How to Configure SAML Authentication for TeamViewer

Item

Details

Prerequisites

  • Prior configuration is required in TeamViewer.

  • You must create an account in TeamViewer using the same email address as TrustLogin.

  • Domain ownership is required, and SSO is only available for user accounts on a verified domain.
  • For the latest configuration steps, please refer to the manual provided by TeamViewer.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)


Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "TeamViewer (SAML)."
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

  4. Click the "Register" button to save.

TeamViewer Configuration

  1. Log in to the admin console and click "Company Management > Single Sign-On > Add First Domain."
    04.png

  2. Configure each item as shown below, then click "Next" to proceed.
    Domain The domain name to be used for SSO
    Configuration Select "Metadata XML"
    Metadata XML Use the "Choose File" button to select and upload the metadata downloaded from TrustLogin
    Options Check according to your operational needs

    05.png

  3. Email addresses, companies, and user groups set as "Excluded" can sign in using their TeamViewer password in addition to SAML SSO.
    This can also be configured later, but we recommend adding the administrator's email address here in case SAML is not configured correctly.
    06.png

  4. Click the "Create Customer Identifier" button, then copy and keep note of the string that is displayed. Click "Next" to proceed.
    07.png
    08.png

  5. Follow the displayed instructions to configure the domain's DNS records. For instructions on configuring DNS records, please refer to your domain registrar's help documentation. Since DNS record updates can take up to approximately 72 hours to take effect, click the "Skip" button once to close the window.
    09.png

  6. After the DNS records have been updated, click "Domain Verification > Start Verification."
    After clicking "Start Verification," TeamViewer will verify the record within 24 hours. If verification is not completed within 24 hours, click "Start Verification" again to retry.
    10.png

  7. Once the DNS record is verified, the domain status will change to "Verified" and SSO will become available. Click the pencil icon to the right of the domain name to open the SAML configuration screen.
    13.png

  8. Delete the value entered in "Single Logout URL" to leave it blank, then click the "Save" button to save.
    14.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Configuration (Continued)

  1. Resume the TrustLogin configuration.
    (On the Admin Page Apps screen, search for the app by name → open the corresponding app detail screen → change the SAML app settings)


  2. Enter the "Customer Identifier" obtained from TeamViewer into the field under "SAML Attribute Settings."
    11.png

  3. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. In "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "TeamViewer (SAML)," then click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "TeamViewer (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In

  • [About the First SAML Login]
    Only the first time you log in via SAML SSO, you will need to enter your TeamViewer password. Please enter your password to log in.
    12.png

    From the second time onward, you can log in by clicking the app icon on the TrustLogin My Page or browser extension, or by entering your email address from "Log in with Single Sign-On" on the TeamViewer login page.
    16.png

  • [How to Log In from the Android Native App]
    Enter only your "Email" and click the "Sign In" button. You will be redirected to the TrustLogin login screen, where you should complete authentication.
    15.png

  • [How to Log In from the iOS Native App / Desktop App]
    Click "Log in with Single Sign-On," then enter your "Email" and click the "Continue" button. You will be redirected to the TrustLogin login screen, where you should complete authentication.
    TeamViewer.png

    17.png

How to Configure SAML Authentication for TeamViewer

Item

Details

Prerequisites

  • Prior configuration is required in TeamViewer.

  • You must create an account in TeamViewer using the same email address as TrustLogin.

  • Domain ownership is required, and SSO is only available for user accounts on a verified domain.
  • For the latest configuration steps, please refer to the manual provided by TeamViewer.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)


Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "TeamViewer (SAML)."
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

  4. Click the "Register" button to save.

TeamViewer Configuration

  1. Log in to the admin console and click "Company Management > Single Sign-On > Add First Domain."
    04.png

  2. Configure each item as shown below, then click "Next" to proceed.
    Domain The domain name to be used for SSO
    Configuration Select "Metadata XML"
    Metadata XML Use the "Choose File" button to select and upload the metadata downloaded from TrustLogin
    Options Check according to your operational needs

    05.png

  3. Email addresses, companies, and user groups set as "Excluded" can sign in using their TeamViewer password in addition to SAML SSO.
    This can also be configured later, but we recommend adding the administrator's email address here in case SAML is not configured correctly.
    06.png

  4. Click the "Create Customer Identifier" button, then copy and keep note of the string that is displayed. Click "Next" to proceed.
    07.png
    08.png

  5. Follow the displayed instructions to configure the domain's DNS records. For instructions on configuring DNS records, please refer to your domain registrar's help documentation. Since DNS record updates can take up to approximately 72 hours to take effect, click the "Skip" button once to close the window.
    09.png

  6. After the DNS records have been updated, click "Domain Verification > Start Verification."
    After clicking "Start Verification," TeamViewer will verify the record within 24 hours. If verification is not completed within 24 hours, click "Start Verification" again to retry.
    10.png

  7. Once the DNS record is verified, the domain status will change to "Verified" and SSO will become available. Click the pencil icon to the right of the domain name to open the SAML configuration screen.
    13.png

  8. Delete the value entered in "Single Logout URL" to leave it blank, then click the "Save" button to save.
    14.png

Now, return to the TrustLogin Admin Page.

TrustLogin Admin Page Configuration (Continued)

  1. Resume the TrustLogin configuration.
    (On the Admin Page Apps screen, search for the app by name → open the corresponding app detail screen → change the SAML app settings)


  2. Enter the "Customer Identifier" obtained from TeamViewer into the field under "SAML Attribute Settings."
    11.png

  3. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. In "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "TeamViewer (SAML)," then click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "TeamViewer (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Log In

  • [About the First SAML Login]
    Only the first time you log in via SAML SSO, you will need to enter your TeamViewer password. Please enter your password to log in.
    12.png

    From the second time onward, you can log in by clicking the app icon on the TrustLogin My Page or browser extension, or by entering your email address from "Log in with Single Sign-On" on the TeamViewer login page.
    16.png

  • [How to Log In from the Android Native App]
    Enter only your "Email" and click the "Sign In" button. You will be redirected to the TrustLogin login screen, where you should complete authentication.
    15.png

  • [How to Log In from the iOS Native App / Desktop App]
    Click "Log in with Single Sign-On," then enter your "Email" and click the "Continue" button. You will be redirected to the TrustLogin login screen, where you should complete authentication.
    TeamViewer.png

    17.png