TrustLogin.
    Discoveriez11.png

  7. After the upload is complete, confirm that all fields except "Entity ID" and "Label" are populated.Discoveriez03.png

  8. Enter the following into the "Entity ID", "Label", and "Single Logout URL" fields, and click the "Save" button.
    "Entity ID" The "Issuer/Entity ID" you noted from TrustLogin
    "Label"

    Enter the Discoveriez login URL changed as follows:
    Example: Login URL https://●●●●.xxxxxxxx.cloud
    ●●●●.xxxxxxxx.cloud SAML SSO

    Note: Be sure to enter a half-width space between "cloud" and "SAML SSO".

    "Single Logout URL" https://portal.trustlogin.com/


Discoveriez04.png


Admin Page Settings in TrustLogin (Continued)

  1. Set each item in "Service Provider Settings" with the Discoveriez information as follows.
    Login URL The "SSO URL" you noted from Discoveriez
    Sign SAML Response Check this box
    Redirect URL After SP Authentication

    Enter the Discoveriez login URL

    Example: Login URL https://●●●●.xxxxxxxx.cloud

    Value for Name ID

    Select "Member" - "email" (leave as default)

    Entity ID

    From the Discoveriez login URL (https://●●●●.xxxxxxxx.cloud)

    extract and enter the ●●●● portion

    Name ID Format Select "emailAddress"
    ACS URL to Service The "ACS URL" you noted from Discoveriez
    Logout URL

    The "Logout URL" you noted from Discoveriez


    Discoveriez06.png

  2. Using the "Add SAML Attribute" button in "SAML Attribute Settings", add rows (attributes) and configure as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Specified Attribute Name Attribute Type Attribute Name Attribute Value
    name Email name Member Member - Email Address
    identityprovider Basic Fixed Value Enter the "Issuer/Entity ID" of TrustLogin

    Discoveriez05.png

  3. Click the "Register" button to save the settings.

User Settings in TrustLogin

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, and click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for the custom SAML app you created and click it.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.