|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
※ |
iOS - Default Browser (Safari) |
|
|
※ |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
※ |
Android - Default Browser (Chrome) |
|
|
※ |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
|
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled only for users to whom the administrator has assigned the SAML app |
|
|
Notes |
None in particular |
|
※ Under verification
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Amazon Cognito (SAML)".
-
Download the metadata from the "Download Metadata" button under "Identity Provider Information".
Now, switch to configuring Amazon Cognito.
Do not click the "Register" button yet — open the Amazon Cognito console in a separate tab.
Amazon Cognito Settings
- [Create a user pool]
Note: If you have already created one, proceed to step 3.
Open the Amazon Cognito console and create a user pool. For detailed steps on creating a user pool, please refer to the Amazon manual.
- Configure each item as follows, and click "Create user directory".
Application type Select the application type Name your application Any application name Options for sign-in identifiers Email address Required attributes for sign-up Add "email", "family_name", and "given_name" from the dropdown Return URL (optional) Set the return URL
- [Disable self-registration]
Click the name of the user pool you created from the user pool list, and open "Sign-up" > edit "Self-service sign-up".
- Uncheck "Enable self-registration" and save the changes.
- [Configure external provider]
Open "Social and external providers" and click "Add identity provider".
- Configure each item as follows and click "Add identity provider".
Federated sign-in options Select SAML Provider name Set any name you like
Note: This will become the button label for the SSO login button on the login page.IdP-initiated SAML sign-in Select "SP-initiated SAML assertion is required" Metadata document Select "Upload metadata document" and upload the metadata downloaded from TrustLogin Map attributes between the SAML provider and your user pool For each corresponding user pool attribute on the left, enter "email", "family_name", and "given_name" in the "SAML attribute" field on the right
- [Add a SAML SSO button to the login page]
Open "App clients" and open the link for the application client name.
- Open the "Login pages" tab and open "Edit" under "Managed login pages configuration".
- From the "Identity providers" dropdown under "Identity providers", check the identity provider you configured to add it.
Save the settings with the "Save changes" button in the bottom right.
Note: You can restrict the login method to SAML SSO only by deleting the "Cognito user pool". If you want to restrict it, we recommend switching over only after all configuration is complete and you have confirmed that the SAML SSO connection works.
- [Obtain the information to configure in TrustLogin]
① User pool ID
Return to the user pool's top page and note down the value of "User pool ID".
② Login page URL
Open the application client's detail screen from "App clients" and obtain the URL of the login page opened by "View login page".
③ Domain
Open "Domain" and note down the value of "Domain" (the Cognito domain or custom domain).
Now return to the TrustLogin settings again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Login URL The "② Login page URL" obtained from Amazon Cognito
Redirect URL after successful SP authentication Leave blank Entity ID The "① User pool ID" obtained from Amazon Cognito ACS URL to Service The "③ Domain" obtained from Amazon Cognito
- Click the "Register" button to save.
TrustLogin User Settings
① When a user adds the app from My Page
Note: The SAML app must be configured by an administrator in advance.
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Amazon Cognito (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an administrator adds members
- Search for and click the "Amazon Cognito (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Login Method and User Information
- Clicking the "Amazon Cognito (SAML)" app from My Page or the browser extension will take you to the login screen.
Click the "Continue with (the identity provider name you configured)" button to complete authentication.
- The verification status of users who logged in via SAML SSO is displayed as "External Provider". Even with the same email address, these are distinguished from users created by the administrator.