|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, click here |
||
|
SP-side settings |
〇 |
Configured by the administrator |
|
Request the SP to configure the settings |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion is not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Bizer team (SAML)".
- Note down the "IdP URL" and "Issuer/Entity ID" under the identity provider information, and download the certificate using the "Certificate" button.
Now let's move on to the Bizer team configuration. Please open Bizer team in a separate window.
Bizer team Configuration
- Log in with an account that has master privileges, and open the gear icon (Company Settings) in the upper left of the screen.
- From Company Settings, click "SAML Settings".
-
Configure item ① of "SAML Settings" as follows, then click "Save".
SAML Entity ID The "Issuer/Entity ID" you noted down from TrustLogin SAML Single Sign-On Service URL The "IdP URL" you noted down from TrustLogin Sign-Out URL https://portal.trustlogin.com/ Certificate Open the certificate downloaded from TrustLogin and paste it in - Note down the "Identifier (Entity ID)" and "Reply URL (Assertion Consumer Service URL)" in item ② of "SAML Settings".
(You will enter these into TrustLogin later.) - Click "Check if you can sign in with SSO" in ③.
- You will be taken to the sign-in screen below. Enter your email address and check whether sign-in succeeds.
- Once sign-in succeeds, click the "Save" button in ④ to save.
Note: Set the "Disable sign-in with email address" checkbox according to your company's policy. Checking this box will disable sign-in by email address, so we recommend leaving it unchecked when configuring SAML.
TrustLogin Admin Page Configuration (Continued)
-
Configure each item under "Service Provider Settings" with the Bizer team information as follows.
Entity ID Enter the "Identifier (Entity ID)" you noted down from Bizer team ACS URL for the Service Enter the "Reply URL (Assertion Consumer Service URL)" you noted down from Bizer team
- Click the "Register" button to save the settings.
TrustLogin User Configuration
① Adding the app from My Page (user)
- Click the "Add App" button on "My Page".
- Select "Bizer team (SAML)" on the "Register App" screen, then click the "Next" button in the upper right of the screen.
- Enter a value if you want to change the "Display Name", then click the "Register" button.
② Adding members (administrator)
- Search for and click the "Bizer team (SAML)" app in the "Admin Page > Apps" menu.
- Click "Add Member", select the users to add from the member list, then click the "Register" button to add them.