How to Configure SAML Authentication for Zscaler Private Access (User)

 Item

Details 

Prior Confirmation

  • Prior configuration in Zscaler Private Access is required.

  • You must create an account in Zscaler Private Access using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the manual provided by Zscaler.

Name ID

Email address

 

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Zscaler Private Access (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring the Zscaler Private Access side.
Do not click the "Register" button yet — please open the Zscaler Private Access admin portal in a separate window.

Zscaler Private Access Settings

  1. Open "Authentication > User Authentication > IdP Configuration".
    04.png

  2. Click the "+" button in the upper right.
    05.png

  3. Enter any IdP configuration name in "Name", select the target domain in "Domains", and click "Next".
    06.png

  4. Copy and note down the values of "Service Provider URL" and "Service Provider Entity ID".
    Click "Next".
    07.png

  5. Click the "Select File" button under "SAML CONFIGURATION > IdP Metadata File" and upload the metadata obtained from TrustLogin.
    Confirm that "IdP Certificate", "Single Sign-On URL", and "IdP Entity ID" have been automatically populated.
    08.png

  6. Configure each item as follows and save by clicking the "Save" button.
    Status Enabled
    ZPA(SP) SAML Request Unsigned
    HTTP-Redirect Disabled
    Force Authentication Disabled
    Login Hint Enabled
    SAML Attributes  for Policy Enabled

    09.png

Now, return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Service Provider Entity ID" obtained from Zscaler Private Access
    ACS URL to Service The "Service Provider URL" obtained from Zscaler Private Access

    10.png

  2. Save the settings by clicking the "Register" button.

  3. After this, to verify IdP operation in Zscaler Private Access, please assign an administrator to test with the SAML app you created.
    Reference) TrustLogin User Settings

 

Now, return to the Zscaler Private Access admin portal again.

Zscaler Private Access Settings (Continued)

  1. Click the Name of the "IdP Configuration" you configured to expand the configuration details.
    While logged in to TrustLogin, click "Import SAML Attributes > Import".
    11.png

  2. If the SAML attributes are imported correctly, the IdP is working properly.
    Save the settings by clicking the "Save" button.
    12.png

 

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Zscaler Private Access (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Zscaler Private Access (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Zscaler Private Access (User)

 Item

Details 

Prior Confirmation

  • Prior configuration in Zscaler Private Access is required.

  • You must create an account in Zscaler Private Access using the same email address as TrustLogin.

  • For the latest setup instructions, please refer to the manual provided by Zscaler.

Name ID

Email address

 

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Zscaler Private Access (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring the Zscaler Private Access side.
Do not click the "Register" button yet — please open the Zscaler Private Access admin portal in a separate window.

Zscaler Private Access Settings

  1. Open "Authentication > User Authentication > IdP Configuration".
    04.png

  2. Click the "+" button in the upper right.
    05.png

  3. Enter any IdP configuration name in "Name", select the target domain in "Domains", and click "Next".
    06.png

  4. Copy and note down the values of "Service Provider URL" and "Service Provider Entity ID".
    Click "Next".
    07.png

  5. Click the "Select File" button under "SAML CONFIGURATION > IdP Metadata File" and upload the metadata obtained from TrustLogin.
    Confirm that "IdP Certificate", "Single Sign-On URL", and "IdP Entity ID" have been automatically populated.
    08.png

  6. Configure each item as follows and save by clicking the "Save" button.
    Status Enabled
    ZPA(SP) SAML Request Unsigned
    HTTP-Redirect Disabled
    Force Authentication Disabled
    Login Hint Enabled
    SAML Attributes  for Policy Enabled

    09.png

Now, return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Service Provider Entity ID" obtained from Zscaler Private Access
    ACS URL to Service The "Service Provider URL" obtained from Zscaler Private Access

    10.png

  2. Save the settings by clicking the "Register" button.

  3. After this, to verify IdP operation in Zscaler Private Access, please assign an administrator to test with the SAML app you created.
    Reference) TrustLogin User Settings

 

Now, return to the Zscaler Private Access admin portal again.

Zscaler Private Access Settings (Continued)

  1. Click the Name of the "IdP Configuration" you configured to expand the configuration details.
    While logged in to TrustLogin, click "Import SAML Attributes > Import".
    11.png

  2. If the SAML attributes are imported correctly, the IdP is working properly.
    Save the settings by clicking the "Save" button.
    12.png

 

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Zscaler Private Access (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an Administrator Adds Members

  1. Search for and click the "Zscaler Private Access (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.