|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
|
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
|
IdP-Initiated SSO |
|
|
Verified Operation by Device |
ー |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Zscaler Private Access (SAML)".
-
Download the metadata from the "Download Metadata" button under "Identity Provider Information".
Now, switch to configuring the Zscaler Private Access side.
Do not click the "Register" button yet — please open the Zscaler Private Access admin portal in a separate window.
Zscaler Private Access Settings
-
Open "Authentication > User Authentication > IdP Configuration".
- Click the "+" button in the upper right.
- Enter any IdP configuration name in "Name", select the target domain in "Domains", and click "Next".
- Copy and note down the values of "Service Provider URL" and "Service Provider Entity ID".
Click "Next".
- Click the "Select File" button under "SAML CONFIGURATION > IdP Metadata File" and upload the metadata obtained from TrustLogin.
Confirm that "IdP Certificate", "Single Sign-On URL", and "IdP Entity ID" have been automatically populated. -
Configure each item as follows and save by clicking the "Save" button.
Status Enabled ZPA(SP) SAML Request Unsigned HTTP-Redirect Disabled Force Authentication Disabled Login Hint Enabled SAML Attributes for Policy Enabled
Now, return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Service Provider Entity ID" obtained from Zscaler Private Access ACS URL to Service The "Service Provider URL" obtained from Zscaler Private Access
- Save the settings by clicking the "Register" button.
- After this, to verify IdP operation in Zscaler Private Access, please assign an administrator to test with the SAML app you created.
Reference) TrustLogin User Settings
Now, return to the Zscaler Private Access admin portal again.
Zscaler Private Access Settings (Continued)
- Click the Name of the "IdP Configuration" you configured to expand the configuration details.
While logged in to TrustLogin, click "Import SAML Attributes > Import".
- If the SAML attributes are imported correctly, the IdP is working properly.
Save the settings by clicking the "Save" button.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Zscaler Private Access (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
②When an Administrator Adds Members
- Search for and click the "Zscaler Private Access (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.