How to Configure SAML Authentication for eYACHO for Business

Item

Details

Pre-check

  • Prior configuration in eYACHO for Business is required.

  • The eYACHO for Business user ID and the TrustLogin email address must match.

  • SSO can also be configured for GEMBA Note for Business and MetaMoJi Share for Business using the same settings as in this manual.

  • This manual was verified and created using eYACHO for Business 6. The screen display may differ depending on the product.
  • For the latest setup instructions, please refer to the manual provided by eYACHO for Business.

Name ID

Email address

Custom attribute Note: For instructions on configuring a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion is not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device-Specific Verified Operation Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Corporate App Registration" screen and select "eYACHO for Business (SAML)".
    eYACHO.png

  3. Note down the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png


  4. For "Login URL" in the service provider settings, specify the URL to redirect to when the app is clicked in the browser, according to your operational needs, as shown below.
    If you want to redirect to the "Web Admin Tool"
    https://mps.metamoji.com/admintool/
    If you want to redirect to the "MetaMoJi Cloud Tool"
    https://mps.metamoji.com/mpsroot/CloudToolLogin?
    Note: By specifying, as the login URL, the URL that results after entering the "Corporate ID" at the above URL, you can also omit entering the "Corporate ID".
    Example: For the "Web Admin Tool"
       https://[your server number].metamoji.com/mmjeditor2/usradm/ja/login.html?cuid=[Corporate ID]
    For the "MetaMoJi Cloud Tool"
      https://[your server number].metamoji.com/mmjCloudWeb/mypage/ja/login.html?cuid=[Corporate ID]

    16.png

  5. Save by clicking the "Register" button.

Configuring eYACHO for Business

  1. Log in to the Web Admin Tool as an administrator user and open "Customization Settings" from the menu.
    04.png

  2. Set "Log in with Other Service" to "Enable," and save the setting by clicking the "Save" button.
    05.png

  3. Return to the administrator menu and open "Login with Other Service Settings."
    06.png

  4. Click "Advanced Settings" for Microsoft Azure AD.
    07.png

  5. Confirm that you are on the "Single Sign-On (SAML)" tab, and configure each item as follows. Finally, save by clicking the "OK" button.
    Login URL The "IdP URL" obtained from TrustLogin
    Certificate (Base64) Select the "Certificate" obtained from TrustLogin using the "Load from File" button
    User Identifier Select "Unique User ID (userprincipalName)"

    08.png

  6. Return to the administrator menu and open "User Management."
    You can also make bulk changes using "Bulk User Registration." Please refer to the manual provided by MetaMoJi Corporation.
    09.png

  7. Open the user information change screen for the target user, configure the following items, and save by clicking the "Change" button. Note: If you change "Log in with Other Service" to "Enable," login with a user ID/password will no longer be possible.
    User ID (employee number, etc.) Same email address as in TrustLogin
    Log in with Other Service Select "Enable"

    10.png

Configuring the TrustLogin User

① When a User Adds via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "eYACHO for Business (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "eYACHO for Business (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Log In

① Logging In to the Web Admin Tool or MetaMoJi Cloud Tool via Browser

  1. When you click the app from My Page in a PC browser or the TrustLogin mobile app, you will be redirected to the URL specified as the login URL. Enter your "Corporate/School ID".
    11.png

  2. Click the "Log in with Other Service" button to complete login.
    12.png

② Logging In to the App of the Target Product

  1. Open the target product in the native app or desktop app, and click "Log in with Other Service."
    13.png


  2. Enter your "Corporate ID" and click "Done."
    14.png

  3. Click the "Log In" button to go to the TrustLogin authentication screen. After logging in to TrustLogin, you will be logged in to the target product. Once added, the Corporate ID is saved, so you do not need to enter it again after the first time.

    You can add or delete Corporate IDs using the settings button (gear icon) in the upper right.
    15.png

How to Configure SAML Authentication for eYACHO for Business

Item

Details

Pre-check

  • Prior configuration in eYACHO for Business is required.

  • The eYACHO for Business user ID and the TrustLogin email address must match.

  • SSO can also be configured for GEMBA Note for Business and MetaMoJi Share for Business using the same settings as in this manual.

  • This manual was verified and created using eYACHO for Business 6. The screen display may differ depending on the product.
  • For the latest setup instructions, please refer to the manual provided by eYACHO for Business.

Name ID

Email address

Custom attribute Note: For instructions on configuring a custom attribute, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion is not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device-Specific Verified Operation Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Configuring the TrustLogin Admin Page

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Corporate App Registration" screen and select "eYACHO for Business (SAML)".
    eYACHO.png

  3. Note down the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.
    03.png


  4. For "Login URL" in the service provider settings, specify the URL to redirect to when the app is clicked in the browser, according to your operational needs, as shown below.
    If you want to redirect to the "Web Admin Tool"
    https://mps.metamoji.com/admintool/
    If you want to redirect to the "MetaMoJi Cloud Tool"
    https://mps.metamoji.com/mpsroot/CloudToolLogin?
    Note: By specifying, as the login URL, the URL that results after entering the "Corporate ID" at the above URL, you can also omit entering the "Corporate ID".
    Example: For the "Web Admin Tool"
       https://[your server number].metamoji.com/mmjeditor2/usradm/ja/login.html?cuid=[Corporate ID]
    For the "MetaMoJi Cloud Tool"
      https://[your server number].metamoji.com/mmjCloudWeb/mypage/ja/login.html?cuid=[Corporate ID]

    16.png

  5. Save by clicking the "Register" button.

Configuring eYACHO for Business

  1. Log in to the Web Admin Tool as an administrator user and open "Customization Settings" from the menu.
    04.png

  2. Set "Log in with Other Service" to "Enable," and save the setting by clicking the "Save" button.
    05.png

  3. Return to the administrator menu and open "Login with Other Service Settings."
    06.png

  4. Click "Advanced Settings" for Microsoft Azure AD.
    07.png

  5. Confirm that you are on the "Single Sign-On (SAML)" tab, and configure each item as follows. Finally, save by clicking the "OK" button.
    Login URL The "IdP URL" obtained from TrustLogin
    Certificate (Base64) Select the "Certificate" obtained from TrustLogin using the "Load from File" button
    User Identifier Select "Unique User ID (userprincipalName)"

    08.png

  6. Return to the administrator menu and open "User Management."
    You can also make bulk changes using "Bulk User Registration." Please refer to the manual provided by MetaMoJi Corporation.
    09.png

  7. Open the user information change screen for the target user, configure the following items, and save by clicking the "Change" button. Note: If you change "Log in with Other Service" to "Enable," login with a user ID/password will no longer be possible.
    User ID (employee number, etc.) Same email address as in TrustLogin
    Log in with Other Service Select "Enable"

    10.png

Configuring the TrustLogin User

① When a User Adds via My Page

  1. Click the "Add App" button on "My Page."
  2. On the "Register App" screen, select "eYACHO for Business (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "eYACHO for Business (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Log In

① Logging In to the Web Admin Tool or MetaMoJi Cloud Tool via Browser

  1. When you click the app from My Page in a PC browser or the TrustLogin mobile app, you will be redirected to the URL specified as the login URL. Enter your "Corporate/School ID".
    11.png

  2. Click the "Log in with Other Service" button to complete login.
    12.png

② Logging In to the App of the Target Product

  1. Open the target product in the native app or desktop app, and click "Log in with Other Service."
    13.png


  2. Enter your "Corporate ID" and click "Done."
    14.png

  3. Click the "Log In" button to go to the TrustLogin authentication screen. After logging in to TrustLogin, you will be logged in to the target product. Once added, the Corporate ID is saved, so you do not need to enter it again after the first time.

    You can add or delete Corporate IDs using the settings button (gear icon) in the upper right.
    15.png