How to Configure SAML Authentication for the IceWall MFA SAML Authentication Option

Item

Details

Prior Confirmation

  • The IceWall MFA SAML Authentication Option requires prior configuration.

  • You need to create an account on the IceWall MFA SAML Authentication Option using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by the IceWall MFA SAML Authentication Option.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "IceWall MFA SAML Authentication Option (SAML)".
    IceWall01.png

  3. Under Identity Provider Information, obtain the metadata from "Download Metadata", then save the app configuration by clicking the "Register" button.
    03.png

  4. Send the following information to your IceWall MFA SAML Authentication Option representative and request SAML configuration.
    Metadata The "metadata" downloaded from TrustLogin

    NameID

    Email address


  5. When you receive notice from the IceWall MFA SAML Authentication Option that their configuration is complete, resume the configuration.
    (On the App screen of the Admin Page, search for the app by name → open the corresponding app's detail screen → change the SAML app settings)

  6. Configure "Service Provider Settings" as follows.
    Login URL The "Access URL" sent by the IceWall MFA SAML Authentication Option
    Entity ID The "Identifier (Entity ID)" sent by the IceWall MFA SAML Authentication Option
    ACS URL for the service The "Assertion Consumer Service URL" sent by the IceWall MFA SAML Authentication Option

    IceWall_MFA02.png

  7. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "IceWall MFA SAML Authentication Option (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "IceWall MFA SAML Authentication Option (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for the IceWall MFA SAML Authentication Option

Item

Details

Prior Confirmation

  • The IceWall MFA SAML Authentication Option requires prior configuration.

  • You need to create an account on the IceWall MFA SAML Authentication Option using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by the IceWall MFA SAML Authentication Option.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "IceWall MFA SAML Authentication Option (SAML)".
    IceWall01.png

  3. Under Identity Provider Information, obtain the metadata from "Download Metadata", then save the app configuration by clicking the "Register" button.
    03.png

  4. Send the following information to your IceWall MFA SAML Authentication Option representative and request SAML configuration.
    Metadata The "metadata" downloaded from TrustLogin

    NameID

    Email address


  5. When you receive notice from the IceWall MFA SAML Authentication Option that their configuration is complete, resume the configuration.
    (On the App screen of the Admin Page, search for the app by name → open the corresponding app's detail screen → change the SAML app settings)

  6. Configure "Service Provider Settings" as follows.
    Login URL The "Access URL" sent by the IceWall MFA SAML Authentication Option
    Entity ID The "Identifier (Entity ID)" sent by the IceWall MFA SAML Authentication Option
    ACS URL for the service The "Assertion Consumer Service URL" sent by the IceWall MFA SAML Authentication Option

    IceWall_MFA02.png

  7. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "IceWall MFA SAML Authentication Option (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "IceWall MFA SAML Authentication Option (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.