How to Configure SAML Authentication for SentinelOne

Item

Details

Prior Confirmation

  • Prior configuration on the SentinelOne side is required.

  • You must create an account on SentinelOne using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by SentinelOne.

Name ID

Email address

Custom attribute Note: For information on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (provisioning; account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (create accounts in each system)
Note: For configuration steps when using provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "SentinelOne (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" in "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to configuring the SentinelOne side.
Do not click the "Register" button yet; open SentinelOne in a separate window.
Note: SSO cannot be configured from the Japanese (jp.) admin console. Please use the English version.

SentinelOne Configuration

  1. Open "SETTINGS" > "INTEGRATIONS > SSO" from the left menu, and switch the "Enable SSO" toggle to ON.
    Configure each item as follows.
    Domain Name Enter your company's email domain
    IDP redirect URL The "IdP URL" obtained from TrustLogin
    IssuerID The "Issuer/Entity ID" obtained from TrustLogin
    IDP public certificate Upload the "certificate" obtained from TrustLogin
    Auto Provisioning Uncheck this option
    Assertion Consumer Service URL Click "Copy" and note down the value
    SP Entity ID Click "Copy" and note down the value

    04.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "SP Entity ID" obtained from SentinelOne
    ACS URL for the Service The "Assertion Consumer Service URL" obtained from SentinelOne

    07.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When Users Add the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "SentinelOne (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When the Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for the "SentinelOne (SAML)" app and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

Return to SentinelOne again.

SentinelOne Configuration (Continued)

  1. Click the "Test" button to perform a connection test.
    05.png

  2. If the message "SSO Test passed!" appears, the test was successful. Click the "Save" button to save.
    06.png

How to Configure SAML Authentication for SentinelOne

Item

Details

Prior Confirmation

  • Prior configuration on the SentinelOne side is required.

  • You must create an account on SentinelOne using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by SentinelOne.

Name ID

Email address

Custom attribute Note: For information on how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (provisioning; account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (create accounts in each system)
Note: For configuration steps when using provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "SentinelOne (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer/Entity ID" in "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

At this point, switch to configuring the SentinelOne side.
Do not click the "Register" button yet; open SentinelOne in a separate window.
Note: SSO cannot be configured from the Japanese (jp.) admin console. Please use the English version.

SentinelOne Configuration

  1. Open "SETTINGS" > "INTEGRATIONS > SSO" from the left menu, and switch the "Enable SSO" toggle to ON.
    Configure each item as follows.
    Domain Name Enter your company's email domain
    IDP redirect URL The "IdP URL" obtained from TrustLogin
    IssuerID The "Issuer/Entity ID" obtained from TrustLogin
    IDP public certificate Upload the "certificate" obtained from TrustLogin
    Auto Provisioning Uncheck this option
    Assertion Consumer Service URL Click "Copy" and note down the value
    SP Entity ID Click "Copy" and note down the value

    04.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "SP Entity ID" obtained from SentinelOne
    ACS URL for the Service The "Assertion Consumer Service URL" obtained from SentinelOne

    07.png

  2. Click the "Register" button to save.

TrustLogin User Configuration

① When Users Add the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "SentinelOne (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When the Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for the "SentinelOne (SAML)" app and click it.
  2. Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.

Return to SentinelOne again.

SentinelOne Configuration (Continued)

  1. Click the "Test" button to perform a connection test.
    05.png

  2. If the message "SSO Test passed!" appears, the test was successful. Click the "Save" button to save.
    06.png