How to Configure SAML Authentication for Splashtop

 Item

Details 

Pre-check

  • Prior configuration in Splashtop is required.

  • You must create a Splashtop account using the same email address as TrustLogin.

  • For the latest setup steps, please refer to the manual provided by Splashtop.

Name ID

Email address

 

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Enterprise App Registration" screen, search for and select "Splashtop (SAML)".
    02.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".
    03.png

  4. Click the "Register" button to save.

 

Splashtop Settings

  1. Log in with an administrator account and open "Admin > Settings".
    04.png

  2. Click "New SSO Method" under "Team > Single Sign-On".
    05.png

  3. Configure each item of "New SSO Method" as follows.
    SSO Name Any name (e.g., TrustLogin)
    Protocol SAML2.0
    IDP Type Other
    JIT Provisioning OFF
    Metadata Upload the metadata downloaded from TrustLogin using the "Choose File" button
    Whitelisted Domain Only accounts with email addresses in whitelisted domains can be added to the SSO method. The domain must be one that you own.

    06.png

  4. You will receive an email from Splashtop to verify your domain. Follow the instructions to configure the DNS records for your domain. For instructions on configuring DNS records, please refer to your domain registrar’s help documentation.
    Until the domain is verified, the "Status" will show "Pending Activation".
    08.png

  5. Once the domain has been verified, enable the "Status" of the SSO method.
     To disable the device authentication email for the SSO method, turn "Device Authentication" OFF.
    07.png

  6. To associate users with the SSO method, open "Admin > Users".

    To associate an existing user, click the gear icon to the right of the target user to open "Change Authentication", select the configured SSO method, and save.
    09.png
    10.png

    For a new user, set the "Authentication Method" to the configured SSO method from "Invite Member", and invite the member.
    11.png
    12.png

 

TrustLogin User Configuration

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "Splashtop (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds a member

  1. In the "Admin Page > Apps" menu, search for and click the "Splashtop (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

 

How to Configure SAML Authentication for Splashtop

 Item

Details 

Pre-check

  • Prior configuration in Splashtop is required.

  • You must create a Splashtop account using the same email address as TrustLogin.

  • For the latest setup steps, please refer to the manual provided by Splashtop.

Name ID

Email address

 

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

 

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Enterprise App Registration" screen, search for and select "Splashtop (SAML)".
    02.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".
    03.png

  4. Click the "Register" button to save.

 

Splashtop Settings

  1. Log in with an administrator account and open "Admin > Settings".
    04.png

  2. Click "New SSO Method" under "Team > Single Sign-On".
    05.png

  3. Configure each item of "New SSO Method" as follows.
    SSO Name Any name (e.g., TrustLogin)
    Protocol SAML2.0
    IDP Type Other
    JIT Provisioning OFF
    Metadata Upload the metadata downloaded from TrustLogin using the "Choose File" button
    Whitelisted Domain Only accounts with email addresses in whitelisted domains can be added to the SSO method. The domain must be one that you own.

    06.png

  4. You will receive an email from Splashtop to verify your domain. Follow the instructions to configure the DNS records for your domain. For instructions on configuring DNS records, please refer to your domain registrar’s help documentation.
    Until the domain is verified, the "Status" will show "Pending Activation".
    08.png

  5. Once the domain has been verified, enable the "Status" of the SSO method.
     To disable the device authentication email for the SSO method, turn "Device Authentication" OFF.
    07.png

  6. To associate users with the SSO method, open "Admin > Users".

    To associate an existing user, click the gear icon to the right of the target user to open "Change Authentication", select the configured SSO method, and save.
    09.png
    10.png

    For a new user, set the "Authentication Method" to the configured SSO method from "Invite Member", and invite the member.
    11.png
    12.png

 

TrustLogin User Configuration

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "Splashtop (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

② When an administrator adds a member

  1. In the "Admin Page > Apps" menu, search for and click the "Splashtop (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.