|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Provisioning via API supported (account management possible in TrustLogin) |
|
| 〇 |
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
|
|
|
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- Search on the "Register Company App" screen and select "SentinelOne (SAML)".
- Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, switch to configuring the SentinelOne side.
Do not click the "Register" button yet — open SentinelOne in a separate window.
Note: SSO cannot be configured from the Japanese-language admin screen at jp. Please use the English version.
SentinelOne Configuration
- Open "SETTINGS" > "INTEGRATIONS > SSO" in the left menu and turn the "Enable SSO" toggle ON.
Configure each item as follows.
Domain Name Enter your company's email address domain IDP redirect URL The "Identity Provider URL" obtained from TrustLogin IssuerID The "Issuer/Entity ID" obtained from TrustLogin Default role Set the role to be assigned when a new user is created IDP public certificate Upload the "certificate" obtained from TrustLogin Auto Provisioning Check this box Assertion Consumer Service URL Click "Copy" to note down the value SP Entity ID Click "Copy" to note down the value
Now return to the TrustLogin admin page again.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "SP Entity ID" obtained from SentinelOne ACS URL to Service The "Assertion Consumer Service URL" obtained from SentinelOne
- Save by clicking the "Register" button.
TrustLogin User Configuration
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "SentinelOne (SAML)", and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
②When an Administrator Adds a Member
- Search for and click the "SentinelOne (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Now return to SentinelOne.
SentinelOne Configuration (Continued)
- Click the "Test" button to run a connection test.
- If the message "SSO Test passed!" appears, the test was successful. Save by clicking the "Save" button.