Squadcast SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Squadcast is required.

  • For the latest setup instructions, please check the manual provided by Squadcast.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Users (SAML authentication only), Administrators (both SAML authentication and password authentication available)

Notes

  • The user's last name/first name are synced by being auto-filled into the new user registration form. They are not synced on subsequent logins.
  • If, when performing SSO on the iOS native app, a blank page is displayed after authenticating with TrustLogin, click "Done" in the upper left.

Table of Contents:

TrustLogin Admin Page Settings

Squadcast Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Squadcast (SAML)".
    02.png

  3. Note down the value for "IdP URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring Squadcast.
Do not click the "Register" button yet — open Squadcast in a separate window.

Squadcast Settings

  1. Log in with an administrator account, open "Settings > Extensions", and click the "Configure" button for "SSO".
    04.png

  2. Configure each item as follows, then save by clicking the "Save" button at the end.
    Enable Single Sign-on(SSO) Turn the toggle ON
    Choose SSO Select "Custom SAML 2.0"
    ACS URL Copy and note down the value
    SAML 2.0 Endpoint The "IdP URL" obtained from TrustLogin
    X.509 Certificate The "Certificate" obtained from TrustLogin
    your Organization Domain Your organization's domain name
    Default New User Role Specify the role to be assigned by default when a new user is created
    Allow Account Owner to use email login Turn the checkbox ON
    Note: We recommend enabling this, as it allows the administrator to log in with a password if the SSO configuration fails or if a TrustLogin outage occurs.

    05.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Set the "ACS URL" obtained from Squadcast in both the "Entity ID" and "ACS URL to Service" fields of "Service Provider Settings".
    06.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Squadcast (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Squadcast (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Squadcast SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Squadcast is required.

  • For the latest setup instructions, please check the manual provided by Squadcast.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Users (SAML authentication only), Administrators (both SAML authentication and password authentication available)

Notes

  • The user's last name/first name are synced by being auto-filled into the new user registration form. They are not synced on subsequent logins.
  • If, when performing SSO on the iOS native app, a blank page is displayed after authenticating with TrustLogin, click "Done" in the upper left.

Table of Contents:

TrustLogin Admin Page Settings

Squadcast Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Squadcast (SAML)".
    02.png

  3. Note down the value for "IdP URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring Squadcast.
Do not click the "Register" button yet — open Squadcast in a separate window.

Squadcast Settings

  1. Log in with an administrator account, open "Settings > Extensions", and click the "Configure" button for "SSO".
    04.png

  2. Configure each item as follows, then save by clicking the "Save" button at the end.
    Enable Single Sign-on(SSO) Turn the toggle ON
    Choose SSO Select "Custom SAML 2.0"
    ACS URL Copy and note down the value
    SAML 2.0 Endpoint The "IdP URL" obtained from TrustLogin
    X.509 Certificate The "Certificate" obtained from TrustLogin
    your Organization Domain Your organization's domain name
    Default New User Role Specify the role to be assigned by default when a new user is created
    Allow Account Owner to use email login Turn the checkbox ON
    Note: We recommend enabling this, as it allows the administrator to log in with a password if the SSO configuration fails or if a TrustLogin outage occurs.

    05.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Set the "ACS URL" obtained from Squadcast in both the "Entity ID" and "ACS URL to Service" fields of "Service Provider Settings".
    06.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Squadcast (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

②When an administrator adds members

  1. Search for and click the "Squadcast (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.