|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based provisioning supported (account management possible via TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible via TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇※1 |
iOS - Standard Browser (Safari) |
|
|
〇※1 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇※1 |
Android - Standard Browser (Chrome) |
|
|
〇※1 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Note: 1 Not supported
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Corporate App" screen and select "AddressLook (SAML)".
- Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the metadata.
-
Open the downloaded metadata file and copy the <ds:X509Certificate> string, and keep it noted down.
(Tip: it's easy to find by searching the file for <ds:X509Certificate>. Copy the string up through the trailing ==.)
- Click the "Register" button.
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "AddressLook (SAML)", then click the "Next" button at the top right of the screen.
- Enter a new value if you want to change the "Display Name", then click the "Register" button.
AddressLook Configuration
- Log in to the AddressLook product admin site and select "Federation Setting" > "New".
-
Configure each item as follows, then click "Update".
Enter the domain portion of the account name (the part after the @ in the account name)
Example: If the account name is ▲▲▲@example.com,
example.com is what you enter
Net BIOS Domain Extract and enter part of the subdomain of the account name
Example: If the account name is ▲▲▲@example.com,
example is the part you enter
Select "2: SAML Authentication" Login Url The "IdP URL" noted from TrustLogin The "Entity ID" noted from TrustLogin
IsCertificate Check the box
Certificate Paste the <ds:X509Certificate>
string extracted from TrustLogin's metadata
o365upn
- In the admin site, select "User" > "Edit".
-
, then click "Update".
Note: For general users who do not need to sign in to the admin site, sign-in via SAML authentication is possible without creating a user under "User".
TrustLogin User Configuration
① When a user adds the app from My Page
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "AddressLook (SAML)", then click the "Next" button at the top right of the screen.
- Enter a new value if you want to change the "Display Name", then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "AddressLook (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log In to AddressLook
① Logging in from the AddressLook login page
- Open the AddressLook website, select "Federation Authentication", enter the account name (AddressLook's "User Id"), and click the login button.
- You will be redirected to the TrustLogin login screen, so please authenticate there. Also, if you are already logged in to TrustLogin, you will be redirected directly to AddressLook.
Note: The only login method for the AddressLook product admin site is form authentication.
② Logging in from TrustLogin's My Page or browser extension
To access AddressLook via SAML authentication from TrustLogin's My Page or browser extension, you can separately register the "AddressLook (SSO)" app, which enables logging in to AddressLook via SAML. (Note: This app can only be authenticated on PC.)
- Search on the "Register Corporate App" screen and select "AddressLook (SSO)".
- Click the "Register" button.
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "AddressLook (SSO)".
- Select "Federation Authentication", enter AddressLook's "" in "Account Name", and click "Save".
- Click the "AddressLook (SSO)" app and verify that login succeeds.