|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For information on how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (provisioning; account management possible from TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported) |
||
|
〇 |
None (create accounts in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation Status by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "SentinelOne (SAML)".
- Note down the values of "IdP URL" and "Issuer/Entity ID" in "Identity Provider Information", and download the certificate using the "Get Certificate" button.
At this point, switch to configuring the SentinelOne side.
Do not click the "Register" button yet; open SentinelOne in a separate window.
Note: SSO cannot be configured from the Japanese (jp.) admin console. Please use the English version.
SentinelOne Configuration
- Open "SETTINGS" > "INTEGRATIONS > SSO" from the left menu, and switch the "Enable SSO" toggle to ON.
Configure each item as follows.
Domain Name Enter your company's email domain IDP redirect URL The "IdP URL" obtained from TrustLogin IssuerID The "Issuer/Entity ID" obtained from TrustLogin IDP public certificate Upload the "certificate" obtained from TrustLogin Auto Provisioning Uncheck this option Assertion Consumer Service URL Click "Copy" and note down the value SP Entity ID Click "Copy" and note down the value
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "SP Entity ID" obtained from SentinelOne ACS URL for the Service The "Assertion Consumer Service URL" obtained from SentinelOne
- Click the "Register" button to save.
TrustLogin User Configuration
① When Users Add the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "SentinelOne (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When the Administrator Adds Members
- In the "Admin Page > Apps" menu, search for the "SentinelOne (SAML)" app and click it.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
Return to SentinelOne again.
SentinelOne Configuration (Continued)
- Click the "Test" button to perform a connection test.
- If the message "SSO Test passed!" appears, the test was successful. Click the "Save" button to save.