|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Cloudflare (SAML)".
-
Download the metadata from the "Download Metadata" button under "Identity Provider Information".
-
Enter the "team name" of your Cloudflare Zero Trust instance into the three blank fields — "Login URL", "Entity ID", and "ACS URL to Service" — under "Service Provider Settings".
The team name can be found under "Settings > General > Team domain" in Cloudflare Zero Trust.
- Click the "Register" button to save.
- To perform a connection test during the Cloudflare configuration in the next section, add the administrator performing this configuration as a member of the SAML app you created. In the "Admin Page > App" menu, search for the "Cloudflare (SAML)" app, and use "Add Member" to add the administrator account.
Cloudflare Settings
- After logging in to the Cloudflare dashboard with the administrator account, open "Zero Trust" from the menu on the left.
- Open "Settings > Authentication".
- Click the "Add new" button under "Login methods".
- Select "SAML".
- Enter any name you like in "Name", and drag and drop the metadata downloaded from TrustLogin into the drop area.
After dropping the metadata, confirm that the values for "Single sign-on URL", "IdP Entity ID or Issuer URL", and "Signing certificate" below have been populated automatically.
- Scroll down to "SAML attributes" and add rows using "+ Add attributes". Enter "email", "firstName", and "lastName" in the three rows.
- Click the "Save" button to save.
- Click "Test" to the right of the SAML configuration you created.
If "Your connection works!" is displayed, the connection test was successful.
- Open "Access > Access Groups" from the menu on the left, and open "Edit" for the default group. (If no Access Group has been configured, add one using "Add a Group".)
- Under "Group configuration", select "Login Methods" from the "Selector" dropdown, and check the SAML configuration you created under "Value".
- Click the "Save" button to save.
- Open "Settings > Authentication" and click the "Manage" button under "App Launcher".
- On the Rules tab, click the "Add a rule" button.
- Set any name you like for "Rule Name", and set "Rule Action" to "Allow".
Under "Assign a group", check the group you configured in step 9, and click the "Save" button to save.
- Open the Authentication tab and allow the SAML configuration you set up. Please configure the details to match your organization's operational needs. (In the image below, all IdP configurations are allowed as an example.)
Finally, click the "Save" button to save.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Cloudflare (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an administrator adds members
- Search for and click the "Cloudflare (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log In to Cloudflare
- From TrustLogin's My Page, the browser extension app icon,
or by opening https://<your team name>.cloudflareaccess.com/ in a browser.
- Click the "Login" button.
- Click the SAML button you configured under "Sign in with:".
- Login is complete and the App Launcher is displayed.