Cloudflare Zero Trust (Cloudflare Access) SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Cloudflare is required.

  • Please refer to the manual provided by Cloudflare for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Cloudflare (SAML)".
    Cloudflare.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png


  4. Enter the "team name" of your Cloudflare Zero Trust instance into the three blank fields — "Login URL", "Entity ID", and "ACS URL to Service" — under "Service Provider Settings".
    The team name can be found under "Settings > General > Team domain" in Cloudflare Zero Trust.
    05.png

    04.png

  5. Click the "Register" button to save.

  6. To perform a connection test during the Cloudflare configuration in the next section, add the administrator performing this configuration as a member of the SAML app you created. In the "Admin Page > App" menu, search for the "Cloudflare (SAML)" app, and use "Add Member" to add the administrator account.
    Cloudflare02.png

Cloudflare Settings

  1. After logging in to the Cloudflare dashboard with the administrator account, open "Zero Trust" from the menu on the left.
    07.png

  2. Open "Settings > Authentication".
    08.png

  3. Click the "Add new" button under "Login methods".
    09.png

  4. Select "SAML".
    10.png

  5. Enter any name you like in "Name", and drag and drop the metadata downloaded from TrustLogin into the drop area.
    11.png

    After dropping the metadata, confirm that the values for "Single sign-on URL", "IdP Entity ID or Issuer URL", and "Signing certificate" below have been populated automatically.
    12.png

  6. Scroll down to "SAML attributes" and add rows using "+ Add attributes". Enter "email", "firstName", and "lastName" in the three rows.
    13.png

  7. Click the "Save" button to save.

  8. Click "Test" to the right of the SAML configuration you created.
    14.png

    If "Your connection works!" is displayed, the connection test was successful.
    15.png

  9. Open "Access > Access Groups" from the menu on the left, and open "Edit" for the default group. (If no Access Group has been configured, add one using "Add a Group".)
    16.png

  10. Under "Group configuration", select "Login Methods" from the "Selector" dropdown, and check the SAML configuration you created under "Value".
    17.png

  11. Click the "Save" button to save.

  12. Open "Settings > Authentication" and click the "Manage" button under "App Launcher".
    20.png

  13. On the Rules tab, click the "Add a rule" button.
    21.png

  14. Set any name you like for "Rule Name", and set "Rule Action" to "Allow".
    Under "Assign a group", check the group you configured in step 9, and click the "Save" button to save.
    22.png

  15. Open the Authentication tab and allow the SAML configuration you set up. Please configure the details to match your organization's operational needs. (In the image below, all IdP configurations are allowed as an example.)
    Finally, click the "Save" button to save.
    23.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Cloudflare (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Cloudflare (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In to Cloudflare

  1. From TrustLogin's My Page, the browser extension app icon,
    or by opening https://<your team name>.cloudflareaccess.com/ in a browser.

  2. Click the "Login" button.
    18.png

  3. Click the SAML button you configured under "Sign in with:".
    19.png

  4. Login is complete and the App Launcher is displayed.
    24.png

Cloudflare Zero Trust (Cloudflare Access) SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Cloudflare is required.

  • Please refer to the manual provided by Cloudflare for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Cloudflare (SAML)".
    Cloudflare.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png


  4. Enter the "team name" of your Cloudflare Zero Trust instance into the three blank fields — "Login URL", "Entity ID", and "ACS URL to Service" — under "Service Provider Settings".
    The team name can be found under "Settings > General > Team domain" in Cloudflare Zero Trust.
    05.png

    04.png

  5. Click the "Register" button to save.

  6. To perform a connection test during the Cloudflare configuration in the next section, add the administrator performing this configuration as a member of the SAML app you created. In the "Admin Page > App" menu, search for the "Cloudflare (SAML)" app, and use "Add Member" to add the administrator account.
    Cloudflare02.png

Cloudflare Settings

  1. After logging in to the Cloudflare dashboard with the administrator account, open "Zero Trust" from the menu on the left.
    07.png

  2. Open "Settings > Authentication".
    08.png

  3. Click the "Add new" button under "Login methods".
    09.png

  4. Select "SAML".
    10.png

  5. Enter any name you like in "Name", and drag and drop the metadata downloaded from TrustLogin into the drop area.
    11.png

    After dropping the metadata, confirm that the values for "Single sign-on URL", "IdP Entity ID or Issuer URL", and "Signing certificate" below have been populated automatically.
    12.png

  6. Scroll down to "SAML attributes" and add rows using "+ Add attributes". Enter "email", "firstName", and "lastName" in the three rows.
    13.png

  7. Click the "Save" button to save.

  8. Click "Test" to the right of the SAML configuration you created.
    14.png

    If "Your connection works!" is displayed, the connection test was successful.
    15.png

  9. Open "Access > Access Groups" from the menu on the left, and open "Edit" for the default group. (If no Access Group has been configured, add one using "Add a Group".)
    16.png

  10. Under "Group configuration", select "Login Methods" from the "Selector" dropdown, and check the SAML configuration you created under "Value".
    17.png

  11. Click the "Save" button to save.

  12. Open "Settings > Authentication" and click the "Manage" button under "App Launcher".
    20.png

  13. On the Rules tab, click the "Add a rule" button.
    21.png

  14. Set any name you like for "Rule Name", and set "Rule Action" to "Allow".
    Under "Assign a group", check the group you configured in step 9, and click the "Save" button to save.
    22.png

  15. Open the Authentication tab and allow the SAML configuration you set up. Please configure the details to match your organization's operational needs. (In the image below, all IdP configurations are allowed as an example.)
    Finally, click the "Save" button to save.
    23.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Cloudflare (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Cloudflare (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In to Cloudflare

  1. From TrustLogin's My Page, the browser extension app icon,
    or by opening https://<your team name>.cloudflareaccess.com/ in a browser.

  2. Click the "Login" button.
    18.png

  3. Click the SAML button you configured under "Sign in with:".
    19.png

  4. Login is complete and the App Launcher is displayed.
    24.png