How to Configure SAML Authentication for Veeam Backup Enterprise Manager

Item

Details

Prerequisites

  • Advance configuration is required in Veeam Backup Enterprise Manager (hereafter "Enterprise Manager").

  • For the latest configuration steps, please check the manual provided by Veeam.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Enterprise App" screen, search and select "Veeam Backup Enterprise Manager (SAML)."
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

Now, switch to the settings on the Enterprise Manager side.
Do not click the "Register" button yet — open Enterprise Manager instead.

Enterprise Manager Settings

  1. Open "Settings" in the upper right.
    04.png

  2. Open "Settings > SAML Authentication" and check "Enable SAML 2.0."
    Using "Import from file," import the metadata downloaded from TrustLogin, and confirm that the values have been loaded into the provider settings.
    06.png
    05.png

  3. Download the metadata from "Download" next to "Veeam Backup Enterprise Manager." Finally, click the "Save" button to save.
    07.png

  4. Configure the SSO user settings.
    Open "Permissions" and click "Add."
    08.png

  5. Configure as follows and click the "OK" button to add.
    Account type Select "External user"
    Account

    The same email address as in TrustLogin

    Role Select the role to assign

    Veeam-Backup-Enterprise-Manager.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (continued)

  1. Under "Service Provider Settings," use "Select Metadata" to upload the metadata obtained from Enterprise Manager.
    09.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Veeam Backup Enterprise Manager (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Veeam Backup Enterprise Manager (SAML)" app.
  2. Click "Add Member," select the user(s) to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Veeam Backup Enterprise Manager

Item

Details

Prerequisites

  • Advance configuration is required in Veeam Backup Enterprise Manager (hereafter "Enterprise Manager").

  • For the latest configuration steps, please check the manual provided by Veeam.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-side settings

Configured by the administrator

Request the SP to configure

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Standard browser (Safari)

iOS - TrustLogin mobile app internal browser

iOS - Native app

Android - Standard browser (Chrome)

Android - TrustLogin mobile app internal browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Enterprise App" screen, search and select "Veeam Backup Enterprise Manager (SAML)."
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information."
    03.png

Now, switch to the settings on the Enterprise Manager side.
Do not click the "Register" button yet — open Enterprise Manager instead.

Enterprise Manager Settings

  1. Open "Settings" in the upper right.
    04.png

  2. Open "Settings > SAML Authentication" and check "Enable SAML 2.0."
    Using "Import from file," import the metadata downloaded from TrustLogin, and confirm that the values have been loaded into the provider settings.
    06.png
    05.png

  3. Download the metadata from "Download" next to "Veeam Backup Enterprise Manager." Finally, click the "Save" button to save.
    07.png

  4. Configure the SSO user settings.
    Open "Permissions" and click "Add."
    08.png

  5. Configure as follows and click the "OK" button to add.
    Account type Select "External user"
    Account

    The same email address as in TrustLogin

    Role Select the role to assign

    Veeam-Backup-Enterprise-Manager.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (continued)

  1. Under "Service Provider Settings," use "Select Metadata" to upload the metadata obtained from Enterprise Manager.
    09.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Veeam Backup Enterprise Manager (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Veeam Backup Enterprise Manager (SAML)" app.
  2. Click "Add Member," select the user(s) to add from the member list, and click the "Register" button to add them.