How to Configure SAML Authentication for OBPM Neo

Item

Details

Prerequisites

  • Prior configuration in OBPM Neo is required.

  • The email address in the OBPM Neo account information must match the email address used in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by OBPM Neo.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure it

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Default browser (Safari)

iOS - TrustLogin mobile app in-app browser

iOS - Native app

Android - Default browser (Chrome)

Android - TrustLogin mobile app in-app browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "OBPM Neo (SAML)".
    02.png

  3. Note the value of "IdP URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Change the file extension of the downloaded certificate from ".txt" to ".cer".

  5. Enter your OBPM Neo login URL in the two blank fields under "Service Provider Settings" (Note: do not include a trailing slash).
    Example: https://{subdomain}.obpm-neo.com
    06.png

  6. Click the "Register" button to save.

Configuring OBPM Neo

  1. Open "Login Authentication Settings" from the main menu.
    04.png

  2. Check "Use SAML Authentication" and configure the items below as follows.
    Finally, click the "Update" button to save.
    IdP Name Any name of your choosing (e.g., trustlogin) Note:
    IdP Login URL The "IdP URL" obtained from TrustLogin
    Redirect URL on Logout https://portal.trustlogin.com/
    IdP Certificate The "Certificate" obtained from TrustLogin (converted to a .cer file)
    SAML ID Type Select "Email address"

    05.png

    Note: The name you set for "IdP Name" will be used as the SAML authentication login button name on the login page.
    08.png

  3. From the main menu > "Account Management", set the "Email address" of the target user to the same email address used in TrustLogin.
    Note: Be careful not to set the same email address for multiple accounts in OBPM Neo. If multiple accounts share the same email address, a login error will occur.
    07.png

  4. (Reference) By configuring "Login Authentication Settings > External Authentication Settings" as follows:
    "Disable ID/Password Authentication" → checked
    "Azure AD Authentication" → unchecked
    you can restrict the login method to SAML authentication only.
    After confirming that the SAML authentication configuration works successfully and notifying users, change the settings according to your operational needs.
    09.png

Configuring TrustLogin Users

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "OBPM Neo (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "OBPM Neo (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for OBPM Neo

Item

Details

Prerequisites

  • Prior configuration in OBPM Neo is required.

  • The email address in the OBPM Neo account information must match the email address used in TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by OBPM Neo.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request the SP to configure it

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation status by device

PC - Browser

PC - Desktop app

iOS - Default browser (Safari)

iOS - TrustLogin mobile app in-app browser

iOS - Native app

Android - Default browser (Chrome)

Android - TrustLogin mobile app in-app browser

Android - Native app

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "OBPM Neo (SAML)".
    02.png

  3. Note the value of "IdP URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Change the file extension of the downloaded certificate from ".txt" to ".cer".

  5. Enter your OBPM Neo login URL in the two blank fields under "Service Provider Settings" (Note: do not include a trailing slash).
    Example: https://{subdomain}.obpm-neo.com
    06.png

  6. Click the "Register" button to save.

Configuring OBPM Neo

  1. Open "Login Authentication Settings" from the main menu.
    04.png

  2. Check "Use SAML Authentication" and configure the items below as follows.
    Finally, click the "Update" button to save.
    IdP Name Any name of your choosing (e.g., trustlogin) Note:
    IdP Login URL The "IdP URL" obtained from TrustLogin
    Redirect URL on Logout https://portal.trustlogin.com/
    IdP Certificate The "Certificate" obtained from TrustLogin (converted to a .cer file)
    SAML ID Type Select "Email address"

    05.png

    Note: The name you set for "IdP Name" will be used as the SAML authentication login button name on the login page.
    08.png

  3. From the main menu > "Account Management", set the "Email address" of the target user to the same email address used in TrustLogin.
    Note: Be careful not to set the same email address for multiple accounts in OBPM Neo. If multiple accounts share the same email address, a login error will occur.
    07.png

  4. (Reference) By configuring "Login Authentication Settings > External Authentication Settings" as follows:
    "Disable ID/Password Authentication" → checked
    "Azure AD Authentication" → unchecked
    you can restrict the login method to SAML authentication only.
    After confirming that the SAML authentication configuration works successfully and notifying users, change the settings according to your operational needs.
    09.png

Configuring TrustLogin Users

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "OBPM Neo (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds members

  1. In the "Admin Page > Apps" menu, search for and click the "OBPM Neo (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.