OneDesk SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in OneDesk is required.

  • A user's first and last name are synchronized only when the account is first created.

  • Please refer to the manual provided by OneDesk for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "OneDesk (SAML)".
    Onedesk05.png


  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.03.png

Now, switch to configuring OneDesk.

Do not click the "Register" button yet — open OneDesk in a separate window.

OneDesk Configuration

  1. Log in to OneDesk as an administrator, click the profile icon at the top right of the screen, and select "Administration>Integrations".
    Onedesk02.png

  2. Open the "Single Sign On" tab and configure it as follows.
    Entable SSO for users Turn the toggle on
    SAML Turn SAML ON and click Expand
    OneDesk Metadata URL

    Copy the unique value at the end of the URL and make a note of it

    [Example] https://app.onedesk.com/sso/saml/metadata/alias/onedesk.com_xxxx

    OneDesk SSO Login URL

    URL for SP-Initiated login; make a note of it if needed

    Upload Metadata File

    Use Choose File to upload the metadata you obtained from TrustLogin

    Entable User Provisioning Turn Entable User Provisioning on and click Expand
    Email Attribute Email
    First Name Attribute FirstName
    Last Name Attribute LastName

    Onedesk04.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The unique value at the end of the OneDesk Metadata URL you obtained from OneDesk
    ACS URL to Service The unique value at the end of the OneDesk Metadata URL you obtained from OneDesk

    Onedesk.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "OneDesk (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "OneDesk (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

OneDesk SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in OneDesk is required.

  • A user's first and last name are synchronized only when the account is first created.

  • Please refer to the manual provided by OneDesk for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "OneDesk (SAML)".
    Onedesk05.png


  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.03.png

Now, switch to configuring OneDesk.

Do not click the "Register" button yet — open OneDesk in a separate window.

OneDesk Configuration

  1. Log in to OneDesk as an administrator, click the profile icon at the top right of the screen, and select "Administration>Integrations".
    Onedesk02.png

  2. Open the "Single Sign On" tab and configure it as follows.
    Entable SSO for users Turn the toggle on
    SAML Turn SAML ON and click Expand
    OneDesk Metadata URL

    Copy the unique value at the end of the URL and make a note of it

    [Example] https://app.onedesk.com/sso/saml/metadata/alias/onedesk.com_xxxx

    OneDesk SSO Login URL

    URL for SP-Initiated login; make a note of it if needed

    Upload Metadata File

    Use Choose File to upload the metadata you obtained from TrustLogin

    Entable User Provisioning Turn Entable User Provisioning on and click Expand
    Email Attribute Email
    First Name Attribute FirstName
    Last Name Attribute LastName

    Onedesk04.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The unique value at the end of the OneDesk Metadata URL you obtained from OneDesk
    ACS URL to Service The unique value at the end of the OneDesk Metadata URL you obtained from OneDesk

    Onedesk.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "OneDesk (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "OneDesk (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.