Rapid7 SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Rapid7 is required.

  • The user's first and last name are synced only when a new account is created through provisioning.
  • For the latest setup instructions, please check the manual provided by Rapid7.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

Only if you want to automatically assign users to a Rapid7 group, perform the following prerequisite setup.
Create groups with the same name in both Rapid7 and TrustLogin.

[Configuration Example]
The following is an example for illustration purposes. Please configure group names and assigned products/roles to match your own operational needs.

  1. Configure groups in Rapid7. (User Management > User Groups)
    Create the groups "Admin" and "Viewer" and assign a product and role to each.
    001.png

  2. Also create groups named "Admin" and "Viewer" in TrustLogin and assign members to them.
    For instructions on how to register groups and assign members, please refer to the following page.
    Register a Group
    002.png

With this configuration, when a user belonging to the "Admin" group in TrustLogin performs SAML login to Rapid7, they will automatically become a member of the "Admin" group and be assigned the configured product and role.


TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    Rapid7.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring the Rapid7 side.
Do not click the "Register" button yet — open Rapid7 in a separate window.

Rapid7 Configuration

  1. Open the "Data management" icon at the top right > "Agents".
    04.png

  2. Open the "Settings" icon in the left menu > "SSO Settings", and configure each item as follows.
    Select your Identity Provider (IdP) Select "Other"
    Add your IdP Certificate

    Drag and drop the "certificate" obtained from TrustLogin into the box, or upload it using the "Browse" button

    Assertion Consumer Service (ACS) URL Copy the value using the "Copy" button on the right
    Audience (EntityID) Copy the value using the "Copy" button on the right
    Relay State Copy the value using the "Copy" button on the right
    Entity ID The "Issuer/Entity ID" obtained from TrustLogin
    Single Sign-On Service URL The "Identity Provider URL" obtained from TrustLogin

    05 (3).png

  3. Configure "Set Up Default Access Profile".
    This lets you define the product and role that will automatically be assigned to newly provisioned users.
    For detailed steps, please see here.
    06.png

  4. Configure "Synchronize IdP Groups with User Groups".
    If you want to automatically assign users to a Rapid7 group Select "IdP group synchronization active"
    If you do not want to automatically assign users to a Rapid7 group Select "IdP group synchronization inactive"

    07.png

  5. Save your settings by clicking the "Submit and turn on SSO" button.

  • Even after enabling SSO, existing "local users" can still log in to Rapid7 with an ID/password. However, once a user authenticates via SSO, they become an "IdP user" and can no longer log in with an ID/password afterward. Please be aware of this.
  • An IdP user cannot be reverted to a local user.
  • For this reason, we recommend keeping at least one local user as a platform administrator user.

    IdP users and local users can be distinguished by the badge shown in the user list.
    11.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication The "Relay State" obtained from Rapid7
    Value for Name ID "Member" > "email"
    Entity ID The "Audience (EntityID)" obtained from Rapid7
    Name ID Format "Unspecified"
    ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Rapid7

    08.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button. Configure each row as follows.

    The Group row only needs to be configured if you want to automatically assign users to a group.
    Select the group name for the group attribute value from the dropdown; you can add multiple groups using the "+" mark on the right.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    FirstName Unspecified FirstName

    Member

    Member - First Name

    LastName Unspecified LastName

    Member

    Member - Last Name

    Email Unspecified Email

    Member

    Member - Email Address

    rbacGroups Unspecified rbacGroups

    Group

    Select the configured group name and add all of them using the "+" button


    [When automatically assigning users to a group]
    09.png


    [When not automatically assigning users to a group]
    10.png


  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Rapid7 SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Rapid7 is required.

  • The user's first and last name are synced only when a new account is created through provisioning.
  • For the latest setup instructions, please check the manual provided by Rapid7.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

Only if you want to automatically assign users to a Rapid7 group, perform the following prerequisite setup.
Create groups with the same name in both Rapid7 and TrustLogin.

[Configuration Example]
The following is an example for illustration purposes. Please configure group names and assigned products/roles to match your own operational needs.

  1. Configure groups in Rapid7. (User Management > User Groups)
    Create the groups "Admin" and "Viewer" and assign a product and role to each.
    001.png

  2. Also create groups named "Admin" and "Viewer" in TrustLogin and assign members to them.
    For instructions on how to register groups and assign members, please refer to the following page.
    Register a Group
    002.png

With this configuration, when a user belonging to the "Admin" group in TrustLogin performs SAML login to Rapid7, they will automatically become a member of the "Admin" group and be assigned the configured product and role.


TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png

  2. Configure the "Application Name" and "Icon" (optional).
    Rapid7.png

  3. Note the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring the Rapid7 side.
Do not click the "Register" button yet — open Rapid7 in a separate window.

Rapid7 Configuration

  1. Open the "Data management" icon at the top right > "Agents".
    04.png

  2. Open the "Settings" icon in the left menu > "SSO Settings", and configure each item as follows.
    Select your Identity Provider (IdP) Select "Other"
    Add your IdP Certificate

    Drag and drop the "certificate" obtained from TrustLogin into the box, or upload it using the "Browse" button

    Assertion Consumer Service (ACS) URL Copy the value using the "Copy" button on the right
    Audience (EntityID) Copy the value using the "Copy" button on the right
    Relay State Copy the value using the "Copy" button on the right
    Entity ID The "Issuer/Entity ID" obtained from TrustLogin
    Single Sign-On Service URL The "Identity Provider URL" obtained from TrustLogin

    05 (3).png

  3. Configure "Set Up Default Access Profile".
    This lets you define the product and role that will automatically be assigned to newly provisioned users.
    For detailed steps, please see here.
    06.png

  4. Configure "Synchronize IdP Groups with User Groups".
    If you want to automatically assign users to a Rapid7 group Select "IdP group synchronization active"
    If you do not want to automatically assign users to a Rapid7 group Select "IdP group synchronization inactive"

    07.png

  5. Save your settings by clicking the "Submit and turn on SSO" button.

  • Even after enabling SSO, existing "local users" can still log in to Rapid7 with an ID/password. However, once a user authenticates via SSO, they become an "IdP user" and can no longer log in with an ID/password afterward. Please be aware of this.
  • An IdP user cannot be reverted to a local user.
  • For this reason, we recommend keeping at least one local user as a platform administrator user.

    IdP users and local users can be distinguished by the badge shown in the user list.
    11.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication The "Relay State" obtained from Rapid7
    Value for Name ID "Member" > "email"
    Entity ID The "Audience (EntityID)" obtained from Rapid7
    Name ID Format "Unspecified"
    ACS URL to Service The "Assertion Consumer Service (ACS) URL" obtained from Rapid7

    08.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button. Configure each row as follows.

    The Group row only needs to be configured if you want to automatically assign users to a group.
    Select the group name for the group attribute value from the dropdown; you can add multiple groups using the "+" mark on the right.

    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    FirstName Unspecified FirstName

    Member

    Member - First Name

    LastName Unspecified LastName

    Member

    Member - Last Name

    Email Unspecified Email

    Member

    Member - Email Address

    rbacGroups Unspecified rbacGroups

    Group

    Select the configured group name and add all of them using the "+" button


    [When automatically assigning users to a group]
    09.png


    [When not automatically assigning users to a group]
    10.png


  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.