|
Item |
Content |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, click here |
||
|
SP-Side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Verification Status |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the top right of the screen.
- Search on the "Corporate App Registration" screen and select "@pocket (SAML)".
- Note down the value of the "Identity Provider URL" in "Identity Provider Information", and download the "Certificate".
- In the 3 blank fields under "Service Provider Settings", enter your organization's @pocket login URL.
(Example) https://xxxxxx.at-pocket.com/xxxxxxxxxxxxxxx/
- Save by clicking the "Register" button.
@pocket Configuration
- Log in to @pocket with a system administrator account and open "Administrator Settings".
- Open "SAML Authentication Settings" and configure each item as follows.
Use SAML Authentication Turn the toggle ON Require Use of SAML Authentication Turn ON/OFF according to your operational needs
Note: If turned ON, the only login method will be SAML authentication, and login with an ID/password will no longer be possible.
By accessing a URL with "?saml=off" appended to the end of the login URL, only system administrators can log in with an ID/password.IdP Login URL The "Identity Provider URL" obtained from TrustLogin IdP Public Key Certificate Using the paperclip icon on the right, upload the "Certificate" obtained from TrustLogin
When "Use SAML Authentication" is turned ON, a "Log in with External ID" button will appear on the login screen. When Require Use of SAML Authentication is enabled, the login screen will not be displayed.
TrustLogin User Configuration
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "@pocket (SAML)" and click the "Next" button in the top right of the screen.
- If you want to change the "Display Name", enter it, and click the "Register" button.
② When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "@pocket (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.