How to Configure SAML Authentication for Zendesk

Note: Prior configuration in Zendesk is required.
Note: You must have already created an account in Zendesk using the same email address as your TrustLogin account.
Note: Please refer to the manual provided by Zendesk for the latest configuration steps.

Enabling SAML Single Sign-On (Professional and Enterprise)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Zendesk (SAML)".
    Note: If you want to configure a redirect to a specific URL after logging in via SAML authentication, select "Zendesk (Custom URL Version) (SAML)" instead.

    02.png

  3. Note the "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and click "Get Certificate" to download the certificate.
    (This will be needed later when configuring Zendesk.)
    03.png

  4. Change the file extension of the downloaded certificate to [.cer] and open the file.
    zendesk_saml_04_1.png
    zendesk_saml_04_2.png

    Note the value of the "Thumbprint" field on the "Details" tab.
    zendesk_saml_04_3.png

  5. Configure the "Service Provider Settings".

    For the "Login URL", enter https://[your Zendesk subdomain].zendesk.com or https://[your Zendesk subdomain].zendesk.com/hc/ja/signin ,
    and for "Redirect URL after successful SP authentication", "Entity ID", and "ACS URL to Service", enter [your Zendesk subdomain].
    05.png

    If you have selected the "Zendesk (Custom URL Version) (SAML)" SAML template, enter the applicable URL in "Redirect URL after successful SP authentication" if you want to fix the page displayed after login; otherwise, leave it blank. All other items are the same as in the standard version.
    12.png

  6. Click the "Register" button.
    06.png

Zendesk Configuration

  1. Click the Zendesk product icon in the top menu bar and select "Admin Center".

    zendesk_saml_07.png

  2. From the left sidebar of the Admin Center, select "Security > Single sign-on", and click "Configure" for SAML.

    zendesk_saml_08.png

  3. Check the box to enable SAML, and register the following information based on what you noted in steps 3 and 4 of "TrustLogin Admin Page Settings" above.

    Zendesk TrustLogin
    SAML SSO URL Identity Provider URL
    Certificate Fingerprint Converted from the certificate
    Remote Logout URL

    https://portal.trustlogin.com/



    zendesk_saml_09.png

  4. Click "Save" to complete.

  5. Next, configure who SAML authentication applies to (staff members, end users, or both).

    【Staff Members】
    From the left sidebar, select "Security > Staff Members".
    Check "External Authentication", select "Single sign-on", and click "Save".

    zendesk_saml_10.png

    【End Users】
    From the left sidebar, select "Security > End Users".
    Check "External Authentication" and click "Save".

    zendesk_saml_11.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Zendesk (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Zendesk (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Zendesk

Note: Prior configuration in Zendesk is required.
Note: You must have already created an account in Zendesk using the same email address as your TrustLogin account.
Note: Please refer to the manual provided by Zendesk for the latest configuration steps.

Enabling SAML Single Sign-On (Professional and Enterprise)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "Zendesk (SAML)".
    Note: If you want to configure a redirect to a specific URL after logging in via SAML authentication, select "Zendesk (Custom URL Version) (SAML)" instead.

    02.png

  3. Note the "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and click "Get Certificate" to download the certificate.
    (This will be needed later when configuring Zendesk.)
    03.png

  4. Change the file extension of the downloaded certificate to [.cer] and open the file.
    zendesk_saml_04_1.png
    zendesk_saml_04_2.png

    Note the value of the "Thumbprint" field on the "Details" tab.
    zendesk_saml_04_3.png

  5. Configure the "Service Provider Settings".

    For the "Login URL", enter https://[your Zendesk subdomain].zendesk.com or https://[your Zendesk subdomain].zendesk.com/hc/ja/signin ,
    and for "Redirect URL after successful SP authentication", "Entity ID", and "ACS URL to Service", enter [your Zendesk subdomain].
    05.png

    If you have selected the "Zendesk (Custom URL Version) (SAML)" SAML template, enter the applicable URL in "Redirect URL after successful SP authentication" if you want to fix the page displayed after login; otherwise, leave it blank. All other items are the same as in the standard version.
    12.png

  6. Click the "Register" button.
    06.png

Zendesk Configuration

  1. Click the Zendesk product icon in the top menu bar and select "Admin Center".

    zendesk_saml_07.png

  2. From the left sidebar of the Admin Center, select "Security > Single sign-on", and click "Configure" for SAML.

    zendesk_saml_08.png

  3. Check the box to enable SAML, and register the following information based on what you noted in steps 3 and 4 of "TrustLogin Admin Page Settings" above.

    Zendesk TrustLogin
    SAML SSO URL Identity Provider URL
    Certificate Fingerprint Converted from the certificate
    Remote Logout URL

    https://portal.trustlogin.com/



    zendesk_saml_09.png

  4. Click "Save" to complete.

  5. Next, configure who SAML authentication applies to (staff members, end users, or both).

    【Staff Members】
    From the left sidebar, select "Security > Staff Members".
    Check "External Authentication", select "Single sign-on", and click "Save".

    zendesk_saml_10.png

    【End Users】
    From the left sidebar, select "Security > End Users".
    Check "External Authentication" and click "Save".

    zendesk_saml_11.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Zendesk (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "Zendesk (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.