How to Configure SAML Authentication for PHONE APPLI PEOPLE

Item

Details

Prior Confirmation

  • Prior configuration in PHONE APPLI PEOPLE is required.

  • You need to create an account in PHONE APPLI PEOPLE with the same email address as TrustLogin as the Login ID in advance.

  • For the latest setup instructions, please refer to the manual provided by PHONE APPLI PEOPLE.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Users (can choose between SAML authentication and password authentication); Administrators (SAML authentication only)

Notes

  • Administrator accounts cannot use password authentication (local authentication). Once SAML authentication is configured, administrator accounts will be required to use SAML authentication. Therefore, please create and operate a separate local authentication user with administrator privileges.
  • The login URL for logging in via SP-Initiated SSO is
    [https://your-environment-URL/sso]. Please note that once you access this URL, you will no longer be able to access the regular login screen you previously used.
    To display the regular login screen again, you will need to clear your browser's local storage.

Table of Contents:

TrustLogin Admin Page Settings

PHONE APPLI PEOPLE Settings

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "PHONE APPLI PEOPLE (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. In the "ACS URL to Service" field under "Service Provider Settings", enter your PHONE APPLI PEOPLE environment URL.
    04.png

  5. Save by clicking the "Register" button.

PHONE APPLI PEOPLE Settings

  1. Log in with an administrator account and open "Authentication Settings" under "Management > Company Information > Basic Settings".
    Change the authentication method to "SAML Authentication", configure each item as follows, and save by clicking the "Update" button.
    URL After Logout Please configure this according to your operational needs.
    If not configured, you will be redirected to the PHONE APPLI PEOPLE login screen.
    URL After Session Timeout

    Please configure this according to your operational needs.
    If not configured, you will be redirected to the PHONE APPLI PEOPLE login screen.

    SSO Endpoint URL The "IdP URL" obtained from TrustLogin
    IdP Entity ID The "Issuer / Entity ID" obtained from TrustLogin
    SP Entity ID Enter "phoneappli_sso"

    IdP Signature Location

    Select "Within Assertion"

    IdP Public Key Certificate

    Upload the "Certificate" obtained from TrustLogin

    05.png

  2. On the user management screen, checking "Use Local Authentication" allows the target user to use local authentication. (SAML authentication will not be available)
    06.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "PHONE APPLI PEOPLE (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "PHONE APPLI PEOPLE (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Configure SAML Authentication for PHONE APPLI PEOPLE

Item

Details

Prior Confirmation

  • Prior configuration in PHONE APPLI PEOPLE is required.

  • You need to create an account in PHONE APPLI PEOPLE with the same email address as TrustLogin as the Login ID in advance.

  • For the latest setup instructions, please refer to the manual provided by PHONE APPLI PEOPLE.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Users (can choose between SAML authentication and password authentication); Administrators (SAML authentication only)

Notes

  • Administrator accounts cannot use password authentication (local authentication). Once SAML authentication is configured, administrator accounts will be required to use SAML authentication. Therefore, please create and operate a separate local authentication user with administrator privileges.
  • The login URL for logging in via SP-Initiated SSO is
    [https://your-environment-URL/sso]. Please note that once you access this URL, you will no longer be able to access the regular login screen you previously used.
    To display the regular login screen again, you will need to clear your browser's local storage.

Table of Contents:

TrustLogin Admin Page Settings

PHONE APPLI PEOPLE Settings

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Company App" screen, search and select "PHONE APPLI PEOPLE (SAML)".
    02.png

  3. Note down the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

  4. In the "ACS URL to Service" field under "Service Provider Settings", enter your PHONE APPLI PEOPLE environment URL.
    04.png

  5. Save by clicking the "Register" button.

PHONE APPLI PEOPLE Settings

  1. Log in with an administrator account and open "Authentication Settings" under "Management > Company Information > Basic Settings".
    Change the authentication method to "SAML Authentication", configure each item as follows, and save by clicking the "Update" button.
    URL After Logout Please configure this according to your operational needs.
    If not configured, you will be redirected to the PHONE APPLI PEOPLE login screen.
    URL After Session Timeout

    Please configure this according to your operational needs.
    If not configured, you will be redirected to the PHONE APPLI PEOPLE login screen.

    SSO Endpoint URL The "IdP URL" obtained from TrustLogin
    IdP Entity ID The "Issuer / Entity ID" obtained from TrustLogin
    SP Entity ID Enter "phoneappli_sso"

    IdP Signature Location

    Select "Within Assertion"

    IdP Public Key Certificate

    Upload the "Certificate" obtained from TrustLogin

    05.png

  2. On the user management screen, checking "Use Local Authentication" allows the target user to use local authentication. (SAML authentication will not be available)
    06.png

TrustLogin User Settings

① When a User Adds the App from My Page

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "PHONE APPLI PEOPLE (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "PHONE APPLI PEOPLE (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.