Amazon Cognito (Supports SP-Initiated SSO) SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Amazon Cognito is required.

  • Please refer to the manual provided by Amazon for the latest configuration steps.

  • For the manual on IdP-Initiated SSO support, please see here.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users to whom the administrator has assigned the SAML app
Password users and external provider users are distinguished from each other

Notes

None in particular

※ Under verification

Table of Contents:

TrustLogin Admin Page Settings

Amazon Cognito Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Login Method and User Information

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Amazon Cognito (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring Amazon Cognito.
Do not click the "Register" button yet — open the Amazon Cognito console in a separate tab.

Amazon Cognito Settings

  1. [Create a user pool]
    Note: If you have already created one, proceed to step 3.
    Open the Amazon Cognito console and create a user pool. For detailed steps on creating a user pool, please refer to the Amazon manual.
    04new.png

  2. Configure each item as follows, and click "Create user directory".
    Application type Select the application type
    Name your application Any application name
    Options for sign-in identifiers Email address
    Required attributes for sign-up Add "email", "family_name", and "given_name" from the dropdown
    Return URL (optional) Set the return URL

    05.png

  3. [Disable self-registration]
    Click the name of the user pool you created from the user pool list, and open "Sign-up" > edit "Self-service sign-up".
    11.png

    12.png

  4. Uncheck "Enable self-registration" and save the changes.
    13.png

  5. [Configure external provider]
    Open "Social and external providers" and click "Add identity provider".
    07.png

  6. Configure each item as follows and click "Add identity provider".
    Federated sign-in options Select SAML
    Provider name Set any name you like
    Note: This will become the button label for the SSO login button on the login page.
    IdP-initiated SAML sign-in
    Select "SP-initiated SAML assertion is required"
    Metadata document Select "Upload metadata document" and upload the metadata downloaded from TrustLogin
    Map attributes between the SAML provider and your user pool

    For each corresponding user pool attribute on the left, enter "email", "family_name", and "given_name" in the "SAML attribute" field on the right


    08.png

  7. [Add a SAML SSO button to the login page]
    Open "App clients" and open the link for the application client name.
    14.png

  8. Open the "Login pages" tab and open "Edit" under "Managed login pages configuration".
    15.png

  9. From the "Identity providers" dropdown under "Identity providers", check the identity provider you configured to add it.
    Save the settings with the "Save changes" button in the bottom right.
    16.png

    17.png

    Note: You can restrict the login method to SAML SSO only by deleting the "Cognito user pool". If you want to restrict it, we recommend switching over only after all configuration is complete and you have confirmed that the SAML SSO connection works.

  10. [Obtain the information to configure in TrustLogin]

    ① User pool ID
    Return to the user pool's top page and note down the value of "User pool ID".
    18.png

    ② Login page URL
    Open the application client's detail screen from "App clients" and obtain the URL of the login page opened by "View login page".
    25.png

    ③ Domain
    Open "Domain" and note down the value of "Domain" (the Cognito domain or custom domain).
    19.png

Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL

    The "② Login page URL" obtained from Amazon Cognito

    Redirect URL after successful SP authentication Leave blank
    Entity ID The "① User pool ID" obtained from Amazon Cognito
    ACS URL to Service The "③ Domain" obtained from Amazon Cognito

    19.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by an administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Amazon Cognito (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Amazon Cognito (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method and User Information

  • Clicking the "Amazon Cognito (SAML)" app from My Page or the browser extension will take you to the login screen.
    Click the "Continue with (the identity provider name you configured)" button to complete authentication.
    21.png

  • The verification status of users who logged in via SAML SSO is displayed as "External Provider". Even with the same email address, these are distinguished from users created by the administrator.
    20.png

Amazon Cognito (Supports SP-Initiated SSO) SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Amazon Cognito is required.

  • Please refer to the manual provided by Amazon for the latest configuration steps.

  • For the manual on IdP-Initiated SSO support, please see here.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users to whom the administrator has assigned the SAML app
Password users and external provider users are distinguished from each other

Notes

None in particular

※ Under verification

Table of Contents:

TrustLogin Admin Page Settings

Amazon Cognito Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Login Method and User Information

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Amazon Cognito (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring Amazon Cognito.
Do not click the "Register" button yet — open the Amazon Cognito console in a separate tab.

Amazon Cognito Settings

  1. [Create a user pool]
    Note: If you have already created one, proceed to step 3.
    Open the Amazon Cognito console and create a user pool. For detailed steps on creating a user pool, please refer to the Amazon manual.
    04new.png

  2. Configure each item as follows, and click "Create user directory".
    Application type Select the application type
    Name your application Any application name
    Options for sign-in identifiers Email address
    Required attributes for sign-up Add "email", "family_name", and "given_name" from the dropdown
    Return URL (optional) Set the return URL

    05.png

  3. [Disable self-registration]
    Click the name of the user pool you created from the user pool list, and open "Sign-up" > edit "Self-service sign-up".
    11.png

    12.png

  4. Uncheck "Enable self-registration" and save the changes.
    13.png

  5. [Configure external provider]
    Open "Social and external providers" and click "Add identity provider".
    07.png

  6. Configure each item as follows and click "Add identity provider".
    Federated sign-in options Select SAML
    Provider name Set any name you like
    Note: This will become the button label for the SSO login button on the login page.
    IdP-initiated SAML sign-in
    Select "SP-initiated SAML assertion is required"
    Metadata document Select "Upload metadata document" and upload the metadata downloaded from TrustLogin
    Map attributes between the SAML provider and your user pool

    For each corresponding user pool attribute on the left, enter "email", "family_name", and "given_name" in the "SAML attribute" field on the right


    08.png

  7. [Add a SAML SSO button to the login page]
    Open "App clients" and open the link for the application client name.
    14.png

  8. Open the "Login pages" tab and open "Edit" under "Managed login pages configuration".
    15.png

  9. From the "Identity providers" dropdown under "Identity providers", check the identity provider you configured to add it.
    Save the settings with the "Save changes" button in the bottom right.
    16.png

    17.png

    Note: You can restrict the login method to SAML SSO only by deleting the "Cognito user pool". If you want to restrict it, we recommend switching over only after all configuration is complete and you have confirmed that the SAML SSO connection works.

  10. [Obtain the information to configure in TrustLogin]

    ① User pool ID
    Return to the user pool's top page and note down the value of "User pool ID".
    18.png

    ② Login page URL
    Open the application client's detail screen from "App clients" and obtain the URL of the login page opened by "View login page".
    25.png

    ③ Domain
    Open "Domain" and note down the value of "Domain" (the Cognito domain or custom domain).
    19.png

Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL

    The "② Login page URL" obtained from Amazon Cognito

    Redirect URL after successful SP authentication Leave blank
    Entity ID The "① User pool ID" obtained from Amazon Cognito
    ACS URL to Service The "③ Domain" obtained from Amazon Cognito

    19.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by an administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Amazon Cognito (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Amazon Cognito (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method and User Information

  • Clicking the "Amazon Cognito (SAML)" app from My Page or the browser extension will take you to the login screen.
    Click the "Continue with (the identity provider name you configured)" button to complete authentication.
    21.png

  • The verification status of users who logged in via SAML SSO is displayed as "External Provider". Even with the same email address, these are distinguished from users created by the administrator.
    20.png