|
Item |
Details |
|
|---|---|---|
|
Prior Confirmation |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in TrustLogin) |
|
|
SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
〇 |
PC - Desktop App |
|
|
ー |
iOS - Standard Browser (Safari) |
|
|
ー |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
ー |
Android - Standard Browser (Chrome) |
|
|
ー |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
Note: If you are using client authentication, SSO is not available on iOS - Native App or Android - Native App.
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Company App" screen, search and select "Stock (SAML)".
- Download the metadata using the "Download Metadata" button under "Identity Provider Information".
Now, switch to the Stock settings.
Without clicking the "Register" button, open Stock in a separate window.
Stock Settings
- Click "Settings > Change Team Settings".
- Open "Single Sign-On", configure it as follows, and click "Change".
Entity ID Copy it and keep a note of it ACS URL Copy it and keep a note of it Upload XML File Upload the metadata you saved from TrustLogin Enable Single Sign-On Select "Migration Mode"
Note: In "Migration Mode", logging in with a password is also possible. Once you have confirmed that team members can successfully log in via single sign-on, we recommend switching to "Single Sign-On Only" mode.
- After clicking the "Change" button, the "Single Sign-On URL" is displayed.
This is the URL for SP-initiated SSO, so make a note of it if needed.
Now, return to the TrustLogin Admin Page.
TrustLogin Admin Page Settings (Continued)
- Configure "Service Provider Settings" as follows.
Entity ID The "Entity ID" you noted from Stock ACS URL to Service The "ACS URL" you noted from Stock
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "Stock (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for and click the "Stock (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Mobile App Login Method
Install the mobile app and select "Other > Single Sign-On".
Enter your team's domain and click "Login" to be redirected to the TrustLogin login screen.
Note: Your team's domain is the "***" portion of the Stock URL "https://www.stock-app.jp/sso/***/sign-in".