SentinelOne SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in SentinelOne is required.

  • For the latest setup instructions, please check the manual provided by SentinelOne.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "SentinelOne (SAML)".
    02.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring the SentinelOne side.
Do not click the "Register" button yet — open SentinelOne in a separate window.
Note: SSO cannot be configured from the Japanese-language admin screen at jp. Please use the English version.

SentinelOne Configuration

  1. Open "SETTINGS" > "INTEGRATIONS > SSO" in the left menu and turn the "Enable SSO" toggle ON.
    Configure each item as follows.
    Domain Name Enter your company's email address domain
    IDP redirect URL The "Identity Provider URL" obtained from TrustLogin
    IssuerID The "Issuer/Entity ID" obtained from TrustLogin
    Default role Set the role to be assigned when a new user is created
    IDP public certificate Upload the "certificate" obtained from TrustLogin
    Auto Provisioning Check this box
    Assertion Consumer Service URL Click "Copy" to note down the value
    SP Entity ID Click "Copy" to note down the value

    04jit.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "SP Entity ID" obtained from SentinelOne
    ACS URL to Service The "Assertion Consumer Service URL" obtained from SentinelOne

    07.png

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "SentinelOne (SAML)", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "SentinelOne (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Now return to SentinelOne.

SentinelOne Configuration (Continued)

  1. Click the "Test" button to run a connection test.
    05.png

  2. If the message "SSO Test passed!" appears, the test was successful. Save by clicking the "Save" button.
    06.png

SentinelOne SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in SentinelOne is required.

  • For the latest setup instructions, please check the manual provided by SentinelOne.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "SentinelOne (SAML)".
    02.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring the SentinelOne side.
Do not click the "Register" button yet — open SentinelOne in a separate window.
Note: SSO cannot be configured from the Japanese-language admin screen at jp. Please use the English version.

SentinelOne Configuration

  1. Open "SETTINGS" > "INTEGRATIONS > SSO" in the left menu and turn the "Enable SSO" toggle ON.
    Configure each item as follows.
    Domain Name Enter your company's email address domain
    IDP redirect URL The "Identity Provider URL" obtained from TrustLogin
    IssuerID The "Issuer/Entity ID" obtained from TrustLogin
    Default role Set the role to be assigned when a new user is created
    IDP public certificate Upload the "certificate" obtained from TrustLogin
    Auto Provisioning Check this box
    Assertion Consumer Service URL Click "Copy" to note down the value
    SP Entity ID Click "Copy" to note down the value

    04jit.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "SP Entity ID" obtained from SentinelOne
    ACS URL to Service The "Assertion Consumer Service URL" obtained from SentinelOne

    07.png

  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "SentinelOne (SAML)", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "SentinelOne (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Now return to SentinelOne.

SentinelOne Configuration (Continued)

  1. Click the "Test" button to run a connection test.
    05.png

  2. If the message "SSO Test passed!" appears, the test was successful. Save by clicking the "Save" button.
    06.png