Trend Cloud One SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Trend Cloud One is required.

  • Please refer to the manual provided by Trend Cloud One for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

When you log in to Trend Cloud One via SAML authentication, JIT provisioning synchronizes user information to Trend Cloud One. Therefore, please complete the following configuration in advance.

Create a Group and Assign Members

Create a group to map to a Trend Cloud One role, and assign members to it.
(If an existing group can be used for this purpose, you may use it instead.)
The group name can be anything you choose.

Please refer to the following page for how to create groups and assign members.
Register a Group

[Configuration Example]

  • Create a "GroupA" group and assign it to the "Identity and Account" role in Trend Cloud One
  • Create a "GroupB" group and assign it to the "Billing and Licensing" role in Trend Cloud One

With this configuration, when a user belonging to the "GroupA" group logs in to Trend Cloud One via SAML, the "Identity and Account" role is automatically assigned. Users who do not belong to any of the configured groups will not be able to log in to Trend Cloud One.
For more information about Trend Cloud One roles, see here.

Custom Attribute Configuration

If you want to link the name, locale (language), and time zone to TrustLogin member information, you need to configure custom attributes in advance. This configuration is optional.

Note: The attribute name can be anything you choose.
Note: If you do not set a name, new users will be created using their email address.
Note: If you do not set the locale (language) or time zone, they will be mapped based on the browser settings. Configure these only if you want to change them.
Note: For the locale (language) attribute value, set "ja" for Japanese or "en" for English.
Note: The time zone attribute value must match the database name (TZ identifier).

[TrustLogin Custom Attribute Configuration Example]

Trend Cloud One 06.png

Please refer to the following pages for instructions on how to configure this.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png


  2. Register the "Application Name" and "Icon" (optional).
    Trend Cloud One 01.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.

    03.png

    Now, switch to configuring Trend Cloud One.
    Do not click the "Register" button yet — open Trend Cloud One in a separate window.

    Trend Cloud One Configuration

    1. Log in to Trend Cloud One with an account that has full access privileges, and open "Administration".
      Trend Cloud One 02.png

    2. Open "Identity Provider", click "Download metadata XML for Trend Cloud One", and save the metadata that opens in your browser. After saving, return to the Trend Cloud One screen and click "New".
      Trend Cloud One 03.png

    3. Configure the settings as follows, then save your settings by clicking "Save".
      Alias Any name you choose
      Metadata XML File Upload the metadata you obtained from TrustLogin
      Role role
      Group
      The group name configured in TrustLogin

      The role to assign (the group configured in Trend Cloud One)

      Name Attribute name Note: optional
      Locale Attribute locale Note: optional
      Time Zone Attribute timezone Note: optional

      Trend Cloud One 04.png

    Now return to the TrustLogin Admin Page again.

    TrustLogin Admin Page Settings (Continued)

    1. Configure "Service Provider Settings" as follows.
      Sign SAML Response Check the box
      Redirect URL after successful SP authentication

      Leave blank or enter "/workload"

      Note: If a Workload Security role has been assigned, entering "/workload" will redirect the user to Workload Security.

      Value for Name ID [Member]-[email]
      Metadata Upload the metadata you obtained from Trend Cloud One

      Trend Cloud One 07.png

    2. Add attributes using the "Add SAML Attribute" button in "SAML Attribute Settings", and configure them as follows.
      Service Provider Attribute TrustLogin (IdP) Attribute
      Attribute Name Attribute Type Attribute Name Attribute Value
      role Unspecified role

      Group

      Select the configured group name and add it using the "+" button

      name Unspecified name

      Custom Attribute

      The attribute name you configured
      (e.g., FullName)

      locale Unspecified locale

      Custom Attribute

      The attribute name you configured
      (e.g., locale)

      timezone Unspecified timezone

      Custom Attribute

      The attribute name you configured
      (e.g., timezone)

      Note: The "name", "locale", and "timezone" items are optional. Configure them only if needed.

      Trend Cloud One 05.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Trend Cloud One SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in Trend Cloud One is required.

  • Please refer to the manual provided by Trend Cloud One for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

When you log in to Trend Cloud One via SAML authentication, JIT provisioning synchronizes user information to Trend Cloud One. Therefore, please complete the following configuration in advance.

Create a Group and Assign Members

Create a group to map to a Trend Cloud One role, and assign members to it.
(If an existing group can be used for this purpose, you may use it instead.)
The group name can be anything you choose.

Please refer to the following page for how to create groups and assign members.
Register a Group

[Configuration Example]

  • Create a "GroupA" group and assign it to the "Identity and Account" role in Trend Cloud One
  • Create a "GroupB" group and assign it to the "Billing and Licensing" role in Trend Cloud One

With this configuration, when a user belonging to the "GroupA" group logs in to Trend Cloud One via SAML, the "Identity and Account" role is automatically assigned. Users who do not belong to any of the configured groups will not be able to log in to Trend Cloud One.
For more information about Trend Cloud One roles, see here.

Custom Attribute Configuration

If you want to link the name, locale (language), and time zone to TrustLogin member information, you need to configure custom attributes in advance. This configuration is optional.

Note: The attribute name can be anything you choose.
Note: If you do not set a name, new users will be created using their email address.
Note: If you do not set the locale (language) or time zone, they will be mapped based on the browser settings. Configure these only if you want to change them.
Note: For the locale (language) attribute value, set "ja" for Japanese or "en" for English.
Note: The time zone attribute value must match the database name (TZ identifier).

[TrustLogin Custom Attribute Configuration Example]

Trend Cloud One 06.png

Please refer to the following pages for instructions on how to configure this.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    jit01.png


  2. Register the "Application Name" and "Icon" (optional).
    Trend Cloud One 01.png

  3. Download the metadata from the "Download Metadata" button in the "Identity Provider Information" section.

    03.png

    Now, switch to configuring Trend Cloud One.
    Do not click the "Register" button yet — open Trend Cloud One in a separate window.

    Trend Cloud One Configuration

    1. Log in to Trend Cloud One with an account that has full access privileges, and open "Administration".
      Trend Cloud One 02.png

    2. Open "Identity Provider", click "Download metadata XML for Trend Cloud One", and save the metadata that opens in your browser. After saving, return to the Trend Cloud One screen and click "New".
      Trend Cloud One 03.png

    3. Configure the settings as follows, then save your settings by clicking "Save".
      Alias Any name you choose
      Metadata XML File Upload the metadata you obtained from TrustLogin
      Role role
      Group
      The group name configured in TrustLogin

      The role to assign (the group configured in Trend Cloud One)

      Name Attribute name Note: optional
      Locale Attribute locale Note: optional
      Time Zone Attribute timezone Note: optional

      Trend Cloud One 04.png

    Now return to the TrustLogin Admin Page again.

    TrustLogin Admin Page Settings (Continued)

    1. Configure "Service Provider Settings" as follows.
      Sign SAML Response Check the box
      Redirect URL after successful SP authentication

      Leave blank or enter "/workload"

      Note: If a Workload Security role has been assigned, entering "/workload" will redirect the user to Workload Security.

      Value for Name ID [Member]-[email]
      Metadata Upload the metadata you obtained from Trend Cloud One

      Trend Cloud One 07.png

    2. Add attributes using the "Add SAML Attribute" button in "SAML Attribute Settings", and configure them as follows.
      Service Provider Attribute TrustLogin (IdP) Attribute
      Attribute Name Attribute Type Attribute Name Attribute Value
      role Unspecified role

      Group

      Select the configured group name and add it using the "+" button

      name Unspecified name

      Custom Attribute

      The attribute name you configured
      (e.g., FullName)

      locale Unspecified locale

      Custom Attribute

      The attribute name you configured
      (e.g., locale)

      timezone Unspecified timezone

      Custom Attribute

      The attribute name you configured
      (e.g., timezone)

      Note: The "name", "locale", and "timezone" items are optional. Configure them only if needed.

      Trend Cloud One 05.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.