Cisco Meraki SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Cisco Meraki is required.

  • For the latest setup instructions, please check the manual provided by Cisco Meraki.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

Add a Custom Attribute to User Information

Add the Cisco Meraki "Username" and "SAML Administrator Role" information as custom attributes in TrustLogin member information.


[TrustLogin Custom Attribute Configuration Example]

  • The attribute name for the custom attribute can be anything you choose.
  • The attribute value for "SAML Administrator Role" is the name of the SAML administrator role you will configure on the Cisco Meraki side later.

    00_1.png

Please refer to the following pages for instructions on how to configure custom attributes.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

The "SAML Administrator Role" can also be configured using group mapping, but this manual introduces the setup method using a custom attribute.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the "Identity Provider URL" value under "Identity Provider Information", and download the certificate using the "Download Certificate" button.
    03.png

  4. Change the extension of the downloaded certificate to [.cer] and open the file.
    04.png
    05.png

    Copy the value of the "Thumbprint" field on the "Details" tab.
    06.png

    Paste the copied "Thumbprint" value into a text editor or similar, and generate a value with a colon (:) inserted every 2 characters.

    07.png

Now, switch over to configuring the Cisco Meraki side.
Do not click the "Register" button yet — open the Cisco Meraki dashboard in a separate window.

Cisco Meraki Configuration

  1. Open "Organization" > "Settings".
    08.png

  2. Go to the "Authentication" settings, switch on "SAML SSO enabled", and specify any subdomain for "SSO Subdomain". Click "Add a SAML IdP".
    09.png

  3. Configure the settings as follows, and save by clicking the "Save" button at the bottom right.
    X.509 cert SHA1 fingerprint The "Thumbprint" value generated in Step 4 above
    SSO login URL The "Identity Provider URL" obtained from TrustLogin

    10.png

  4. Make a note of either the "Consumer URL" or "Consumer URL (Vision)".
    This URL is where users will be redirected to after authentication, so choose it according to your operational needs.
    11.png

  5. Select the thumbprint of the SAML IdP you configured under "SP initiated SAML IdP", and save by clicking the "Save" button.
    16.png

    For SP-Initiated SSO, you can log in from the following URLs.
    https://account.meraki.com/login/dashboard_login?sso=true
    [your configured SSO Subdomain].sso.meraki.com
    Meraki Vision login page

  6. Open "Organization" > "Administrators".
    12.png

  7. Click the "Add a SAML role" button to add an administrator role setting.
    The role name is the attribute value you added to the custom attribute.
    Save by clicking the "Save changes" button.
    13.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID https://[the SSO Subdomain you configured in Cisco Meraki].sso.meraki.com
    Name ID Format emailAddress
    ACS URL to Service

    The "Consumer URL" or "Consumer URL (Vision)" obtained from Cisco Meraki


    14.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value

    Value ①

    Basic

    Value ①

    Custom Attribute

    The attribute name in which "Username" was configured

    Value ② Basic Value ② Custom Attribute The attribute name in which "SAML Administrator Role" was configured
    https://dashboard.meraki.com/saml/attributes/username
    https://dashboard.meraki.com/saml/attributes/role

    15.png

  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Cisco Meraki SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Cisco Meraki is required.

  • For the latest setup instructions, please check the manual provided by Cisco Meraki.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Prerequisites

Add a Custom Attribute to User Information

Add the Cisco Meraki "Username" and "SAML Administrator Role" information as custom attributes in TrustLogin member information.


[TrustLogin Custom Attribute Configuration Example]

  • The attribute name for the custom attribute can be anything you choose.
  • The attribute value for "SAML Administrator Role" is the name of the SAML administrator role you will configure on the Cisco Meraki side later.

    00_1.png

Please refer to the following pages for instructions on how to configure custom attributes.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

The "SAML Administrator Role" can also be configured using group mapping, but this manual introduces the setup method using a custom attribute.

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register SAML App" button at the top right of the screen.
    01.png

  2. Configure the "Application Name" and "Icon" (optional).
    02.png

  3. Note down the "Identity Provider URL" value under "Identity Provider Information", and download the certificate using the "Download Certificate" button.
    03.png

  4. Change the extension of the downloaded certificate to [.cer] and open the file.
    04.png
    05.png

    Copy the value of the "Thumbprint" field on the "Details" tab.
    06.png

    Paste the copied "Thumbprint" value into a text editor or similar, and generate a value with a colon (:) inserted every 2 characters.

    07.png

Now, switch over to configuring the Cisco Meraki side.
Do not click the "Register" button yet — open the Cisco Meraki dashboard in a separate window.

Cisco Meraki Configuration

  1. Open "Organization" > "Settings".
    08.png

  2. Go to the "Authentication" settings, switch on "SAML SSO enabled", and specify any subdomain for "SSO Subdomain". Click "Add a SAML IdP".
    09.png

  3. Configure the settings as follows, and save by clicking the "Save" button at the bottom right.
    X.509 cert SHA1 fingerprint The "Thumbprint" value generated in Step 4 above
    SSO login URL The "Identity Provider URL" obtained from TrustLogin

    10.png

  4. Make a note of either the "Consumer URL" or "Consumer URL (Vision)".
    This URL is where users will be redirected to after authentication, so choose it according to your operational needs.
    11.png

  5. Select the thumbprint of the SAML IdP you configured under "SP initiated SAML IdP", and save by clicking the "Save" button.
    16.png

    For SP-Initiated SSO, you can log in from the following URLs.
    https://account.meraki.com/login/dashboard_login?sso=true
    [your configured SSO Subdomain].sso.meraki.com
    Meraki Vision login page

  6. Open "Organization" > "Administrators".
    12.png

  7. Click the "Add a SAML role" button to add an administrator role setting.
    The role name is the attribute value you added to the custom attribute.
    Save by clicking the "Save changes" button.
    13.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Configuration (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID https://[the SSO Subdomain you configured in Cisco Meraki].sso.meraki.com
    Name ID Format emailAddress
    ACS URL to Service

    The "Consumer URL" or "Consumer URL (Vision)" obtained from Cisco Meraki


    14.png

  2. Click the "Specify Custom Attribute" button in "SAML Attribute Settings", then add a row (attribute) using the "Add SAML Attribute" button and configure it as follows.
    Service Provider Attribute TrustLogin (IdP) Attribute
    Attribute Name Attribute Type Attribute Name Attribute Value

    Value ①

    Basic

    Value ①

    Custom Attribute

    The attribute name in which "Username" was configured

    Value ② Basic Value ② Custom Attribute The attribute name in which "SAML Administrator Role" was configured
    https://dashboard.meraki.com/saml/attributes/username
    https://dashboard.meraki.com/saml/attributes/role

    15.png

  3. Save by clicking the "Register" button.

TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select the custom SAML app you created, and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the custom SAML app you created in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.