Slack SAML JIT Setup Guide

Note: SAML authentication can be used with the web browser, desktop app, and mobile app.
Note: Prior configuration in Slack is required.
Note: For the latest setup instructions, please check the manual provided by Slack.

Slack Help Center "SAML Single Sign-On"
https://get.slack.help/hc/ja/articles/203772216

Note: When you configure SAML authentication in Slack, account information is synced by default (account creation, license assignment, information sync) via a mechanism called JIT provisioning (Just-In-Time provisioning).
For details, please see About SAML JIT.




TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.

    slack_saml_01.png

  2. Search on the "Register Company App" screen and select "Slack (SAML)".

    slack_saml_02.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and the contents of the certificate downloaded by clicking "Get Certificate".
    (These will be needed later when configuring Slack.)

    slack_saml_03.png


  4. Enter your Slack workspace name in the "Login URL", "Entity ID", "ACS URL to Service", and "Logout URL" fields under "Service Provider Settings".
    ([Your Slack workspace name].slack.com)

    slack_saml_04.png


  5. You do not need to configure the "SAML Attribute Settings" items. Please proceed to the next step as is.

    slack_saml_11.png

  6. Click the "Register" button.

    slack_saml_05_1.png

  7. Search for and click the "Slack (SAML)" app you created in the "Admin Page > App" menu.

    slack_saml_05_2.png

  8. Click "Add Member", select the administrator from the member list, and click the "Register" button to add them. (A connection test will be performed once the configuration in Slack is complete.)

    slack_saml_05_2.png

Slack Settings

Log in to Slack with an administrator account.

  1. Click the workspace name in the upper left of the screen, and select "Other Admin Settings > Workspace Settings" from the menu.

    slack_saml_06.png

  2. Click the "Authentication" tab, and click the "Change Settings" button to the right of SAML authentication.

    slack_saml_07.png

  3. On the "SAML Authentication Settings" screen, enter the information you noted down in step 3 of "TrustLogin Admin Page Settings" above, as follows.

    Slack TrustLogin
    SAML 2.0 Endpoint (HTTP) Identity Provider URL
    Identity Provider Issuer Issuer / Entity ID
    Public Certificate Certificate


    slack_saml_08.png

  4. Open "Advanced Settings" and enter
    https://[your workspace name].slack.com in the "Service Provider Issuer" field.

    Uncheck "Signed Response" and check "Signed Assertion".

    slack_saml_09.png

  5. Under "Settings", if you want to sync TrustLogin username information to Slack, check "Update profile every time a user logs in". Also, configure the target members under "Members who require workspace authentication".

    slack_saml_12.png

  6. Click "Save Settings" to complete the setup.
    Note: When you save, Slack automatically performs an authentication test, so the user assigned in step 7 of "TrustLogin Admin Page Settings" must be logged in to TrustLogin in a separate browser tab.

    slack_saml_10.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Slack (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. Search for and click the "Slack (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

About SAML JIT

① Information Synced to Accounts
When TrustLogin and Slack are connected via identity federation, member information is mapped as follows.

TrustLogin Slack
Email address Email
First name + Last name Full name
The part of the email before the @ Display name
The part of the email before the @ Username
Note: The username can be up to 21 characters. If it exceeds 21 characters, it will be truncated to 21 characters.

② If You Do Not Want Account Sync via SAML JIT
When you configure SAML authentication, account sync is performed by default via JIT provisioning
(licenses are also assigned automatically), and TrustLogin (the IdP) cannot control whether this account sync occurs.
If you want to allow members to add the Slack app themselves, but do not want Slack accounts to be automatically created or synced, please request that SAML JIT be disabled via the help screen in the Slack admin portal.
If you have any questions, please contact Slack.

Slack SAML JIT Setup Guide

Note: SAML authentication can be used with the web browser, desktop app, and mobile app.
Note: Prior configuration in Slack is required.
Note: For the latest setup instructions, please check the manual provided by Slack.

Slack Help Center "SAML Single Sign-On"
https://get.slack.help/hc/ja/articles/203772216

Note: When you configure SAML authentication in Slack, account information is synced by default (account creation, license assignment, information sync) via a mechanism called JIT provisioning (Just-In-Time provisioning).
For details, please see About SAML JIT.




TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.

    slack_saml_01.png

  2. Search on the "Register Company App" screen and select "Slack (SAML)".

    slack_saml_02.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" under "Identity Provider Information", and the contents of the certificate downloaded by clicking "Get Certificate".
    (These will be needed later when configuring Slack.)

    slack_saml_03.png


  4. Enter your Slack workspace name in the "Login URL", "Entity ID", "ACS URL to Service", and "Logout URL" fields under "Service Provider Settings".
    ([Your Slack workspace name].slack.com)

    slack_saml_04.png


  5. You do not need to configure the "SAML Attribute Settings" items. Please proceed to the next step as is.

    slack_saml_11.png

  6. Click the "Register" button.

    slack_saml_05_1.png

  7. Search for and click the "Slack (SAML)" app you created in the "Admin Page > App" menu.

    slack_saml_05_2.png

  8. Click "Add Member", select the administrator from the member list, and click the "Register" button to add them. (A connection test will be performed once the configuration in Slack is complete.)

    slack_saml_05_2.png

Slack Settings

Log in to Slack with an administrator account.

  1. Click the workspace name in the upper left of the screen, and select "Other Admin Settings > Workspace Settings" from the menu.

    slack_saml_06.png

  2. Click the "Authentication" tab, and click the "Change Settings" button to the right of SAML authentication.

    slack_saml_07.png

  3. On the "SAML Authentication Settings" screen, enter the information you noted down in step 3 of "TrustLogin Admin Page Settings" above, as follows.

    Slack TrustLogin
    SAML 2.0 Endpoint (HTTP) Identity Provider URL
    Identity Provider Issuer Issuer / Entity ID
    Public Certificate Certificate


    slack_saml_08.png

  4. Open "Advanced Settings" and enter
    https://[your workspace name].slack.com in the "Service Provider Issuer" field.

    Uncheck "Signed Response" and check "Signed Assertion".

    slack_saml_09.png

  5. Under "Settings", if you want to sync TrustLogin username information to Slack, check "Update profile every time a user logs in". Also, configure the target members under "Members who require workspace authentication".

    slack_saml_12.png

  6. Click "Save Settings" to complete the setup.
    Note: When you save, Slack automatically performs an authentication test, so the user assigned in step 7 of "TrustLogin Admin Page Settings" must be logged in to TrustLogin in a separate browser tab.

    slack_saml_10.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Slack (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. Search for and click the "Slack (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

About SAML JIT

① Information Synced to Accounts
When TrustLogin and Slack are connected via identity federation, member information is mapped as follows.

TrustLogin Slack
Email address Email
First name + Last name Full name
The part of the email before the @ Display name
The part of the email before the @ Username
Note: The username can be up to 21 characters. If it exceeds 21 characters, it will be truncated to 21 characters.

② If You Do Not Want Account Sync via SAML JIT
When you configure SAML authentication, account sync is performed by default via JIT provisioning
(licenses are also assigned automatically), and TrustLogin (the IdP) cannot control whether this account sync occurs.
If you want to allow members to add the Slack app themselves, but do not want Slack accounts to be automatically created or synced, please request that SAML JIT be disabled via the help screen in the Slack admin portal.
If you have any questions, please contact Slack.