microCMS SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in microCMS is required.

  • Role assignment via SAML JIT only occurs at the first login. It is not changed on subsequent logins, so if you want to change the role, you will need to change it manually.
  • Please refer to the manual provided by microCMS for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites
When a user is created via SAML JIT, the "Display Name" is synced to microCMS. You need to configure a custom attribute in advance to link microCMS's "Display Name" to the TrustLogin member information.

Note: The attribute name can be anything you choose.

[TrustLogin Custom Attribute Configuration Example]

HUE Project Board11.png

Please refer to the following pages for instructions on how to configure custom attributes.


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Configure the "Application Name" and "Icon" (optional).
    microCMS06.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".

    03.png

Now, switch to configuring microCMS.
Do not click the "Register" button yet — open microCMS in a separate window.

microCMS Settings

  1. Log in with an administrator account and open "Gear icon > Security > SAML".
    Make a note of the "Service Provider Callback URL" and "Entity ID" values for the microCMS information to enter into the identity provider, as well as the "email" and "name" attribute values.
    microCMS01.png

  2. Configure as follows, and save the settings by clicking "Change".
    Metadata Select the "XML" tab and paste the contents of the TrustLogin metadata
    Default Role

    Select the role to be assigned when a user first logs in via SAML JIT

    Note: The role is set to Administrator by default.We recommend first configuring it as Administrator and verifying the SAML JIT connection.

    Note: If you want to assign a different role, you must create the role in microCMS in advance.


    microCMS02.png

  3. Configure as follows, and click the "Change" button again.
    Required

    Configure as desired

    Note: Turning this on will mean the admin screen, etc. can only be accessed via SAML authentication. (Even though password login itself will still work, access to the admin screen will not be allowed.) If you turn this on, please do so only after confirming that SAML authentication was successful.

    Note: If you set the default role to something other than Administrator during the initial SAML setup and turn this toggle on, all members will lose access to the admin screen. For this reason, when testing SAML for the first time, set the default role to Administrator and make sure an administrator user is created via SAML JIT.

    Login URL Copy and make a note of it

    microCMS03.png

Now return to the TrustLogin admin page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" you noted from microCMS
    Value for Name ID Select "Member" - "email" (leave as default)
    Entity ID The "Entity ID" you noted from microCMS
    Name ID Format Select persistent
    ACS URL to Service The "Service Provider Callback URL" you noted from microCMS

    microCMS04.png

  2. Click the "Add SAML Attribute" button in "SAML Attribute Settings" to add a row (attribute), and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    The value of the "email" Attribute noted from microCMS
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    Unspecified http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    Member

    Member - Email Address

    The value of the "name" Attribute noted from microCMS
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    Unspecified http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

    Custom Attribute

    The attribute name you configured
    (e.g., Display Name)

    microCMS05.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

microCMS SAML JIT Setup Guide

Item

Details

Pre-check

  • Prior configuration in microCMS is required.

  • Role assignment via SAML JIT only occurs at the first login. It is not changed on subsequent logins, so if you want to change the role, you will need to change it manually.
  • Please refer to the manual provided by microCMS for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the administrator

Request SP to configure

Provisioning

API-based provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites
When a user is created via SAML JIT, the "Display Name" is synced to microCMS. You need to configure a custom attribute in advance to link microCMS's "Display Name" to the TrustLogin member information.

Note: The attribute name can be anything you choose.

[TrustLogin Custom Attribute Configuration Example]

HUE Project Board11.png

Please refer to the following pages for instructions on how to configure custom attributes.


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button in the upper right of the screen.
    jit01.png


  2. Configure the "Application Name" and "Icon" (optional).
    microCMS06.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".

    03.png

Now, switch to configuring microCMS.
Do not click the "Register" button yet — open microCMS in a separate window.

microCMS Settings

  1. Log in with an administrator account and open "Gear icon > Security > SAML".
    Make a note of the "Service Provider Callback URL" and "Entity ID" values for the microCMS information to enter into the identity provider, as well as the "email" and "name" attribute values.
    microCMS01.png

  2. Configure as follows, and save the settings by clicking "Change".
    Metadata Select the "XML" tab and paste the contents of the TrustLogin metadata
    Default Role

    Select the role to be assigned when a user first logs in via SAML JIT

    Note: The role is set to Administrator by default.We recommend first configuring it as Administrator and verifying the SAML JIT connection.

    Note: If you want to assign a different role, you must create the role in microCMS in advance.


    microCMS02.png

  3. Configure as follows, and click the "Change" button again.
    Required

    Configure as desired

    Note: Turning this on will mean the admin screen, etc. can only be accessed via SAML authentication. (Even though password login itself will still work, access to the admin screen will not be allowed.) If you turn this on, please do so only after confirming that SAML authentication was successful.

    Note: If you set the default role to something other than Administrator during the initial SAML setup and turn this toggle on, all members will lose access to the admin screen. For this reason, when testing SAML for the first time, set the default role to Administrator and make sure an administrator user is created via SAML JIT.

    Login URL Copy and make a note of it

    microCMS03.png

Now return to the TrustLogin admin page.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The "Login URL" you noted from microCMS
    Value for Name ID Select "Member" - "email" (leave as default)
    Entity ID The "Entity ID" you noted from microCMS
    Name ID Format Select persistent
    ACS URL to Service The "Service Provider Callback URL" you noted from microCMS

    microCMS04.png

  2. Click the "Add SAML Attribute" button in "SAML Attribute Settings" to add a row (attribute), and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value
    The value of the "email" Attribute noted from microCMS
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    Unspecified http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress

    Member

    Member - Email Address

    The value of the "name" Attribute noted from microCMS
    http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    Unspecified http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name

    Custom Attribute

    The attribute name you configured
    (e.g., Display Name)

    microCMS05.png

  3. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select the custom SAML app you created, and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.