How to Configure SAML Authentication for Remote

Item

Details

Prerequisites

  • Prior configuration in Remote is required.

  • You must create an account in Remote using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Remote.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The app is a Progressive Web App (PWA) installed from a web page.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Remote (SAML)."
    Remote.png

  3. Note down the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring the Remote side.
Do not click the "Register" button yet — open Remote in a separate window.

Remote Configuration

  1. Log in to Remote, open "Company settings>Authentication," and click the "Turn on Single Sign-on(SSO)" button.Remote02.png

  2. Configure the fields as follows, then enable SSO with the "Turn on Single Sign-on(SSO)" button.
    URL Copy it using the copy button and note it down
    Audience Copy it using the copy button and note it down
    Company domain

    Enter the domain of the email address for the company where you want to enable SSO

    Example: For test@xxx.com, enter xxx.com

    Identity provider URL Enter the "IdP URL" noted from TrustLogin
    Upload certificate Upload the "Certificate" noted from TrustLogin

    Remote03.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID Enter the "Audience" noted from Remote
    ACS URL for the Service Enter the "URL" noted from Remote

    Remote04.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Remote (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Remote (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Remote

Item

Details

Prerequisites

  • Prior configuration in Remote is required.

  • You must create an account in Remote using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Remote.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible in TrustLogin)

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Note: The app is a Progressive Web App (PWA) installed from a web page.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Remote (SAML)."
    Remote.png

  3. Note down the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

Now, switch to configuring the Remote side.
Do not click the "Register" button yet — open Remote in a separate window.

Remote Configuration

  1. Log in to Remote, open "Company settings>Authentication," and click the "Turn on Single Sign-on(SSO)" button.Remote02.png

  2. Configure the fields as follows, then enable SSO with the "Turn on Single Sign-on(SSO)" button.
    URL Copy it using the copy button and note it down
    Audience Copy it using the copy button and note it down
    Company domain

    Enter the domain of the email address for the company where you want to enable SSO

    Example: For test@xxx.com, enter xxx.com

    Identity provider URL Enter the "IdP URL" noted from TrustLogin
    Upload certificate Upload the "Certificate" noted from TrustLogin

    Remote03.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID Enter the "Audience" noted from Remote
    ACS URL for the Service Enter the "URL" noted from Remote

    Remote04.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Remote (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Remote (SAML)" app.
  2. Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.