How to Configure SAML Authentication for Assured

Item

Details

Pre-check

  • Prior configuration in Assured is required.

  • You must create an account in Assured using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Assured.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP Configuration

Configured by the Administrator

Request configuration from SP

Provisioning

API-based Provisioning supported (account management available via TrustLogin)

SAML JITProvisioning supported (account management available via TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Login is possible, but this is not a recommended environment.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "Assured (SAML)".
    Assured05.png

  3. Make a note of the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information", then download the certificate using the "Get Certificate" button.03.png

Now, proceed to the Assured settings.
Do not click the "Register" button yet; open Assured in a separate window.

Assured Settings

  1. Open "Organization Settings > Authentication/IP Restrictions > SAML SSO Settings", and use the copy buttons to note down the "SP Entity ID (Issuer)" and "ACS URL (Endpoint URL)". Then, click the "Edit" button under "Identity Provider Settings".
    Assured02.png

  2. Configure "Identity Provider Settings" as follows, and click the "Submit" button.
    IdP Entity ID (Issuer) The "Issuer/Entity ID" you noted from TrustLogin
    SSO URL (Endpoint URL) The "IdP URL" you noted from TrustLogin
    X.509 Certificate Paste the contents of the "Certificate" you downloaded from TrustLogin

    Assured03.png

Return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The login URL of Assured
    Note: Please set the URL for your environment.

    For user companies: https://c.assured.jp/login

    For provider companies: https://p.assured.jp/login

    Entity ID The "SP Entity ID (Issuer)" you noted from Assured
    ACS URL to Service The "ACS URL (Endpoint URL)" you noted from Assured

    Assured01.png


  2. Save by clicking the "Register" button.

Assured Settings (continued)

  1. On the "Identity Provider Settings" screen, check the "Enable SAML Authentication" checkbox.
    Note: Once SAML authentication is enabled, all users belonging to the organization will be required to log in via single sign-on.
    Assured04.png


TrustLogin User Settings

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. In the "Register App" screen, select "Assured (SAML)" and click the "Next" button in the upper right.
  3. If you wish to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. In the "Admin Page > App" menu, search for and click the "Assured (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In

When logging in with "Assured (SAML)"

Running "Assured (SAML)" from My Page or the browser extension will take you to the Assured login screen.

Enter your email address, then click the "Continue" button to complete the login.
Assured.png


② When using the auxiliary app

Omitting the email address entry from the login process described in ① is possible using the auxiliary apps "[SAML Auxiliary] Assured (Provider Company)" and "[SAML Auxiliary] Assured (User Company)", which we also provide.

Note: Please disable your browser's pop-up blocker before using this. (If pop-ups are blocked, automatic entry will not work.)
Note: The auxiliary apps can only be used in a PC browser.

  1. The login URL differs between "[SAML Auxiliary] Assured (Provider Company)" and "[SAML Auxiliary] Assured (User Company)". Search on the "Register Company App" screen and select the app matching your Assured environment.
    assured_hojyo.png

    Assured06.png

    Assured07.png


  2. Save by clicking the "Register" button.

  3. Add the app using the same procedure as a standard app registration, either by the administrator or by the user themselves.

How to Configure SAML Authentication for Assured

Item

Details

Pre-check

  • Prior configuration in Assured is required.

  • You must create an account in Assured using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Assured.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP Configuration

Configured by the Administrator

Request configuration from SP

Provisioning

API-based Provisioning supported (account management available via TrustLogin)

SAML JITProvisioning supported (account management available via TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

Login is possible, but this is not a recommended environment.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search for and select "Assured (SAML)".
    Assured05.png

  3. Make a note of the "IdP URL" and "Issuer/Entity ID" values under "Identity Provider Information", then download the certificate using the "Get Certificate" button.03.png

Now, proceed to the Assured settings.
Do not click the "Register" button yet; open Assured in a separate window.

Assured Settings

  1. Open "Organization Settings > Authentication/IP Restrictions > SAML SSO Settings", and use the copy buttons to note down the "SP Entity ID (Issuer)" and "ACS URL (Endpoint URL)". Then, click the "Edit" button under "Identity Provider Settings".
    Assured02.png

  2. Configure "Identity Provider Settings" as follows, and click the "Submit" button.
    IdP Entity ID (Issuer) The "Issuer/Entity ID" you noted from TrustLogin
    SSO URL (Endpoint URL) The "IdP URL" you noted from TrustLogin
    X.509 Certificate Paste the contents of the "Certificate" you downloaded from TrustLogin

    Assured03.png

Return to the TrustLogin Admin Page.

TrustLogin Admin Page Settings (continued)

  1. Configure "Service Provider Settings" as follows.
    Login URL The login URL of Assured
    Note: Please set the URL for your environment.

    For user companies: https://c.assured.jp/login

    For provider companies: https://p.assured.jp/login

    Entity ID The "SP Entity ID (Issuer)" you noted from Assured
    ACS URL to Service The "ACS URL (Endpoint URL)" you noted from Assured

    Assured01.png


  2. Save by clicking the "Register" button.

Assured Settings (continued)

  1. On the "Identity Provider Settings" screen, check the "Enable SAML Authentication" checkbox.
    Note: Once SAML authentication is enabled, all users belonging to the organization will be required to log in via single sign-on.
    Assured04.png


TrustLogin User Settings

① When a user adds the app from My Page

  1. On "My Page", click the "Add App" button.
  2. In the "Register App" screen, select "Assured (SAML)" and click the "Next" button in the upper right.
  3. If you wish to change the "Display Name", enter it and click the "Save" button.

② When an administrator adds members

  1. In the "Admin Page > App" menu, search for and click the "Assured (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In

When logging in with "Assured (SAML)"

Running "Assured (SAML)" from My Page or the browser extension will take you to the Assured login screen.

Enter your email address, then click the "Continue" button to complete the login.
Assured.png


② When using the auxiliary app

Omitting the email address entry from the login process described in ① is possible using the auxiliary apps "[SAML Auxiliary] Assured (Provider Company)" and "[SAML Auxiliary] Assured (User Company)", which we also provide.

Note: Please disable your browser's pop-up blocker before using this. (If pop-ups are blocked, automatic entry will not work.)
Note: The auxiliary apps can only be used in a PC browser.

  1. The login URL differs between "[SAML Auxiliary] Assured (Provider Company)" and "[SAML Auxiliary] Assured (User Company)". Search on the "Register Company App" screen and select the app matching your Assured environment.
    assured_hojyo.png

    Assured06.png

    Assured07.png


  2. Save by clicking the "Register" button.

  3. Add the app using the same procedure as a standard app registration, either by the administrator or by the user themselves.