|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
| ※1 |
Custom attribute Note: For instructions on configuring custom attributes, see here |
|
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (accounts can be managed from TrustLogin) |
|
|
Supports SAML JIT provisioning (accounts can be managed from TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation status by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Standard browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app internal browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Standard browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app internal browser |
|
|
ー |
Android - Native app |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search and select "Phrase Suite (SAML)".
-
Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information," then download the certificate using the "Get Certificate" button.
Now, switch to configuring the Phrase Suite side.
Do not click the "Register" button yet — open Phrase Suite in a separate window.
Phrase Suite Configuration
- From the icon at the top right, open "Settings > Organization".
- Open the "SSO" tab and click "Enable SSO".
- Configure each item as follows, and finally save by clicking the "Save" button.
SAML metadata Download using the "Download Metadata" button Require users to sign in with SSO We recommend leaving this off during setup and testing.
If you want SAML SSO to be the only login method, switch it ON when going live.GUID (Globally Unique Identifier) Specify any string (e.g., company name)
(Used when logging in via SSO from the Phrase Suite login page)Identifier type Email address Login URL The "IdP URL" obtained from TrustLogin Issuer URL The "Issuer / Entity ID" obtained from TrustLogin Certificate Select "I have an Identity Provider certificate" and upload the certificate obtained from TrustLogin using the "Upload Certificate" button
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Configuration (Continued)
- Upload the metadata downloaded from Phrase Suite to the "Metadata" field under "Service Provider Settings".
Note 1: Steps for configuring "Name ID" when multiple users exist in Suite with the same email addressIf multiple users exist in Phrase Suite with the same email address (i.e., the email addresses of TMS and Strings users overlap but the usernames differ), you can log in to Suite via SSO by setting the username in a custom attribute.
If you do not configure the custom attribute, the email address will not be a unique value, and you will not be able to log in to Suite via SSO.
Set either the TMS or Strings username as the custom attribute.
[TrustLogin Custom Attribute Configuration Example]
Note: The attribute name can be anything.
For configuration instructions, please refer to the pages below.
- Custom Attribute Configuration (Individual Registration)
-
Custom Attribute Configuration (Bulk Registration)
In that case, also set the "Value for Name ID" as the custom attribute.
2. Save by clicking the "Register" button.
TrustLogin User Configuration
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Phrase Suite (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name," enter it, then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "Phrase Suite (SAML)" app.
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.