How to Configure SAML Authentication for Sales Force Assistant

Item

Details

Prerequisites

  • Prior configuration is required on the Sales Force Assistant side.

  • You must create an account in Sales Force Assistant whose "Login ID" uses the same email address as the one registered with GMO TrustLogin.
  • For the latest setup instructions, please refer to the manual provided by Sales Force Assistant.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: If the "Login ID" in Sales Force Assistant is not an email address, you will need to add the "Login ID" to the member information in TrustLogin and link the two. For detailed instructions, please refer to the pages below.
(This is not necessary if the Login ID for Sales Force Assistant is set to the same email address registered in TrustLogin.)

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Sales Force Assistant (SAML)."
    Sales_Force_Assistant01.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information." (You will need this later when configuring the Sales Force Assistant side.)
    03.png

Now let's move on to the settings on the Sales Force Assistant side. Please open Sales Force Assistant in a separate window.
Note: If you might need to interrupt your work, click the "Register" button in the upper right to save your settings.

Configuring Sales Force Assistant

  1. Log in with an administrator account and click "System Settings" to go to the administrator screen.
    Sales_Force_Assistant02.png

  2. Open "Security > SAML Authentication."
    05.png

  3. For the logout URL under "Service Provider (NI Product) Settings," enter any URL you want users to be redirected to after logging out of Sales Force Assistant. Download the metadata using the download button under "Metadata."
    06.png

  4. Under "Identity Provider Settings," upload the metadata you downloaded from TrustLogin by dragging and dropping it into the "Metadata" field, or by using the button on the right.
    07.png

    After clicking the "Load" button, the "Entity ID," "Endpoint URL," and "Certificate" fields will be filled in automatically.
    08.png

  5. Check "Use" under "Single Sign-On Settings > Single Sign-On" and save.
    09.png

  6. Click "Finish Settings."
    10.png

Return to the TrustLogin Admin Page again.

Configuring the TrustLogin Admin Page (Continued)

  1. Configure each item under "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication

    Enter the URL of the My Page that appears after logging in to Sales Force Assistant.
    Example) https://xxxxxxxx.com/xxxxxxxx/ni/nicrm/main/

    Value for Name ID

    ・If the Sales Force Assistant Login ID and the TrustLogin email address are the same

    → Set "Member > email"


    ・If the Sales Force Assistant Login ID and the TrustLogin email address are different
    → Set "Custom Attribute > the custom attribute name you configured"

    Metadata Upload the metadata downloaded from Sales Force Assistant

    11.png

  2. Click the "Register" button in the upper right to finish.

Configuring TrustLogin Users

① When users add the app from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "Sales Force Assistant (SAML)" and click the "Next" button in the upper right of the screen.
  3. Enter a new value if you want to change the "Display Name," then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Sales Force Assistant (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Sales Force Assistant

Item

Details

Prerequisites

  • Prior configuration is required on the Sales Force Assistant side.

  • You must create an account in Sales Force Assistant whose "Login ID" uses the same email address as the one registered with GMO TrustLogin.
  • For the latest setup instructions, please refer to the manual provided by Sales Force Assistant.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure this

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; users cannot be deleted)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

Note: If the "Login ID" in Sales Force Assistant is not an email address, you will need to add the "Login ID" to the member information in TrustLogin and link the two. For detailed instructions, please refer to the pages below.
(This is not necessary if the Login ID for Sales Force Assistant is set to the same email address registered in TrustLogin.)

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Sales Force Assistant (SAML)."
    Sales_Force_Assistant01.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information." (You will need this later when configuring the Sales Force Assistant side.)
    03.png

Now let's move on to the settings on the Sales Force Assistant side. Please open Sales Force Assistant in a separate window.
Note: If you might need to interrupt your work, click the "Register" button in the upper right to save your settings.

Configuring Sales Force Assistant

  1. Log in with an administrator account and click "System Settings" to go to the administrator screen.
    Sales_Force_Assistant02.png

  2. Open "Security > SAML Authentication."
    05.png

  3. For the logout URL under "Service Provider (NI Product) Settings," enter any URL you want users to be redirected to after logging out of Sales Force Assistant. Download the metadata using the download button under "Metadata."
    06.png

  4. Under "Identity Provider Settings," upload the metadata you downloaded from TrustLogin by dragging and dropping it into the "Metadata" field, or by using the button on the right.
    07.png

    After clicking the "Load" button, the "Entity ID," "Endpoint URL," and "Certificate" fields will be filled in automatically.
    08.png

  5. Check "Use" under "Single Sign-On Settings > Single Sign-On" and save.
    09.png

  6. Click "Finish Settings."
    10.png

Return to the TrustLogin Admin Page again.

Configuring the TrustLogin Admin Page (Continued)

  1. Configure each item under "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication

    Enter the URL of the My Page that appears after logging in to Sales Force Assistant.
    Example) https://xxxxxxxx.com/xxxxxxxx/ni/nicrm/main/

    Value for Name ID

    ・If the Sales Force Assistant Login ID and the TrustLogin email address are the same

    → Set "Member > email"


    ・If the Sales Force Assistant Login ID and the TrustLogin email address are different
    → Set "Custom Attribute > the custom attribute name you configured"

    Metadata Upload the metadata downloaded from Sales Force Assistant

    11.png

  2. Click the "Register" button in the upper right to finish.

Configuring TrustLogin Users

① When users add the app from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "Sales Force Assistant (SAML)" and click the "Next" button in the upper right of the screen.
  3. Enter a new value if you want to change the "Display Name," then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "Sales Force Assistant (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.