How to Configure SAML Authentication for Concur

Item

Details

Pre-Check

  • Prior configuration on the Concur side is required.

  • The Concur login ID must match the email address registered in TrustLogin.

  • If the Concur login ID differs from the email address registered in TrustLogin, you need to set the login ID as a custom attribute in TrustLogin.
  • For the latest setup instructions, please refer to the manual provided by Concur.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Device Compatibility Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: Not verified by us

Preparation

Add a Custom Attribute to User Information

Add the Concur "Login ID" information as a custom attribute in the TrustLogin member information.
Note: If the "Concur login ID" matches the "email address registered in TrustLogin", this step is not required. Please proceed to the next step.

[TrustLogin Custom Attribute Configuration Example]
Concur03.png

For instructions on how to configure custom attributes, please refer to the pages below. You may use any name you like for the custom attribute.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Concur (SAML)".
    Concur02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring the Concur side.
Do not click the "Register" button yet. Open Concur in a separate window.

Concur Configuration

  1. Log in to Concur with an account that has organization administrator privileges, and click "Administration" > "Company" > "Authentication Admin".

  2. On the "Authentication Admin" screen, click "Manage Single Sign-On".

  3. Download the metadata from "SAP Concur Metadata Download".

  4. Under "IdP Metadata", click "Add".

  5. In "Add IdP Metadata", configure the settings as follows, then click "Add Metadata".
    Custom IdP Name Enter any name (e.g., TrustLogin)
    Logout URL Leave blank, or enter https://portal.trustlogin.com/
    Upload IdP Metadata Upload the metadata you saved from TrustLogin

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Upload the metadata you saved from Concur to "Metadata" under "Service Provider Settings".
    Concur.png

  2. If you have set the Concur login ID as a custom attribute, change "Value for Name ID" to
    [Custom Attribute] - [the attribute name you configured].
    Note: This step is not required if the login ID matches the email address registered in TrustLogin.
    Concur04.png

  3. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Concur (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Concur (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Concur

Item

Details

Pre-Check

  • Prior configuration on the Concur side is required.

  • The Concur login ID must match the email address registered in TrustLogin.

  • If the Concur login ID differs from the email address registered in TrustLogin, you need to set the login ID as a custom attribute in TrustLogin.
  • For the latest setup instructions, please refer to the manual provided by Concur.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Device Compatibility Status

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

Note: Not verified by us

Preparation

Add a Custom Attribute to User Information

Add the Concur "Login ID" information as a custom attribute in the TrustLogin member information.
Note: If the "Concur login ID" matches the "email address registered in TrustLogin", this step is not required. Please proceed to the next step.

[TrustLogin Custom Attribute Configuration Example]
Concur03.png

For instructions on how to configure custom attributes, please refer to the pages below. You may use any name you like for the custom attribute.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Concur (SAML)".
    Concur02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring the Concur side.
Do not click the "Register" button yet. Open Concur in a separate window.

Concur Configuration

  1. Log in to Concur with an account that has organization administrator privileges, and click "Administration" > "Company" > "Authentication Admin".

  2. On the "Authentication Admin" screen, click "Manage Single Sign-On".

  3. Download the metadata from "SAP Concur Metadata Download".

  4. Under "IdP Metadata", click "Add".

  5. In "Add IdP Metadata", configure the settings as follows, then click "Add Metadata".
    Custom IdP Name Enter any name (e.g., TrustLogin)
    Logout URL Leave blank, or enter https://portal.trustlogin.com/
    Upload IdP Metadata Upload the metadata you saved from TrustLogin

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Upload the metadata you saved from Concur to "Metadata" under "Service Provider Settings".
    Concur.png

  2. If you have set the Concur login ID as a custom attribute, change "Value for Name ID" to
    [Custom Attribute] - [the attribute name you configured].
    Note: This step is not required if the login ID matches the email address registered in TrustLogin.
    Concur04.png

  3. Click the "Register" button to save.

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Concur (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Concur (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.