How to Configure SAML Authentication for AgileWorks

Item

Details

Pre-check

  • Advance configuration in AgileWorks is required.

  • You must register the same email address as your TrustLogin account as the "Login ID" in AgileWorks.
  • This manual was created based on verification performed using the AgileWorks cloud version.
  • For the latest configuration steps, please refer to the manual provided by AgileWorks.

Name ID

Email address

 

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

 

Request the SP to configure this

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users with SAML authentication applied on the SP side (both SAML authentication and password authentication available)

Notes

This manual describes the steps for consolidating AgileWorks SAML settings into a single SAML app. If you want to configure each one individually, please refer to the manuals below.

 

Table of Contents:

TrustLogin Admin Page Settings

AgileWorks Settings

TrustLogin User Settings


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "AgileWorks (SAML)."
    AgileWorks01.png

  3. Make a note of the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

  4. Enter the following in the "Service Provider Settings."
    Login URL

    Enter one of the following SSO login URLs for AgileWorks

    ・Admin Site
    ・User Site
    ・Mobile Site

    If you want to log in to all or multiple of the above sites via SAML,
    we recommend setting one of the URLs as the Login URL and registering the other sites in a Bookmark Template, or using your browser's bookmark feature. Please register the SSO login URL (the one with "SAML" at the end of the login URL).

    For instructions on setting up the "Bookmark Template," see here

    [Example SSO Login URLs]

    Admin Site: https://xxxx.atledcloud.jp/AgileWorks/Broker/EMMASAML

    User Site: https://xxxx.atledcloud.jp/AgileWorks/Broker/PicusSAML

    Mobile Site: https://xxxx.atledcloud.jp/AgileWorks/Broker/MobileSAML

    Note: You can also check the URL on the AgileWorks SAML settings screen.

     

    [Configuration Example]
    Login URL: Set the SSO login URL for the Admin Site
    Bookmark Template:
    Register the SSO login URLs for the User Site and Mobile Site

    ACS URL to the Service

    Enter the AgileWorks URL

    in the format "https://xxxx.atledcloud.jp" in all blank fields


    AgileWorks30.png

  5. Save by clicking the "Register" button.

    AgileWorks Settings

    1. Log in to the Admin Site, select "Site Management > Site Common Settings > Login Authentication > Admin Site," and click "Edit."
      AgileWorks06.png

    2. Open the "Basic" tab and select "Available" for "Usage Status."
      AgileWorks09.png

    3. Open the "SAML" tab and configure it as follows.
      Redirect Authentication URL The "IdP URL" you noted down from TrustLogin
      Public Key Certificate File Upload the "certificate" you downloaded from TrustLogin

      AgileWorks10.png

    4. Configure "Access Permissions" according to your company's operational policy.

    5. Save the settings by clicking "Save."

    6. Configure and save SAML in the same manner as above for the "User Site," "Gadget," "Mobile Site," and "App," respectively.
      AgileWorks17.png

       

      TrustLogin User Settings

      ① When a User Adds the App from My Page

      1. On "My Page," click the "Add App" button.
      2. On the "Register App" screen, select "AgileWorks (SAML)," and click the "Next" button in the upper right of the screen.
      3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

      ② When an Administrator Adds Members

      1. In the "Admin Page > App" menu, search for and click the "AgileWorks (SAML)" app.
      2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

       

How to Configure SAML Authentication for AgileWorks

Item

Details

Pre-check

  • Advance configuration in AgileWorks is required.

  • You must register the same email address as your TrustLogin account as the "Login ID" in AgileWorks.
  • This manual was created based on verification performed using the AgileWorks cloud version.
  • For the latest configuration steps, please refer to the manual provided by AgileWorks.

Name ID

Email address

 

Custom attribute Note: For instructions on setting up a custom attribute, see here

SP-Side Configuration

Configured by the administrator

 

Request the SP to configure this

Provisioning

 

Supports provisioning via API (account management possible in TrustLogin)

 

Supports SAML JIT provisioning (account management possible in TrustLogin; user deletion not possible)

None (accounts are created individually in each system)

Access Method

SP-Initiated SSO

 

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App Internal Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App Internal Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users with SAML authentication applied on the SP side (both SAML authentication and password authentication available)

Notes

This manual describes the steps for consolidating AgileWorks SAML settings into a single SAML app. If you want to configure each one individually, please refer to the manuals below.

 

Table of Contents:

TrustLogin Admin Page Settings

AgileWorks Settings

TrustLogin User Settings


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Corporate App" screen and select "AgileWorks (SAML)."
    AgileWorks01.png

  3. Make a note of the value of "IdP URL" under "Identity Provider Information," and download the certificate using the "Get Certificate" button.03.png

  4. Enter the following in the "Service Provider Settings."
    Login URL

    Enter one of the following SSO login URLs for AgileWorks

    ・Admin Site
    ・User Site
    ・Mobile Site

    If you want to log in to all or multiple of the above sites via SAML,
    we recommend setting one of the URLs as the Login URL and registering the other sites in a Bookmark Template, or using your browser's bookmark feature. Please register the SSO login URL (the one with "SAML" at the end of the login URL).

    For instructions on setting up the "Bookmark Template," see here

    [Example SSO Login URLs]

    Admin Site: https://xxxx.atledcloud.jp/AgileWorks/Broker/EMMASAML

    User Site: https://xxxx.atledcloud.jp/AgileWorks/Broker/PicusSAML

    Mobile Site: https://xxxx.atledcloud.jp/AgileWorks/Broker/MobileSAML

    Note: You can also check the URL on the AgileWorks SAML settings screen.

     

    [Configuration Example]
    Login URL: Set the SSO login URL for the Admin Site
    Bookmark Template:
    Register the SSO login URLs for the User Site and Mobile Site

    ACS URL to the Service

    Enter the AgileWorks URL

    in the format "https://xxxx.atledcloud.jp" in all blank fields


    AgileWorks30.png

  5. Save by clicking the "Register" button.

    AgileWorks Settings

    1. Log in to the Admin Site, select "Site Management > Site Common Settings > Login Authentication > Admin Site," and click "Edit."
      AgileWorks06.png

    2. Open the "Basic" tab and select "Available" for "Usage Status."
      AgileWorks09.png

    3. Open the "SAML" tab and configure it as follows.
      Redirect Authentication URL The "IdP URL" you noted down from TrustLogin
      Public Key Certificate File Upload the "certificate" you downloaded from TrustLogin

      AgileWorks10.png

    4. Configure "Access Permissions" according to your company's operational policy.

    5. Save the settings by clicking "Save."

    6. Configure and save SAML in the same manner as above for the "User Site," "Gadget," "Mobile Site," and "App," respectively.
      AgileWorks17.png

       

      TrustLogin User Settings

      ① When a User Adds the App from My Page

      1. On "My Page," click the "Add App" button.
      2. On the "Register App" screen, select "AgileWorks (SAML)," and click the "Next" button in the upper right of the screen.
      3. If you want to change the "Display Name," enter a new one, then click the "Register" button.

      ② When an Administrator Adds Members

      1. In the "Admin Page > App" menu, search for and click the "AgileWorks (SAML)" app.
      2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.