|
Item |
Details |
|
|---|---|---|
|
Prerequisites |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure custom attributes, see here |
||
|
SP-side configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure it |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified operation status by device |
〇 |
PC - Browser |
|
ー |
PC - Desktop app |
|
|
〇 |
iOS - Default browser (Safari) |
|
|
〇 |
iOS - TrustLogin mobile app in-app browser |
|
|
ー |
iOS - Native app |
|
|
〇 |
Android - Default browser (Chrome) |
|
|
〇 |
Android - TrustLogin mobile app in-app browser |
|
|
ー |
Android - Native app |
|
Configuring the TrustLogin Admin Page
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Company App" screen, search for and select "OBPM Neo (SAML)".
- Note the value of "IdP URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
- Change the file extension of the downloaded certificate from ".txt" to ".cer".
- Enter your OBPM Neo login URL in the two blank fields under "Service Provider Settings" (Note: do not include a trailing slash).
Example: https://{subdomain}.obpm-neo.com - Click the "Register" button to save.
Configuring OBPM Neo
- Open "Login Authentication Settings" from the main menu.
- Check "Use SAML Authentication" and configure the items below as follows.
Finally, click the "Update" button to save.
IdP Name Any name of your choosing (e.g., trustlogin) Note: IdP Login URL The "IdP URL" obtained from TrustLogin Redirect URL on Logout https://portal.trustlogin.com/ IdP Certificate The "Certificate" obtained from TrustLogin (converted to a .cer file) SAML ID Type Select "Email address"
Note: The name you set for "IdP Name" will be used as the SAML authentication login button name on the login page.
- From the main menu > "Account Management", set the "Email address" of the target user to the same email address used in TrustLogin.
Note: Be careful not to set the same email address for multiple accounts in OBPM Neo. If multiple accounts share the same email address, a login error will occur.
- (Reference) By configuring "Login Authentication Settings > External Authentication Settings" as follows:
"Disable ID/Password Authentication" → checked
"Azure AD Authentication" → unchecked
you can restrict the login method to SAML authentication only.
After confirming that the SAML authentication configuration works successfully and notifying users, change the settings according to your operational needs.
Configuring TrustLogin Users
① When a user adds the app from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "OBPM Neo (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > Apps" menu, search for and click the "OBPM Neo (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.