Knowledge Suite SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Knowledge Suite is required.

  • For the latest setup instructions, please check the manual provided by Knowledge Suite.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: Verification of native app operation is in progress for both iOS and Android.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click "Register App" in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Knowledge Suite (SAML)".
    02.png

  3. Note down the "Identity Provider URL" in "Identity Provider Information", and download the "Certificate".
    03.png

Now, switch to configuring the Knowledge Suite side.
Do not click the "Register" button yet — open the Knowledge Suite admin page in a separate tab.

Knowledge Suite Settings

  1. Log in to Knowledge Suite with administrator privileges and click "Settings" at the top of the screen.
    04.png

  2. Open "Knowledge Suite Settings > SSO Settings" in the left menu.
    05.png

  3. For "SSO Usage Setting", select "Disabled", enter any subdomain of your choice in "URL for SSO Usage", and click "Save Settings".
    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. In the blank fields for "Login URL", "Entity ID", and "ACS URL to Service" under "Service Provider Settings", enter the subdomain you configured in step 3 of "Knowledge Suite Settings" above.
    07.png
  2. Click the "Register" button.

Knowledge Suite Settings (Continued)

  1. Open "Knowledge Suite Settings > SSO Settings" again.

  2. Configure each item as follows, and click "Save Settings".
    SSO Usage Setting Change to "Enabled"
    Regular Login Permission Setting for SSO Usage Select who is allowed to use regular login
    JIT Integration Usage Setting Select "Enabled"
    Identifier Format Select "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
    Identity Provider Login URL The "Identity Provider URL" you noted down from the TrustLogin Admin Page
    Identity Provider Logout URL Specify https://portal.trustlogin.com/
    Identity Provider Certificate Upload the certificate downloaded from the TrustLogin Admin Page

    08.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Knowledge Suite (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "Knowledge Suite (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Knowledge Suite SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Knowledge Suite is required.

  • For the latest setup instructions, please check the manual provided by Knowledge Suite.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: Verification of native app operation is in progress for both iOS and Android.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click "Register App" in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Knowledge Suite (SAML)".
    02.png

  3. Note down the "Identity Provider URL" in "Identity Provider Information", and download the "Certificate".
    03.png

Now, switch to configuring the Knowledge Suite side.
Do not click the "Register" button yet — open the Knowledge Suite admin page in a separate tab.

Knowledge Suite Settings

  1. Log in to Knowledge Suite with administrator privileges and click "Settings" at the top of the screen.
    04.png

  2. Open "Knowledge Suite Settings > SSO Settings" in the left menu.
    05.png

  3. For "SSO Usage Setting", select "Disabled", enter any subdomain of your choice in "URL for SSO Usage", and click "Save Settings".
    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. In the blank fields for "Login URL", "Entity ID", and "ACS URL to Service" under "Service Provider Settings", enter the subdomain you configured in step 3 of "Knowledge Suite Settings" above.
    07.png
  2. Click the "Register" button.

Knowledge Suite Settings (Continued)

  1. Open "Knowledge Suite Settings > SSO Settings" again.

  2. Configure each item as follows, and click "Save Settings".
    SSO Usage Setting Change to "Enabled"
    Regular Login Permission Setting for SSO Usage Select who is allowed to use regular login
    JIT Integration Usage Setting Select "Enabled"
    Identifier Format Select "urn:oasis:names:tc:SAML:1.1:nameid-format:unspecified"
    Identity Provider Login URL The "Identity Provider URL" you noted down from the TrustLogin Admin Page
    Identity Provider Logout URL Specify https://portal.trustlogin.com/
    Identity Provider Certificate Upload the certificate downloaded from the TrustLogin Admin Page

    08.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Knowledge Suite (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "Knowledge Suite (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.