|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verification Status by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search and select "HireRoo (SAML)".
- Note down the values of "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
- Save by clicking the "Register" button.
HireRoo Configuration
- Log in with an administrator account and open "Company Settings > Security".
Click the "Edit" button, then turn ON the "Enable SSO" toggle.
- Configure each item as follows, then save by clicking the "Save" button.
IdP Endpoint URL (SSO URL) The "Identity Provider URL" obtained from TrustLogin IdP Entity ID (issuer) The "Issuer/Entity ID" obtained from TrustLogin IdP Certificate (X.509 Certificate) The contents of the "Certificate" obtained from TrustLogin Target Domain Specify the domain of users subject to SAML SSO Enable Enforcement Mode Turn ON to restrict authentication methods other than SAML SSO
Note: We recommend keeping this OFF until SAML configuration testing and user communication are complete. Also note that if turned ON, users outside the target domain will no longer be able to log in.
TrustLogin User Configuration
① When Users Add the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "HireRoo (SAML)" and click the "Next" button at the top right of the screen.
- Enter a value if you want to change the "Display Name", then click the "Register" button.
② When an Administrator Adds Members
- Search for the "HireRoo (SAML)" app in the "Admin Page > Apps" menu and click it.
- Click "Add Member", select the users to add from the member list, and click the "Register" button to add them.
How to Log In
① Logging In with "HireRoo (SAML)"
Running "HireRoo (SAML)" from My Page or the browser extension will take you to the HireRoo login screen. Click "Single Sign-On", enter your "Company Email Address", and then click "Sign in with SSO (Single Sign-On)" to complete the login.
② Using the Helper App
We also provide a helper app that can automatically fill in your "Company Email Address".
Search for it on the app search screen and register "【SAML Helper】HireRoo" to use it.
Note: The helper app is only available on PC browsers.