Device Restriction Option User Manual

This page provides an overview of device restriction using device certificates, the setup flow, and important notes.
We encourage both customers considering this feature and those about to proceed with setup to read through this page.

Table of Contents:

About the Device Restriction Feature

How to Use

List of Device Restriction Feature Setup Guides

Notes

FAQ

About the Device Certificate Option

This feature issues and distributes device certificates linked to unique device information (such as MAC addresses) of the devices used by users.

By using the certificate import tool "Secure Authentication Suite" (Sixscape Inc.), you can install device certificates without providing certificate files directly to users.
Note: The tool must be installed on the target device in advance.

In addition, since a separate certificate is issued for each device, certificates can also be revoked on a per-device basis.
Up to 10 certificates can be issued per user.

The supported OS and device identification information used when issuing and distributing certificates are as follows.
Note: Due to the specifications of virtual desktops, we have confirmed that duplicate MAC addresses may be used in some cases.

In such cases, TrustLogin's device restriction feature will return an error and cannot be used.

Supported OS Device Information Used for Identification

Windows 10 or later, 64-bit

Note: .NET Framework 4.8 runtime is required

MAC address

(MAC address of the first active physical network adapter)
macOS 10.12 or later MAC address
(MAC address of the Wi-Fi adapter)
iOS / iPadOS 15 or later IMEI
Android 9.0 or later Device ID
ChromeOS Not supported


Note: In addition to a TrustLogin Pro Plan subscription, a subscription to this option is required to use this feature.
For pricing, please see here

How to Use

Both the administrator and the member (device user) need to perform steps. The basic setup flow is as follows.


① Administrator: Assign the device certificate option to the member.

② Member: Install the certificate import tool on the device.

③ Member: Launch the certificate import tool and log in with the TrustLogin account.

④ Member: Request a certificate from the certificate import tool.

⑤ Administrator: Check the member's request on the Admin Page and approve or deny it.

⑥ Member: Perform the operation in the certificate import tool to install the certificate.



List of Device Restriction Feature Setup Guides

Please refer to each of the following pages for setup instructions.

1. (For Administrators) Assigning the Option and Approving Requests

2-1. (For Members) Device Restriction Option User Manual

2-2. (For Members) Tool Import and Certificate Installation [Windows]

2-3. (For Members) Tool Import and Certificate Installation [Mac]

2-4. (For Members) Tool Import and Certificate Installation [iOS]

2-5. (For Members) Tool Import and Certificate Installation [Android]

(For Administrators) Bulk Registration of Approved Devices

Device Certificate Troubleshooting

Notes

There are some specification-related notes regarding this option. Administrators should be aware of the following information.

- This option cannot be used for a user with the same email address across multiple company IDs.
You must remove the option assignment from all company IDs other than the one you want to use.

- The system emails sent by this option are only available in Japanese.
(English-language emails are planned for a future release.)

- Logs generated by this option's asynchronous processing are recorded
as if performed by the administrator who created the company ID.

- You cannot install device certificates for multiple users on the same device.
Any attempt to install will fail with an error.

- On some older iPhone/iPad models, device information cannot be obtained unless a SIM card is inserted,
so a device certificate cannot be obtained.

- This option cannot be used together with the Client Authentication option for the same member.
When enabling "Enable Device Certificate Check,"
you must unassign the Client Authentication option.

- In the Windows version of the "Secure Authentication Suite" app, we have confirmed that the following error occurs
when logging in to TrustLogin using push notification authentication.
"An error has occurred in the script on this page."
If you cancel this error twice, a notification will arrive after a longer time than usual, allowing authentication to proceed.
If this behavior is not acceptable, we apologize for the inconvenience, but please temporarily assign
a different authentication method, such as password authentication, instead.

FAQ

Q. What is the difference from Client Authentication?

A. They differ in what the certificate is linked to and how the certificate is distributed.

Device Restriction Option:
Certificates are distributed linked to device identification information such as the device's MAC address or IMEI.
Since certificate distribution is performed via the tool, no certificate file remains on the device.

Client Authentication Option:
Certificates are issued linked to the information of each user to whom the option is assigned.
Since the certificate is provided as a file, distribution is done via MDM, an asset management tool, or manually by the administrator or member.

Device Restriction Option User Manual

This page provides an overview of device restriction using device certificates, the setup flow, and important notes.
We encourage both customers considering this feature and those about to proceed with setup to read through this page.

Table of Contents:

About the Device Restriction Feature

How to Use

List of Device Restriction Feature Setup Guides

Notes

FAQ

About the Device Certificate Option

This feature issues and distributes device certificates linked to unique device information (such as MAC addresses) of the devices used by users.

By using the certificate import tool "Secure Authentication Suite" (Sixscape Inc.), you can install device certificates without providing certificate files directly to users.
Note: The tool must be installed on the target device in advance.

In addition, since a separate certificate is issued for each device, certificates can also be revoked on a per-device basis.
Up to 10 certificates can be issued per user.

The supported OS and device identification information used when issuing and distributing certificates are as follows.
Note: Due to the specifications of virtual desktops, we have confirmed that duplicate MAC addresses may be used in some cases.

In such cases, TrustLogin's device restriction feature will return an error and cannot be used.

Supported OS Device Information Used for Identification

Windows 10 or later, 64-bit

Note: .NET Framework 4.8 runtime is required

MAC address

(MAC address of the first active physical network adapter)
macOS 10.12 or later MAC address
(MAC address of the Wi-Fi adapter)
iOS / iPadOS 15 or later IMEI
Android 9.0 or later Device ID
ChromeOS Not supported


Note: In addition to a TrustLogin Pro Plan subscription, a subscription to this option is required to use this feature.
For pricing, please see here

How to Use

Both the administrator and the member (device user) need to perform steps. The basic setup flow is as follows.


① Administrator: Assign the device certificate option to the member.

② Member: Install the certificate import tool on the device.

③ Member: Launch the certificate import tool and log in with the TrustLogin account.

④ Member: Request a certificate from the certificate import tool.

⑤ Administrator: Check the member's request on the Admin Page and approve or deny it.

⑥ Member: Perform the operation in the certificate import tool to install the certificate.



List of Device Restriction Feature Setup Guides

Please refer to each of the following pages for setup instructions.

1. (For Administrators) Assigning the Option and Approving Requests

2-1. (For Members) Device Restriction Option User Manual

2-2. (For Members) Tool Import and Certificate Installation [Windows]

2-3. (For Members) Tool Import and Certificate Installation [Mac]

2-4. (For Members) Tool Import and Certificate Installation [iOS]

2-5. (For Members) Tool Import and Certificate Installation [Android]

(For Administrators) Bulk Registration of Approved Devices

Device Certificate Troubleshooting

Notes

There are some specification-related notes regarding this option. Administrators should be aware of the following information.

- This option cannot be used for a user with the same email address across multiple company IDs.
You must remove the option assignment from all company IDs other than the one you want to use.

- The system emails sent by this option are only available in Japanese.
(English-language emails are planned for a future release.)

- Logs generated by this option's asynchronous processing are recorded
as if performed by the administrator who created the company ID.

- You cannot install device certificates for multiple users on the same device.
Any attempt to install will fail with an error.

- On some older iPhone/iPad models, device information cannot be obtained unless a SIM card is inserted,
so a device certificate cannot be obtained.

- This option cannot be used together with the Client Authentication option for the same member.
When enabling "Enable Device Certificate Check,"
you must unassign the Client Authentication option.

- In the Windows version of the "Secure Authentication Suite" app, we have confirmed that the following error occurs
when logging in to TrustLogin using push notification authentication.
"An error has occurred in the script on this page."
If you cancel this error twice, a notification will arrive after a longer time than usual, allowing authentication to proceed.
If this behavior is not acceptable, we apologize for the inconvenience, but please temporarily assign
a different authentication method, such as password authentication, instead.

FAQ

Q. What is the difference from Client Authentication?

A. They differ in what the certificate is linked to and how the certificate is distributed.

Device Restriction Option:
Certificates are distributed linked to device identification information such as the device's MAC address or IMEI.
Since certificate distribution is performed via the tool, no certificate file remains on the device.

Client Authentication Option:
Certificates are issued linked to the information of each user to whom the option is assigned.
Since the certificate is provided as a file, distribution is done via MDM, an asset management tool, or manually by the administrator or member.