How to Configure SAML Authentication for IPFM Cloud

Item

Details

Prerequisites

  • Prior configuration on IPFM Cloud is required.

  • You must register the same email address as in TrustLogin for the SSO principal name in IPFM Cloud.

  • For the latest configuration steps, please refer to the manual provided by IPFM Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "IPFM Cloud (SAML)".
    IPFMCloud.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

  4. Please send the obtained "Metadata" to your contact at IRD Co., Ltd. and request the SAML configuration.

  5. Configure the SSO information for IPFM Cloud received from IRD Co., Ltd. in "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication The "Post-authentication URL" provided by IRD Co., Ltd.
    Entity ID The "Entity ID" provided by IRD Co., Ltd.
    ACS URL to Service The "ACS URL" provided by IRD Co., Ltd.
    Logout URL The "Logout URL" provided by IRD Co., Ltd.
    Note: Single logout is planned as a future feature addition, but is not currently implemented and does not work

    IPFM Cloud .png

  6. Click the "Register" button to save.

TrustLogin User Configuration

① When Users Add the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "IPFM Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

②When Administrators Add Members

  1. In the "Admin Page > Apps" menu, search for and click the "IPFM Cloud (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for IPFM Cloud

Item

Details

Prerequisites

  • Prior configuration on IPFM Cloud is required.

  • You must register the same email address as in TrustLogin for the SSO principal name in IPFM Cloud.

  • For the latest configuration steps, please refer to the manual provided by IPFM Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verification Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "IPFM Cloud (SAML)".
    IPFMCloud.png

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

  4. Please send the obtained "Metadata" to your contact at IRD Co., Ltd. and request the SAML configuration.

  5. Configure the SSO information for IPFM Cloud received from IRD Co., Ltd. in "Service Provider Settings" as follows.
    Redirect URL after successful SP authentication The "Post-authentication URL" provided by IRD Co., Ltd.
    Entity ID The "Entity ID" provided by IRD Co., Ltd.
    ACS URL to Service The "ACS URL" provided by IRD Co., Ltd.
    Logout URL The "Logout URL" provided by IRD Co., Ltd.
    Note: Single logout is planned as a future feature addition, but is not currently implemented and does not work

    IPFM Cloud .png

  6. Click the "Register" button to save.

TrustLogin User Configuration

① When Users Add the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "IPFM Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

②When Administrators Add Members

  1. In the "Admin Page > Apps" menu, search for and click the "IPFM Cloud (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.