How to Configure SAML Authentication for HRMOS Expense

Item

Details

Pre-check

  • Prior setup in HRMOS Expense is required.

  • You must set your TrustLogin email address in the "SSO ID" field of the user information in HRMOS Expense.

  • For the latest setup instructions, please refer to the manual provided by HRMOS Expense.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request the SP to configure the settings

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App


Preparation

  1. Log in to HRMOS Expense, open "Users > Master", and open the personal information screen of the user who will use single sign-on.

  2. Set your TrustLogin email address in "SSO ID" and click the "Register" button to save.
    00.png

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Corporate App Registration" screen, search and select "HRMOS Expense (SAML)".
    02.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".
    03.png

At this point, move on to the settings on the HRMOS Expense side.
Do not click the "Register" button; open HRMOS Expense in a separate window.

HRMOS Expense Settings

  1. Open "Admin > SAML Authentication".
    04.png

  2. Click the "Export Metadata" button to obtain the metadata.
    Use the "Import Metadata" button to import the metadata downloaded from TrustLogin.
    05.png

  3. Confirm that values have been automatically inserted into the "SSO URL" and "Certificate" fields of the IdP settings, then click the "Register" button to save.
    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Using the "Select Metadata" button under "Service Provider Settings", upload the metadata obtained from HRMOS Expense.
    07.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app via My Page

  1. On "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "HRMOS Expense (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. In the "Admin Page > Apps" menu, search for and click the "HRMOS Expense (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for HRMOS Expense

Item

Details

Pre-check

  • Prior setup in HRMOS Expense is required.

  • You must set your TrustLogin email address in the "SSO ID" field of the user information in HRMOS Expense.

  • For the latest setup instructions, please refer to the manual provided by HRMOS Expense.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Configuration

Configured by the administrator

Request the SP to configure the settings

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App


Preparation

  1. Log in to HRMOS Expense, open "Users > Master", and open the personal information screen of the user who will use single sign-on.

  2. Set your TrustLogin email address in "SSO ID" and click the "Register" button to save.
    00.png

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Corporate App Registration" screen, search and select "HRMOS Expense (SAML)".
    02.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".
    03.png

At this point, move on to the settings on the HRMOS Expense side.
Do not click the "Register" button; open HRMOS Expense in a separate window.

HRMOS Expense Settings

  1. Open "Admin > SAML Authentication".
    04.png

  2. Click the "Export Metadata" button to obtain the metadata.
    Use the "Import Metadata" button to import the metadata downloaded from TrustLogin.
    05.png

  3. Confirm that values have been automatically inserted into the "SSO URL" and "Certificate" fields of the IdP settings, then click the "Register" button to save.
    06.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Using the "Select Metadata" button under "Service Provider Settings", upload the metadata obtained from HRMOS Expense.
    07.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a user adds the app via My Page

  1. On "My Page", click the "Add App" button.
  2. On the "App Registration" screen, select "HRMOS Expense (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. In the "Admin Page > Apps" menu, search for and click the "HRMOS Expense (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.