| Item | Details | |
|---|---|---|
| Pre-check |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For how to configure custom attributes, see here | ||
| SP Configuration | 〇 | Configured by the administrator |
| Request SP to configure | ||
| Provisioning | API-based Provisioning supported (account management available in TrustLogin) | |
| 〇 | SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
None (accounts created in each system) |
||
| Access Method | 〇 | SP-Initiated SSO |
| IdP-Initiated SSO | ||
| Device Compatibility | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Standard Browser (Safari) | |
| ー | iOS - TrustLogin Mobile App In-App Browser | |
| 〇 | iOS - Native App | |
| 〇 | Android - Standard Browser (Chrome) | |
| ー | Android - TrustLogin Mobile App In-App Browser | |
| 〇 | Android - Native App | |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "ovice (SAML)".
- Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate from the "Get Certificate" button.
Now, switch to configuring the ovice side. Please open ovice in a separate window.
ovice Settings
- Log in with an account that has administrator privileges and click "Space Settings".
- Click "Access Permissions", then select "Email Authentication" from "Allow Access as Member".
- Open the "SSO Authentication" tab and click the + button to the right of "Register SAML Authentication".
-
On the "Edit SAML Login" screen, configure the settings as follows and click "Save".
IdP Name Any name of your choosing Note: This is the name that will be displayed on the login screen.
(e.g., GMO TrustLogin)
Entity ID The "Issuer / Entity ID" you noted down from TrustLogin IdP Login URL The "Identity Provider URL" you noted down from TrustLogin IdP Logout URL https://portal.trustlogin.com/ Redirect Destination space or lobby Note: Please select according to your company's policy. IdP x509 Certificate Open the certificate downloaded from TrustLogin and paste it in
- Note down the "Identifier", "Reply URL", and "Login URL" under "SAML settings".
-
Under "Activate SSO Authentication", check the box for the IdP name you registered.
TrustLogin Admin Page Settings (Continued)
-
Configure each item under "Service Provider Settings" with the ovice information as follows.
Login URL Enter the "Login URL" you noted down from ovice Entity ID Enter the "Identifier" you noted down from ovice ACS URL to Service Enter the "Reply URL" you noted down from ovice
- Click the "Register" button to save the settings.
-
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "ovice (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Save" button.
②When an administrator adds members
- Search for and click the "ovice (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.
How to Log in to ovice
- When logging in, if the screen below is displayed, click the IdP name you registered in ovice (in this example, GMO TrustLogin) to log in.
- A verification email will be sent to the email address registered in TrustLogin. Please check the email and complete the verification.
- Enter your ovice space domain and click "Enter Space".
Note: This is only required for the first login.
SSO Authentication Method for the Native App
- Download the ovice native app.
- Open the ovice app and select "Specify Workspace".
- Enter your ovice space domain and click "OK".
- The IdP name you registered in ovice (in this example, GMO TrustLogin) will be displayed as shown below. Click the button for the registered IdP name to log in.
- You will be redirected to the TrustLogin login screen. Log in to TrustLogin and use the app. (Note: If you are already logged in to TrustLogin, you will not be redirected to the login screen.)