How to Configure SAML JIT for Amazon Business

Note: Prior configuration in Amazon Business is required.

Note: You need to create an Amazon Business account using the same email address as your TrustLogin (formerly SKUID) account.

Note: For the latest setup instructions, please refer to the manual provided by Amazon Business.
About Single Sign-On for Amazon Business

Note: If a user does not already exist in Amazon Business, the user will be created.

Amazon Business supports Just-In-Time user provisioning. This is enabled by default, and no action is required on the user's part. If a user does not yet exist in Amazon Business, they will be newly created after authentication.

Configuration Steps

TrustLogin Admin Page Settings ①

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.

    amazon_saml_01.png

  2. Search on the "Register Company App" screen and select "Amazon Business (SAML)".

    amazon_saml_02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".

    amazon_saml_21.png

Now, switch to configuring Amazon Business.
Do not click the "Register" button yet — open the Amazon Business admin page in a separate tab.

Amazon Business Settings

  1. Log in to the Amazon Business admin page and open "Business Account Settings".

    amazon_saml_03.png

  2. Open "Single Sign-On (SSO)".

    amazon_saml_04.png
  3. Click "Please select an identity provider (IdP)", select "TrustLogin", and click "Next".

    amazon_saml_05.png
    amazon_saml_06.png
    amazon_saml_07.png

  4. Select the "Default Group" and "Default Purchasing Role", then click "Next".

    amazon_saml_08.png

  5. Use the "Browse" button to select and upload the metadata you downloaded in step 3 of "TrustLogin Admin Page Settings ①" above. On the next screen, confirm that the connection data information has been entered, and click "Next".

    amazon_saml_09.png
    amazon_saml_10.png
  6. "Skip" the next screen.

    amazon_saml_12.png

  7. Add the following items to the attribute mapping, then click "Next".

    Email email

    First Name

    first_name
    Last Name last_name

    amazon_saml_13.png

  8. Download the "Metadata XML File" from the Amazon connection data, then click "Next".

    amazon_saml_14.png

Now, return to configuring TrustLogin again.
Open the TrustLogin Admin Page tab.

TrustLogin Admin Page Settings ②

  1. Using "Select Metadata" under "Service Provider Settings", upload the metadata you downloaded in step 8 of "Amazon Business Settings" above.
    Note: Do not delete this metadata, as you will use it again later.

    amazon_saml_15.png

  2. Click "Register".

    amazon_saml_22.png

  3. Search for Amazon Business using "Search App" and click the app name.

    amazon_saml_23.png
  4. To perform the connection test in Amazon, select the administrator from "Add Member" and click the "Register" button to add them.

    amazon_saml_24.png

Return to the Amazon Business tab again to perform the connection test.

Amazon Business Admin Page Settings (Connection Test)

  1. Check the Amazon connection data and click "Start Testing".
     amazon_saml_16.png

  2. Click "Test".

    amazon_saml_17.png

  3. Make a note of the "IDP initiated URL", then click "Activate".

    amazon_saml_18.png
  4. Confirm that you have completed steps 1 through 3, check the checkbox, and click "Switch to Active".

    amazon_saml_19.png

  5. Confirm that the status is "Active" — the Amazon Business configuration is now complete.

    amazon_saml_20.png

TrustLogin Admin Page Settings (Metadata Correction)

  1. Open the metadata you downloaded in step 8 of "Amazon Business Settings" above in a text editor, rewrite the section below to the "IDP initiated URL" you noted in step 3 of "Amazon Business Admin Page Settings (Connection Test)", and save, overwriting the original file.

    amazon_saml_25.png

  2. Using "Select Metadata" under "Service Provider Settings", upload the metadata you just corrected and overwrote.

    amazon_saml_15.png

  3. Click "Register" to complete the setup.

    amazon_saml_22.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Amazon Business (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and confirm that login succeeds.

② When an Administrator Adds a Member

  1. Search for and click the "Amazon Business (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML JIT for Amazon Business

Note: Prior configuration in Amazon Business is required.

Note: You need to create an Amazon Business account using the same email address as your TrustLogin (formerly SKUID) account.

Note: For the latest setup instructions, please refer to the manual provided by Amazon Business.
About Single Sign-On for Amazon Business

Note: If a user does not already exist in Amazon Business, the user will be created.

Amazon Business supports Just-In-Time user provisioning. This is enabled by default, and no action is required on the user's part. If a user does not yet exist in Amazon Business, they will be newly created after authentication.

Configuration Steps

TrustLogin Admin Page Settings ①

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.

    amazon_saml_01.png

  2. Search on the "Register Company App" screen and select "Amazon Business (SAML)".

    amazon_saml_02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".

    amazon_saml_21.png

Now, switch to configuring Amazon Business.
Do not click the "Register" button yet — open the Amazon Business admin page in a separate tab.

Amazon Business Settings

  1. Log in to the Amazon Business admin page and open "Business Account Settings".

    amazon_saml_03.png

  2. Open "Single Sign-On (SSO)".

    amazon_saml_04.png
  3. Click "Please select an identity provider (IdP)", select "TrustLogin", and click "Next".

    amazon_saml_05.png
    amazon_saml_06.png
    amazon_saml_07.png

  4. Select the "Default Group" and "Default Purchasing Role", then click "Next".

    amazon_saml_08.png

  5. Use the "Browse" button to select and upload the metadata you downloaded in step 3 of "TrustLogin Admin Page Settings ①" above. On the next screen, confirm that the connection data information has been entered, and click "Next".

    amazon_saml_09.png
    amazon_saml_10.png
  6. "Skip" the next screen.

    amazon_saml_12.png

  7. Add the following items to the attribute mapping, then click "Next".

    Email email

    First Name

    first_name
    Last Name last_name

    amazon_saml_13.png

  8. Download the "Metadata XML File" from the Amazon connection data, then click "Next".

    amazon_saml_14.png

Now, return to configuring TrustLogin again.
Open the TrustLogin Admin Page tab.

TrustLogin Admin Page Settings ②

  1. Using "Select Metadata" under "Service Provider Settings", upload the metadata you downloaded in step 8 of "Amazon Business Settings" above.
    Note: Do not delete this metadata, as you will use it again later.

    amazon_saml_15.png

  2. Click "Register".

    amazon_saml_22.png

  3. Search for Amazon Business using "Search App" and click the app name.

    amazon_saml_23.png
  4. To perform the connection test in Amazon, select the administrator from "Add Member" and click the "Register" button to add them.

    amazon_saml_24.png

Return to the Amazon Business tab again to perform the connection test.

Amazon Business Admin Page Settings (Connection Test)

  1. Check the Amazon connection data and click "Start Testing".
     amazon_saml_16.png

  2. Click "Test".

    amazon_saml_17.png

  3. Make a note of the "IDP initiated URL", then click "Activate".

    amazon_saml_18.png
  4. Confirm that you have completed steps 1 through 3, check the checkbox, and click "Switch to Active".

    amazon_saml_19.png

  5. Confirm that the status is "Active" — the Amazon Business configuration is now complete.

    amazon_saml_20.png

TrustLogin Admin Page Settings (Metadata Correction)

  1. Open the metadata you downloaded in step 8 of "Amazon Business Settings" above in a text editor, rewrite the section below to the "IDP initiated URL" you noted in step 3 of "Amazon Business Admin Page Settings (Connection Test)", and save, overwriting the original file.

    amazon_saml_25.png

  2. Using "Select Metadata" under "Service Provider Settings", upload the metadata you just corrected and overwrote.

    amazon_saml_15.png

  3. Click "Register" to complete the setup.

    amazon_saml_22.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Amazon Business (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app from "My Page" or the browser extension, and confirm that login succeeds.

② When an Administrator Adds a Member

  1. Search for and click the "Amazon Business (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.