|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
〇 |
Email address |
|
|
Custom attribute Note: For how to configure custom attributes, click here |
||
|
SP Configuration |
〇 |
Configured by the administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Company App" screen, search for and select "Notion (SAML)".
- Download the metadata from the "Download Metadata" button under "Identity Provider Information".
- Save by clicking the "Register" button.
Notion Settings
- After logging in with an account that has workspace owner permissions, open "Settings" > "Settings" and, if a domain is set under "Allowed email domains", remove it and save.
- Open "Authentication and provisioning" and click "+Add domain" under domain management.
- Enter the domain name to verify and click "Next".
Follow the displayed instructions to configure the domain's DNS records. For instructions on how to configure DNS records, please refer to your domain registrar's help documentation. DNS record updates may take up to approximately 72 hours to propagate.
- After the DNS record has been updated, click "Verify", and a notification requesting confirmation of the DNS record will be sent to Notion. Once verification is complete, the domain's status will be displayed as "Verified".
- Configure each item of SAML Single Sign-On (SSO) as follows.
Enable SAML SSO ON Edit SAML SSO configuration Click the button and, in the window that opens,
-
Make a note of the "Assertion Consumer Service (ACS) URL" value.
-
Check "Identity provider metadata XML" under "Identity provider details", open the metadata obtained from TrustLogin in a text editor, copy its entire contents, and paste it in.
Login method Configure this according to your operational needs.
Note: Selecting "SAML SSO only" will disable login using a Notion account, etc. Please be careful when selecting this option.Automatic account creation ON
-
Make a note of the "Assertion Consumer Service (ACS) URL" value.
- Make a note of the value under "Setup information > Workspace ID".
Return to the TrustLogin admin page again.
TrustLogin Admin Page Settings (Continued)
- Resume the TrustLogin configuration.
(On the app screen in the Admin Page, search by app name → open the relevant app's detail screen → change the SAML app settings) -
Configure "Service Provider Settings" as follows.
Login URL The "Assertion Consumer Service (ACS) URL" obtained from Notion Entity ID The "Workspace ID" obtained from Notion ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Notion - Save by clicking the "Register" button.
TrustLogin User Settings
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Notion (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
②When an administrator adds members
- Search for and click the "Notion (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.