How to Configure SAML Authentication for Dropbox

Item

Description

Prerequisites

  • Prior setup on the Dropbox side is required.

  • Single sign-on is available with Dropbox's Advanced or Enterprise plan.
  • You must create an account in Dropbox using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Dropbox.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side settings

Configured by the administrator

Request the SP to configure the settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operating environment by device

PC - Browser

PC - Desktop app

iOS - Default browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Default browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    dropbox_saml_01.png

  2. Search on the "Register Corporate App" screen and select "Dropbox (SAML)".

    dropbox_saml_02.png

  3. Note down the "Identity Provider URL" in the "Identity Provider Information" section, and download the certificate from "Get Certificate".
    (You will need this later when configuring the settings on the Dropbox side.)

    dropbox_saml_03.png

Now, let's move on to the settings on the Dropbox side.
Please open the Dropbox admin page in a separate tab.

Dropbox Settings

  1. Select "Admin Console" from the left-hand menu.

    dropbox_saml_04.png

  2. Select "Settings > Single sign-on".

    dropbox_saml_06.png

  3. Select how members log in under "Single sign-on". Choose "Optional" or "Required" from the drop-down list.
    Note: If you select "Required", members will only be able to log in via SSO. We recommend selecting "Required" only after confirming that SAML SSO works successfully and notifying your users.

    DropBox.png

  4. Configure the Dropbox settings as follows.
    Identity provider sign-in URL Enter the "Identity Provider URL" you noted from TrustLogin
    X.509 certificate Upload the "certificate" you obtained from TrustLogin

    dropbox_saml_06.png

  5. Copy the "SSO Sign-in URL" link and click "Save".

    dropbox_saml_07.png

    Now, return to the TrustLogin admin page.

TrustLogin Admin Page Settings (continued)

  1. Enter the following in the "Service Provider Settings":

    Sign-in URL

    The "SSO Sign-in URL" you noted from Dropbox
    Entity ID

    The unique value for your account at the end of the "SSO Sign-in URL" you noted from Dropbox

    Example: https://www.dropbox.com/sso/[your unique value]

    dropbox_saml_08.png

   

 5. Click the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Dropbox (SAML)" on the "Register App" screen and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. On the "Admin Page > Apps" menu, search for and click the "Dropbox (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Dropbox

Item

Description

Prerequisites

  • Prior setup on the Dropbox side is required.

  • Single sign-on is available with Dropbox's Advanced or Enterprise plan.
  • You must create an account in Dropbox using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Dropbox.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side settings

Configured by the administrator

Request the SP to configure the settings

Provisioning

Supports provisioning via API (accounts can be managed in TrustLogin)

Supports SAML JIT provisioning (accounts can be managed in TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operating environment by device

PC - Browser

PC - Desktop app

iOS - Default browser (Safari)

iOS - In-app browser of the TrustLogin mobile app

iOS - Native app

Android - Default browser (Chrome)

Android - In-app browser of the TrustLogin mobile app

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.

    dropbox_saml_01.png

  2. Search on the "Register Corporate App" screen and select "Dropbox (SAML)".

    dropbox_saml_02.png

  3. Note down the "Identity Provider URL" in the "Identity Provider Information" section, and download the certificate from "Get Certificate".
    (You will need this later when configuring the settings on the Dropbox side.)

    dropbox_saml_03.png

Now, let's move on to the settings on the Dropbox side.
Please open the Dropbox admin page in a separate tab.

Dropbox Settings

  1. Select "Admin Console" from the left-hand menu.

    dropbox_saml_04.png

  2. Select "Settings > Single sign-on".

    dropbox_saml_06.png

  3. Select how members log in under "Single sign-on". Choose "Optional" or "Required" from the drop-down list.
    Note: If you select "Required", members will only be able to log in via SSO. We recommend selecting "Required" only after confirming that SAML SSO works successfully and notifying your users.

    DropBox.png

  4. Configure the Dropbox settings as follows.
    Identity provider sign-in URL Enter the "Identity Provider URL" you noted from TrustLogin
    X.509 certificate Upload the "certificate" you obtained from TrustLogin

    dropbox_saml_06.png

  5. Copy the "SSO Sign-in URL" link and click "Save".

    dropbox_saml_07.png

    Now, return to the TrustLogin admin page.

TrustLogin Admin Page Settings (continued)

  1. Enter the following in the "Service Provider Settings":

    Sign-in URL

    The "SSO Sign-in URL" you noted from Dropbox
    Entity ID

    The unique value for your account at the end of the "SSO Sign-in URL" you noted from Dropbox

    Example: https://www.dropbox.com/sso/[your unique value]

    dropbox_saml_08.png

   

 5. Click the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. Select "Dropbox (SAML)" on the "Register App" screen and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an administrator adds a member

  1. On the "Admin Page > Apps" menu, search for and click the "Dropbox (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.