|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
NameID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring a custom attribute, see here |
||
|
SP-side configuration |
|
Configured by the administrator |
| 〇 |
Request configuration from the SP |
|
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Device compatibility verification status |
〇 |
PC - Browser |
|
〇 |
PC - Desktop app |
|
|
ー |
iOS - Standard browser (Safari) |
|
|
ー |
iOS - In-app browser of the TrustLogin mobile app |
|
|
〇 |
iOS - Native app |
|
|
ー |
Android - Standard browser (Chrome) |
|
|
ー |
Android - In-app browser of the TrustLogin mobile app |
|
|
〇 |
Android - Native app |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "InCircle (SAML)".
- Obtain the metadata from "Download Metadata" under Identity Provider Information, and click the "Register" button to save the app settings. Send it to your InCircle representative and request SAML configuration.
- Once InCircle notifies you that the SAML configuration is complete, resume the configuration.
(On the Admin Page's Apps screen, search by app name → open the corresponding app's details screen → change the SAML app settings)
Open the metadata sent by InCircle in a text editor, extract the values of the "Entity ID" and "ACS URL for the service", and set them in the respective fields of the Service Provider configuration as shown below.
Login URL InCircle login URL
Note: Overwrite the value that was originally set.
Example: https://xxxx.incircle.jp/xxxxxx/Entity ID Search the metadata for "entityID" and extract the value enclosed in quotation marks (" ") in [entityID="~"]
Example: https://xxxx.incircle.jp:443/xxxxxx/saml/metadata
ACS URL for the service Search the metadata for "AssertionConsumerService Binding="urn:oasis:names:tc:SAML:2.0:bindings:HTTP-POST"" and extract the value enclosed in quotation marks (" ") in [Location="~"]
Example: https://xxxx.incircle.jp:443/xxxxxx/saml/SSO
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- Select "InCircle (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds members
- Search for and click the "InCircle (SAML)" app in the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
How to Log In to InCircle
Click "Use Single Sign-On" on the login screen. If you are not logged in to TrustLogin, you will be redirected to the TrustLogin login screen; once you authenticate, login to InCircle will complete.