Sentry SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Sentry is required.

  • The user's "Last Name" and "First Name" are synced only when the account is first created.

  • For the latest setup instructions, please check the manual provided by Sentry.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Sentry (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate using the "Download Certificate" button.
    03.png

  4. Enter the Sentry Organization ID (Organization Slug) in both the "Entity ID" and "ACS URL to Service" fields under "Service Provider Settings".
    09.png

    Note: You can find the Sentry Organization ID (Organization Slug) under "Organization Settings > Organization Slug" in Sentry.
    04.png

  5. Save by clicking the "Register" button.

  6. Sentry performs a connection check when you configure the settings on its side, so please assign an administrator to the SAML app you created to perform the connection check.
    Reference) TrustLogin User Configuration

Sentry Configuration

  1. Open "Organization Settings > Auth" and click the "Configure" button for "SAML2".
    05.png

  2. Select the "IdP Data" tab and configure each item as follows.
    Save by clicking the "Save Metadata" button.
    Entity ID The "Issuer/Entity ID" obtained from TrustLogin
    Single Sign On URL The "Identity Provider URL" obtained from TrustLogin
    x509 public certificate The contents of the "Certificate" obtained from TrustLogin

    06.png

  3. Configure each item with the following values and save by clicking the "Save Attributes" button.
    IdP User ID http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    User Email http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    First Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
    Last Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

    07.png

  4. A message is displayed when SSO is configured correctly.
    08_1.png

  5. The "Login URL" is the login URL used for SP-Initiated SSO. Make a note of it if needed.
    10.png

  6. Scroll down to "General Settings" and configure each item according to your operational needs.
    Require SSO

    Turn this ON if you want to require SAML SSO.
    Note: We recommend keeping this OFF until testing and user notification are complete.

    Enable SCIM Turn this OFF
    Default Role Specify the role to assign when a user is created.

    08_2.png


TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Sentry (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "Sentry (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Sentry SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Sentry is required.

  • The user's "Last Name" and "First Name" are synced only when the account is first created.

  • For the latest setup instructions, please check the manual provided by Sentry.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Sentry (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer/Entity ID" values under "Identity Provider Information", and download the certificate using the "Download Certificate" button.
    03.png

  4. Enter the Sentry Organization ID (Organization Slug) in both the "Entity ID" and "ACS URL to Service" fields under "Service Provider Settings".
    09.png

    Note: You can find the Sentry Organization ID (Organization Slug) under "Organization Settings > Organization Slug" in Sentry.
    04.png

  5. Save by clicking the "Register" button.

  6. Sentry performs a connection check when you configure the settings on its side, so please assign an administrator to the SAML app you created to perform the connection check.
    Reference) TrustLogin User Configuration

Sentry Configuration

  1. Open "Organization Settings > Auth" and click the "Configure" button for "SAML2".
    05.png

  2. Select the "IdP Data" tab and configure each item as follows.
    Save by clicking the "Save Metadata" button.
    Entity ID The "Issuer/Entity ID" obtained from TrustLogin
    Single Sign On URL The "Identity Provider URL" obtained from TrustLogin
    x509 public certificate The contents of the "Certificate" obtained from TrustLogin

    06.png

  3. Configure each item with the following values and save by clicking the "Save Attributes" button.
    IdP User ID http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
    User Email http://schemas.xmlsoap.org/ws/2005/05/identity/claims/emailaddress
    First Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/givenname
    Last Name http://schemas.xmlsoap.org/ws/2005/05/identity/claims/surname

    07.png

  4. A message is displayed when SSO is configured correctly.
    08_1.png

  5. The "Login URL" is the login URL used for SP-Initiated SSO. Make a note of it if needed.
    10.png

  6. Scroll down to "General Settings" and configure each item according to your operational needs.
    Require SSO

    Turn this ON if you want to require SAML SSO.
    Note: We recommend keeping this OFF until testing and user notification are complete.

    Enable SCIM Turn this OFF
    Default Role Specify the role to assign when a user is created.

    08_2.png


TrustLogin User Configuration

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Sentry (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

②When an Administrator Adds a Member

  1. Search for and click the "Sentry (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.