Note: Prior configuration in Zendesk is required.
Note: You must have already created an account in Zendesk using the same email address as your TrustLogin account.
Note: Please refer to the manual provided by Zendesk for the latest configuration steps.
Enabling SAML Single Sign-On (Professional and Enterprise)
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search for and select "Zendesk (SAML)".
Note: If you want to configure a redirect to a specific URL after logging in via SAML authentication, select "Zendesk (Custom URL Version) (SAML)" instead.
- Note the "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and click "Get Certificate" to download the certificate.
(This will be needed later when configuring Zendesk.)
- Change the file extension of the downloaded certificate to [.cer] and open the file.
Note the value of the "Thumbprint" field on the "Details" tab.
- Configure the "Service Provider Settings".
For the "Login URL", enter https://[your Zendesk subdomain].zendesk.com or https://[your Zendesk subdomain].zendesk.com/hc/ja/signin ,
and for "Redirect URL after successful SP authentication", "Entity ID", and "ACS URL to Service", enter [your Zendesk subdomain].
If you have selected the "Zendesk (Custom URL Version) (SAML)" SAML template, enter the applicable URL in "Redirect URL after successful SP authentication" if you want to fix the page displayed after login; otherwise, leave it blank. All other items are the same as in the standard version.
- Click the "Register" button.
Zendesk Configuration
- Click the Zendesk product icon in the top menu bar and select "Admin Center".
- From the left sidebar of the Admin Center, select "Security > Single sign-on", and click "Configure" for SAML.
- Check the box to enable SAML, and register the following information based on what you noted in steps 3 and 4 of "TrustLogin Admin Page Settings" above.
Zendesk TrustLogin SAML SSO URL Identity Provider URL Certificate Fingerprint Converted from the certificate Remote Logout URL https://portal.trustlogin.com/
- Click "Save" to complete.
- Next, configure who SAML authentication applies to (staff members, end users, or both).
【Staff Members】
From the left sidebar, select "Security > Staff Members".
Check "External Authentication", select "Single sign-on", and click "Save".
【End Users】
From the left sidebar, select "Security > End Users".
Check "External Authentication" and click "Save".
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Zendesk (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app on "My Page" or in the "browser extension" and check that login succeeds.
② When an Administrator Adds Members
- Search for and click the "Zendesk (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.