|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
| 〇 |
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
|
|
|
None (accounts created in each system) |
|
|
Access Method |
|
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
Prerequisites
When you log in to Trend Cloud One via SAML authentication, JIT provisioning synchronizes user information to Trend Cloud One. Therefore, please complete the following configuration in advance.
Create a Group and Assign Members
Create a group to map to a Trend Cloud One role, and assign members to it.
(If an existing group can be used for this purpose, you may use it instead.)
The group name can be anything you choose.
Please refer to the following page for how to create groups and assign members.
Register a Group
[Configuration Example]
- Create a "GroupA" group and assign it to the "Identity and Account" role in Trend Cloud One
- Create a "GroupB" group and assign it to the "Billing and Licensing" role in Trend Cloud One
With this configuration, when a user belonging to the "GroupA" group logs in to Trend Cloud One via SAML, the "Identity and Account" role is automatically assigned. Users who do not belong to any of the configured groups will not be able to log in to Trend Cloud One.
For more information about Trend Cloud One roles, see here.
Custom Attribute Configuration
If you want to link the name, locale (language), and time zone to TrustLogin member information, you need to configure custom attributes in advance. This configuration is optional.
Note: The attribute name can be anything you choose.
Note: If you do not set a name, new users will be created using their email address.
Note: If you do not set the locale (language) or time zone, they will be mapped based on the browser settings. Configure these only if you want to change them.
Note: For the locale (language) attribute value, set "ja" for Japanese or "en" for English.
Note: The time zone attribute value must match the database name (TZ identifier).
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for instructions on how to configure this.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
- Register the "Application Name" and "Icon" (optional).
-
Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.
Now, switch to configuring Trend Cloud One.
Do not click the "Register" button yet — open Trend Cloud One in a separate window.Trend Cloud One Configuration
- Log in to Trend Cloud One with an account that has full access privileges, and open "Administration".
- Open "Identity Provider", click "Download metadata XML for Trend Cloud One", and save the metadata that opens in your browser. After saving, return to the Trend Cloud One screen and click "New".
- Configure the settings as follows, then save your settings by clicking "Save".
Alias Any name you choose Metadata XML File Upload the metadata you obtained from TrustLogin Role role Group The group name configured in TrustLogin The role to assign (the group configured in Trend Cloud One)
Name Attribute name Note: optional Locale Attribute locale Note: optional Time Zone Attribute timezone Note: optional
Now return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Sign SAML Response Check the box Redirect URL after successful SP authentication Leave blank or enter "/workload"
Note: If a Workload Security role has been assigned, entering "/workload" will redirect the user to Workload Security.
Value for Name ID [Member]-[email] Metadata Upload the metadata you obtained from Trend Cloud One
- Add attributes using the "Add SAML Attribute" button in "SAML Attribute Settings", and configure them as follows.
Note: The "name", "locale", and "timezone" items are optional. Configure them only if needed.Service Provider Attribute TrustLogin (IdP) Attribute Attribute Name Attribute Type Attribute Name Attribute Value role Unspecified role Group
Select the configured group name and add it using the "+" button
name Unspecified name Custom Attribute
The attribute name you configured
(e.g., FullName)locale Unspecified locale Custom Attribute
The attribute name you configured
(e.g., locale)timezone Unspecified timezone Custom Attribute
The attribute name you configured
(e.g., timezone)
- Log in to Trend Cloud One with an account that has full access privileges, and open "Administration".
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
②When an Administrator Adds a Member
- Search for and click the custom SAML app you created in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.