|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on setting up a custom attribute, see here |
||
|
SP-Side Configuration |
〇 |
Configured by the administrator |
|
Request the SP to configure this |
||
|
Provisioning |
Supports provisioning via API (account management possible in TrustLogin) |
|
|
Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible) |
||
|
〇 |
None (accounts are created individually in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App Internal Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App Internal Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: |
|
|
Notes |
Workaround in the Event of a TrustLogin Outage or SAML Configuration Failure
|
|
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "Office Station (SAML)".
- Download the metadata using the "Download Metadata" button under "Identity Provider Information".
Now, we will move on to the settings on the Office Station side.
Please do not click the "Register" button yet, and open Office Station in a separate window.
Office Station Settings
- Click "Master Management > Company Settings".
- Click "Other Settings >Single Sign-On (SSO) Management".
- Click the "Download" button for "SAML Metadata File" under "Office Station (Service Provider) Information" to download the metadata.
- Configure "Identity Provider Information" as follows.
SAML Metadata File Click the "Load File" button and upload the metadata obtained from TrustLogin. SSO Endpoint URL (SLS) May be left blank. Identity Provider Service Name If you want to replace labels such as the button name on the login screen or the menu name on the Employee My Page, enter the Identity Provider Service Name.
-
If using SSO on the Administrator screen
Select "Use" for "SSO Login" under "Administrator Screen SSO Settings".
If you want to configure two-factor authentication, select "Use" for "Two-Factor Authentication".
-
If using SSO on the Employee My Page screen
Select "Use" for "SSO Login" under "Employee My Page Screen SSO Settings".
If you want to allow employees to set their own SSO Login ID, select "Allowed" for "SSO Login ID Setting by Employees".
- Click "Save" at the bottom of the screen to save the settings.
-
If using SSO on the Administrator screen
Click "Master Management > User Management".
- Click the user to whom you want to apply SAML SSO.
- Enter the same email address as your TrustLogin account in "Login ID (Email Address)" under "SSO Account".
- Click "Check Details" at the bottom of the screen, and if there are no errors, click "Save" to save the settings.
-
If using SSO on the Employee My Page screen
Click "Employee My Page > Employee My Page Management".
- Click "Register Login ID" for the employee to whom you want to apply SAML SSO.
- Enter the same email address as your TrustLogin account in "SSO Login ID (Email Address)", and click "Register".
TrustLogin Admin Page Settings (Continued)
-
Configure the input fields in "Service Provider Settings" as follows.
Login URL May be left blank
[Optional]
If the following conditions are met, leaving the Login URL blank will log employees who have both an Employee ID and a User ID into the Administrator screen when they log in from the TrustLogin app. By setting the Login URL to a URL other than the Employee My Page system's login URL, both employees and users can log in to the Employee My Page.
(Example) Top screen: https://officestation.jp/xxxxxxxx/user-mypage/top・The "SSO Login" option is set to "Use" on both the Administrator screen and the Employee My Page screen.
・An employee who has both an Employee ID and a User ID has registered the same SSO Login ID for both the Employee ID and the User ID.Metadata Metadata obtained from Office Station
-
Save by clicking the "Register" button.
TrustLogin User Settings
① When a user adds the app from My Page
- On "My Page," click the "Add App" button.
- On the "Register App" screen, select "Office Station (SAML)", and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter a new one, then click the "Register" button.
② When an administrator adds members
- In the "Admin Page > App" menu, search for and click "Office Station (SAML)".
- Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.