|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on configuring custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
※ |
iOS - Native App (possible depending on the app) |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
※ |
Android - Native App (possible depending on the app) |
|
|
SAML Authentication Scope |
ー |
Enabled for everyone (SAML authentication only) |
| 〇 |
Other: |
|
|
Remarks |
If you are using multiple services linked to Google, after completing the SAML configuration in this manual, please also refer to the following manual. |
|
|
Table of Contents: TrustLogin Admin Page Configuration Google Workspace Configuration |
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Enterprise App Registration" screen, search and select "Google Workspace (SAML)".
- Note down the values of "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information", then download the certificate using the "Get Certificate" button.
At this point, switch to the configuration on the Google side.
Do not click the "Register" button yet — open the Google Workspace Admin console in a separate window.
Google Workspace Configuration
- From the menu, click "Add SAML profile" under "Security > Authentication > SSO with third-party IdP > Third-party SSO profiles".
-
Configure each item under "SAML SSO Profile" as follows, then click "Save" to save the settings.
SSO Profile Name Any name of your choice (e.g., IdP name, name of the organizational unit to assign) IdP Entity ID The "Issuer/Entity ID" obtained from TrustLogin Sign-in Page URL
The "IdP URL" obtained from TrustLogin Sign-out Page URL https://portal.trustlogin.com/ Verification Certificate The "Certificate" obtained from TrustLogin
- Copy and note down the "Entity ID" and "ACS URL" from the "SP Details" of the SSO profile you created.
- Return to "SSO with third-party IdP" and click "Manage" under "Manage SSO profile assignments".
(If you are configuring this item for the first time, click "Get Started" instead.)
- Select the organizational unit or group to assign, and select the SSO profile you configured under "Select SSO profile".
Select "Ask for Google username first, then redirect to this profile's IdP sign-in page" and click "Save" to save the settings.
Note: By selecting "None" as the sign-in method, you can exclude the target organizational unit or group from SSO. This allows you to configure SSO on/off in detail for the entire organization, or for individual organizational units or groups.
(Example) If you configure an SSO profile at the organizational-unit level and select "None" as the sign-in method for a group, users belonging to that group will not have SSO applied, even though SSO is enabled for the organizational unit.
Note: If you want to allow SP-initiated sign-in with a password, select "Ask users to enter their Google username and password to sign in".
-
Click the edit icon next to "Domain-specific service URL".
- This controls the behavior when a user clicks an app from TrustLogin, or accesses a domain-specific service URL (e.g., https://mail.google.com/a/example.com).
・Automatically redirect users to the third-party IdP included in the following SSO profile
Redirects to the IdP of the selected SSO profile. If a user clicks an app from TrustLogin, they can be taken directly to the service. However, do not select this setting if there are organizational units or groups to which SSO should not be applied.
・Ask users to enter their username on the Google sign-in page first
Redirects to the Google sign-in page. After entering their email address, users subject to SSO are redirected to the IdP, while users not subject to SSO proceed to password entry.
Now, return to the TrustLogin Admin Page.
TrustLogin Admin Page Configuration (Continued)
- Configure "Service Provider Settings" as follows.
Login URL The URL of the service
https://[subdomain of each service].google.com/a/[your primary domain]Example:
https://mail.google.com/a/example.com
https://calendar.google.com/a/example.comNote: If left blank, after SSO, users will be taken to the Google Account page.
Entity ID The "Entity ID" obtained from Google Workspace ACS URL for the Service The "ACS URL" obtained from Google Workspace
- Click the "Register" button to save.
TrustLogin User Configuration
① When a user adds the app from My Page
- On "My Page", click the "Add App" button.
- On the "App Registration" screen, select "Google Workspace (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter a new one, then click the "Register" button.
② When an administrator adds members
- From the "Admin Page > Apps" menu, search for and click the "Google Workspace (SAML)" app.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.