How to Configure SAML Authentication for Runbook

Item

Details

Pre-check

  • Prior configuration in Runbook is required.

  • You need to create an account in Runbook with the same email address as TrustLogin in advance.

  • For the latest setup instructions, please refer to the manual provided by Runbook.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)
※Note: For how to configure provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "Runbook (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Convert the extension of the downloaded certificate to ".cer".

Now, let's move on to the settings on the Runbook side.
Do not click the "Register" button yet — open Runbook in a separate window.

Runbook Settings

  1. Open the organization name dropdown at the top right and select "Billing / Security".
    04.png

  2. Open "Single Sign-On" and check "Enable SAML Authentication".
    05.png

  3. Configure each item as follows and save by clicking the "Save" button.
    Login URL The "IdP URL" obtained from TrustLogin
    Entity ID The "Issuer / Entity ID" obtained from TrustLogin
    Signing Certificate The "Certificate" obtained from TrustLogin, converted to a .cer file
    Note: Checking "Require SAML Authentication" disables password login, restricting login to SAML authentication only. If you want to enforce this restriction, we recommend switching over only after confirming the single sign-on connection is successful and notifying your users.

    06.png

  4. Click "Download Metadata" to obtain the metadata.
    07.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (continued)

  1. Upload the metadata obtained from Runbook to the metadata field under "Service Provider Settings".
    08.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Runbook (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Runbook (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Configure SAML Authentication for Runbook

Item

Details

Pre-check

  • Prior configuration in Runbook is required.

  • You need to create an account in Runbook with the same email address as TrustLogin in advance.

  • For the latest setup instructions, please refer to the manual provided by Runbook.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)
※Note: For how to configure provisioning, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "Runbook (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. Convert the extension of the downloaded certificate to ".cer".

Now, let's move on to the settings on the Runbook side.
Do not click the "Register" button yet — open Runbook in a separate window.

Runbook Settings

  1. Open the organization name dropdown at the top right and select "Billing / Security".
    04.png

  2. Open "Single Sign-On" and check "Enable SAML Authentication".
    05.png

  3. Configure each item as follows and save by clicking the "Save" button.
    Login URL The "IdP URL" obtained from TrustLogin
    Entity ID The "Issuer / Entity ID" obtained from TrustLogin
    Signing Certificate The "Certificate" obtained from TrustLogin, converted to a .cer file
    Note: Checking "Require SAML Authentication" disables password login, restricting login to SAML authentication only. If you want to enforce this restriction, we recommend switching over only after confirming the single sign-on connection is successful and notifying your users.

    06.png

  4. Click "Download Metadata" to obtain the metadata.
    07.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (continued)

  1. Upload the metadata obtained from Runbook to the metadata field under "Service Provider Settings".
    08.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "Runbook (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "Runbook (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.