|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, click here |
||
|
SP-side settings |
〇 |
Configured by the administrator |
|
Request the SP to configure |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed in TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation status by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
ー |
Android - Native app |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Enterprise App" screen, search and select "Jamf Pro (SAML)."
- Download the metadata from the "Download Metadata" button under "Identity Provider Information."
-
Configure the "Service Provider Settings" as follows.
Redirect URL after successful SP authentication If you want users to be redirected to the Jamf Pro profile distribution screen after SSO login, enter "https://xxxxxx.jamfcloud.com/enroll".
Note: "xxxxxx" is your Jamf Pro subdomain name.
Note: This is an optional setting item. Leave it blank if you want users to be redirected to the dashboard screen.
Entity ID Enter your Jamf Pro subdomain name.
Note: If your Jamf Pro URL is "https://xxxxxx.jamfcloud.com", enter "xxxxxx".ACS URL for service Enter your Jamf Pro subdomain name.
- Click the "Register" button to save.
Jamf Pro Settings
- Open "Settings (gear icon in the upper right) > Single Sign-On."
- After clicking "Edit," switch the Single Sign-On Authentication toggle to ON.
- Configure each item as follows, then click the "Save" button to save.
Note: Do not check the optional "Enable Single Sign-On for User Enrollment."Failover Login URL This is the URL that allows you to log in with your Jamf Pro ID/password even after SAML SSO is enabled, so copy it and keep it for your records.
Identity Provider Select "Other..." Identity Provider Metadata Source Select "Metadata File," then drag the metadata downloaded from TrustLogin into the dotted box, or upload it by browsing for the file Override Token Expiration Specify any time (in minutes) according to your operational needs Identity Provider User Mapping Select "NameID" Jamf Pro User Mapping Select "Email" Identity Provider Group Attribute Name Enter "groups"
TrustLogin User Settings
① When a User Adds the App from My Page
- On "My Page," click the "Add App" button.
- On the "Register App" screen, select "Jamf Pro (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "Jamf Pro (SAML)" app.
- Click "Add Member," select the user(s) to add from the member list, and click the "Register" button to add them.