|
Item |
Description |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, click here |
||
|
SP-Side Configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure settings |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Verification Status by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
-
Admin Page Settings in TrustLogin
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
- Register the "Application Name" and "Icon" (optional).
- Download the metadata from "Identity Provider Information", and make a note of the "Issuer/Entity ID."
Now, switch to the configuration on the Discoveriez side. Please open Discoveriez in a separate window. - Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register SAML App" button in the upper right of the screen.
Discoveriez Configuration
- Log in with an administrator account, and select "Maintenance" from the hamburger menu.
- Open Development > Login Settings.
- From the Login Method dropdown, select "SSO Login (SAML Authentication)".
- For "Login Mode Selection", please choose according to your company's policy.
Note: If you select "SAML SSO Only", normal login using a username and password will no longer be possible. When configuring SAML, we recommend selecting "Use Normal Login and SAML SSO Together". - From "Step 1: Register Discoveriez information with the IdP", make a note of the "SSO URL", "ACS URL", and "Logout URL". (You will set these in TrustLogin later.)
- In "Step 2: Enter IdP information in Discoveriez", under the "Upload Authentication File" item, upload the metadata you noted from TrustLogin.
- After the upload is complete, confirm that all fields except "Entity ID" and "Label" are populated.
- Enter the following into the "Entity ID", "Label", and "Single Logout URL" fields, and click the "Save" button.
"Entity ID" The "Issuer/Entity ID" you noted from TrustLogin "Label" Enter the Discoveriez login URL changed as follows:
Example: Login URL https://●●●●.xxxxxxxx.cloud
→●●●●.xxxxxxxx.cloud SAML SSONote: Be sure to enter a half-width space between "cloud" and "SAML SSO".
"Single Logout URL" https://portal.trustlogin.com/
Admin Page Settings in TrustLogin (Continued)
-
Set each item in "Service Provider Settings" with the Discoveriez information as follows.
Login URL The "SSO URL" you noted from Discoveriez Sign SAML Response Check this box Redirect URL After SP Authentication Enter the Discoveriez login URL
Example: Login URL https://●●●●.xxxxxxxx.cloud
Value for Name ID Select "Member" - "email" (leave as default)
Entity ID From the Discoveriez login URL (https://●●●●.xxxxxxxx.cloud)
extract and enter the ●●●● portion
Name ID Format Select "emailAddress" ACS URL to Service The "ACS URL" you noted from Discoveriez Logout URL The "Logout URL" you noted from Discoveriez
-
Using the "Add SAML Attribute" button in "SAML Attribute Settings", add rows (attributes) and configure as follows.
Service Provider Attribute TrustLogin (IdP) Attribute Specified Attribute Name Attribute Type Attribute Name Attribute Value name Email name Member Member - Email Address identityprovider Basic Fixed Value Enter the "Issuer/Entity ID" of TrustLogin
- Click the "Register" button to save the settings.
User Settings in TrustLogin
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter a new one, and click the "Register" button.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for the custom SAML app you created and click it.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.