How to Configure SAML Authentication for Datadog

Item

Details

Prerequisites

  • Prior configuration in Datadog is required.

  • You must create an account in Datadog using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Datadog.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request the configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on configuring provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser (Note)

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser (Note)

Android - Native App

Note: Login itself will occur in the internal browser of the TrustLogin mobile app; however, because the internal browser is not supported by Datadog, it may not function correctly.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Datadog (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, let's move on to the configuration on the Datadog side.
Do not click the "Register" button yet; open Datadog in a separate window.

Datadog Configuration

  1. Log in to Datadog, open "Organization Settings" from the icon in the lower left, and click the "Configure" button under "Login Methods > SAML".
    04.png

  2. Use the "Choose File" button to select the metadata you downloaded from TrustLogin, then click the "Upload and Enable" button.
    05.png

  3. Open the SAML settings screen again and check "Identity Provider (IdP) Initiated Login".
    Make a note of the "Single Sign-on URL", "Service Provider Entity ID", and "Assertion Consumer Service URL" (2 of them) respectively.
    Save the settings by clicking the "Save Changes" button.
    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Single Sign-on URL" obtained from Datadog
    Entity ID The "Service Provider Entity ID" obtained from Datadog
    ACS URL for the Service The "Assertion Consumer Service URL" obtained from Datadog
    Enter both of the two values on separate lines. The order does not matter.

    07.png

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Datadog (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the "Datadog (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In from the Datadog Mobile App

  1. Log in to the TrustLogin mobile app in advance.

  2. Open the mobile app, select your region, and click the "Sign In" button.
    08.png

  3. Click "Using Single Sign-On (SAML)?".
    On the next screen, enter your email address and send it by clicking "Send email".
    09.png 10.png

  4. You will receive an email containing the login URL at your email address; open the "Mobile Login" link on your mobile device. Login is completed when you click the "Authorize" button in the mobile app.
    11.png


How to Configure SAML Authentication for Datadog

Item

Details

Prerequisites

  • Prior configuration in Datadog is required.

  • You must create an account in Datadog using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by Datadog.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request the configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For instructions on configuring provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser (Note)

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser (Note)

Android - Native App

Note: Login itself will occur in the internal browser of the TrustLogin mobile app; however, because the internal browser is not supported by Datadog, it may not function correctly.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Datadog (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, let's move on to the configuration on the Datadog side.
Do not click the "Register" button yet; open Datadog in a separate window.

Datadog Configuration

  1. Log in to Datadog, open "Organization Settings" from the icon in the lower left, and click the "Configure" button under "Login Methods > SAML".
    04.png

  2. Use the "Choose File" button to select the metadata you downloaded from TrustLogin, then click the "Upload and Enable" button.
    05.png

  3. Open the SAML settings screen again and check "Identity Provider (IdP) Initiated Login".
    Make a note of the "Single Sign-on URL", "Service Provider Entity ID", and "Assertion Consumer Service URL" (2 of them) respectively.
    Save the settings by clicking the "Save Changes" button.
    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Single Sign-on URL" obtained from Datadog
    Entity ID The "Service Provider Entity ID" obtained from Datadog
    ACS URL for the Service The "Assertion Consumer Service URL" obtained from Datadog
    Enter both of the two values on separate lines. The order does not matter.

    07.png

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Datadog (SAML)" on the "Register App" screen, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. Search for and click the "Datadog (SAML)" app in the "Admin Page > Apps" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Log In from the Datadog Mobile App

  1. Log in to the TrustLogin mobile app in advance.

  2. Open the mobile app, select your region, and click the "Sign In" button.
    08.png

  3. Click "Using Single Sign-On (SAML)?".
    On the next screen, enter your email address and send it by clicking "Send email".
    09.png 10.png

  4. You will receive an email containing the login URL at your email address; open the "Mobile Login" link on your mobile device. Login is completed when you click the "Authorize" button in the mobile app.
    11.png