How to Configure SAML Authentication for Office Station

Item

Details

Pre-check

  • Advance configuration in Office Station is required.

  • For the latest configuration steps, please refer to the manual provided by Office Station.

Name ID

Email address

 

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

 

Request the SP to configure this

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Only accounts with an SSO Login ID configured are enabled (SAML authentication only)

Notes

Workaround in the Event of a TrustLogin Outage or SAML Configuration Failure
Please use the following steps to log in to Office Station and change the settings.

  1. Log in to Office Station using the initial login ID and password (Office Station account) stated in the Office Station registration email (Subject: "Registration Complete Notification" or a notice about using Office Station).
  2. After logging in, change "SSO Login" to "Do not use" on the "Single Sign-On (SSO) Management" screen.
  3. Log in with the Office Station account.

 

Table of Contents:

TrustLogin Admin Page Settings 

Office Station Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Office Station (SAML)".

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

 
Now, we will move on to the settings on the Office Station side.
Please do not click the "Register" button yet, and open Office Station in a separate window.

Office Station Settings

  1. Click "Master Management > Company Settings".

  2. Click "Other Settings >Single Sign-On (SSO) Management".

  3. Click the "Download" button for "SAML Metadata File" under "Office Station (Service Provider) Information" to download the metadata.


  4. Configure "Identity Provider Information" as follows.
    SAML Metadata File Click the "Load File" button and upload the metadata obtained from TrustLogin.
    SSO Endpoint URL (SLS) May be left blank.
    Identity Provider Service Name

    If you want to replace labels such as the button name on the login screen or the menu name on the Employee My Page, enter the Identity Provider Service Name.




  5. If using SSO on the Administrator screen
    Select "Use" for "SSO Login" under "Administrator Screen SSO Settings".
    If you want to configure two-factor authentication, select "Use" for "Two-Factor Authentication".


  6. If using SSO on the Employee My Page screen
    Select "Use" for "SSO Login" under "Employee My Page Screen SSO Settings".
    If you want to allow employees to set their own SSO Login ID, select "Allowed" for "SSO Login ID Setting by Employees".

  7. Click "Save" at the bottom of the screen to save the settings.

  8. If using SSO on the Administrator screen
    Click "Master Management > User Management".

  9. Click the user to whom you want to apply SAML SSO.



  10. Enter the same email address as your TrustLogin account in "Login ID (Email Address)" under "SSO Account".

  11. Click "Check Details" at the bottom of the screen, and if there are no errors, click "Save" to save the settings.

  12. If using SSO on the Employee My Page screen
    Click "Employee My Page > Employee My Page Management".

  13. Click "Register Login ID" for the employee to whom you want to apply SAML SSO.


  14. Enter the same email address as your TrustLogin account in "SSO Login ID (Email Address)", and click "Register".



TrustLogin Admin Page Settings (Continued)

  1. Configure the input fields in "Service Provider Settings" as follows.
    Login URL

    May be left blank

    [Optional]
    If the following conditions are met, leaving the Login URL blank will log employees who have both an Employee ID and a User ID into the Administrator screen when they log in from the TrustLogin app. By setting the Login URL to a URL other than the Employee My Page system's login URL, both employees and users can log in to the Employee My Page.
    (Example) Top screen: https://officestation.jp/xxxxxxxx/user-mypage/top

    ・The "SSO Login" option is set to "Use" on both the Administrator screen and the Employee My Page screen.
    ・An employee who has both an Employee ID and a User ID has registered the same SSO Login ID for both the Employee ID and the User ID.

    Metadata Metadata obtained from Office Station



  2. Save by clicking the "Register" button.


    TrustLogin User Settings

    ① When a user adds the app from My Page

    1. On "My Page," click the "Add App" button.
    2. On the "Register App" screen, select "Office Station (SAML)", and click the "Next" button in the upper right of the screen.
    3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

    ② When an administrator adds members

    1. In the "Admin Page > App" menu, search for and click "Office Station (SAML)".
    2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

 

 

How to Configure SAML Authentication for Office Station

Item

Details

Pre-check

  • Advance configuration in Office Station is required.

  • For the latest configuration steps, please refer to the manual provided by Office Station.

Name ID

Email address

 

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

 

Request the SP to configure this

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other:
Only accounts with an SSO Login ID configured are enabled (SAML authentication only)

Notes

Workaround in the Event of a TrustLogin Outage or SAML Configuration Failure
Please use the following steps to log in to Office Station and change the settings.

  1. Log in to Office Station using the initial login ID and password (Office Station account) stated in the Office Station registration email (Subject: "Registration Complete Notification" or a notice about using Office Station).
  2. After logging in, change "SSO Login" to "Do not use" on the "Single Sign-On (SSO) Management" screen.
  3. Log in with the Office Station account.

 

Table of Contents:

TrustLogin Admin Page Settings 

Office Station Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "Office Station (SAML)".

  3. Download the metadata using the "Download Metadata" button under "Identity Provider Information".03.png

 
Now, we will move on to the settings on the Office Station side.
Please do not click the "Register" button yet, and open Office Station in a separate window.

Office Station Settings

  1. Click "Master Management > Company Settings".

  2. Click "Other Settings >Single Sign-On (SSO) Management".

  3. Click the "Download" button for "SAML Metadata File" under "Office Station (Service Provider) Information" to download the metadata.


  4. Configure "Identity Provider Information" as follows.
    SAML Metadata File Click the "Load File" button and upload the metadata obtained from TrustLogin.
    SSO Endpoint URL (SLS) May be left blank.
    Identity Provider Service Name

    If you want to replace labels such as the button name on the login screen or the menu name on the Employee My Page, enter the Identity Provider Service Name.




  5. If using SSO on the Administrator screen
    Select "Use" for "SSO Login" under "Administrator Screen SSO Settings".
    If you want to configure two-factor authentication, select "Use" for "Two-Factor Authentication".


  6. If using SSO on the Employee My Page screen
    Select "Use" for "SSO Login" under "Employee My Page Screen SSO Settings".
    If you want to allow employees to set their own SSO Login ID, select "Allowed" for "SSO Login ID Setting by Employees".

  7. Click "Save" at the bottom of the screen to save the settings.

  8. If using SSO on the Administrator screen
    Click "Master Management > User Management".

  9. Click the user to whom you want to apply SAML SSO.



  10. Enter the same email address as your TrustLogin account in "Login ID (Email Address)" under "SSO Account".

  11. Click "Check Details" at the bottom of the screen, and if there are no errors, click "Save" to save the settings.

  12. If using SSO on the Employee My Page screen
    Click "Employee My Page > Employee My Page Management".

  13. Click "Register Login ID" for the employee to whom you want to apply SAML SSO.


  14. Enter the same email address as your TrustLogin account in "SSO Login ID (Email Address)", and click "Register".



TrustLogin Admin Page Settings (Continued)

  1. Configure the input fields in "Service Provider Settings" as follows.
    Login URL

    May be left blank

    [Optional]
    If the following conditions are met, leaving the Login URL blank will log employees who have both an Employee ID and a User ID into the Administrator screen when they log in from the TrustLogin app. By setting the Login URL to a URL other than the Employee My Page system's login URL, both employees and users can log in to the Employee My Page.
    (Example) Top screen: https://officestation.jp/xxxxxxxx/user-mypage/top

    ・The "SSO Login" option is set to "Use" on both the Administrator screen and the Employee My Page screen.
    ・An employee who has both an Employee ID and a User ID has registered the same SSO Login ID for both the Employee ID and the User ID.

    Metadata Metadata obtained from Office Station



  2. Save by clicking the "Register" button.


    TrustLogin User Settings

    ① When a user adds the app from My Page

    1. On "My Page," click the "Add App" button.
    2. On the "Register App" screen, select "Office Station (SAML)", and click the "Next" button in the upper right of the screen.
    3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

    ② When an administrator adds members

    1. In the "Admin Page > App" menu, search for and click "Office Station (SAML)".
    2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.