ArcGIS Online SAML Authentication Setup Guide

 Item

Details

Pre-Check

  • Prior configuration in ArcGIS Online is required.

  • For the latest setup instructions, please check the manual provided by ArcGIS Online.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Provisioning via API supported (account management possible in TrustLogin)

 

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For setup instructions when provisioning is required, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for members invited as SAML members (SAML authentication only)

Notes

  • Members are distinguished by login type: ArcGIS and SAML. Therefore, in order for an existing member to use SAML SSO, they must be invited again as a SAML member.
  • When a new SAML member is invited, the user type, role, group, etc. configured under "Organization > Settings > Default settings for new members" will be applied.

 

Table of Contents:

TrustLogin Admin Page Settings

ArcGIS Online Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Invite SAML Members

Native App Login Method

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "ArcGIS Online (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png


Now, switch to configuring ArcGIS Online.
Do not click the "Register" button yet — open ArcGIS Online in a separate window.

ArcGIS Online Settings

  1. Log in with an administrator account and open "Organization" > "Settings".
    04.png

  2. Open "Security" in the left menu, and click "New SAML Login" under the "Login" section.
    05.png

  3. Select "Single Identity Provider" and proceed by clicking "Next".
    06.png

  4. Configure each item as follows and click the "Save" button.
    Name Any name you choose (e.g., TrustLogin)
    Note: This will be used as the label for the SAML SSO login button on the login page.
    Users can join under the following condition Select "When invited by an administrator"
    Enterprise identity provider metadata source Select "File" and upload the metadata obtained from TrustLogin

    07.png

  5. Click the download icon button to the left of "Configure Login" for the SAML login to obtain the SP metadata.
    08.png

 

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from ArcGIS Online to "Metadata" under "Service Provider Settings".
    10.png

  2. Save by clicking the "Register" button.

 

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "ArcGIS Online (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "ArcGIS Online (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

 

How to Invite SAML Members

To use SAML SSO, members must be invited as SAML members.

Note: The "email address" of the member you invite must match their TrustLogin email address.
Note: When inviting a member, select either "Add member using an organization-specific ID, without sending an invitation email" or "Invite the member to join using an organization-specific login".

"Add member using an organization-specific ID, without sending an invitation email"
→ The invited member can immediately log in from the SAML app in TrustLogin, or from the SAML SSO button on the ArcGIS Online login page.

"Invite the member to join using an organization-specific login"
→ The invited member completes the invitation by clicking the URL in the invitation email and authenticating with TrustLogin. After that, they can log in from the SAML app in TrustLogin, or from the SAML SSO button on the ArcGIS Online login page.

11.png


Native App Login Method

Note: This was verified using "ArcGIS Navigator".

  1. Open the app and click "Sign in with ArcGIS Online".
    Image.png

  2. Click "ArcGIS Organization Site URL" and enter your organization's subdomain.
    12.png
  3. Click the SAML SSO login button.
    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen. Login will be completed after authentication.
    13.png

ArcGIS Online SAML Authentication Setup Guide

 Item

Details

Pre-Check

  • Prior configuration in ArcGIS Online is required.

  • For the latest setup instructions, please check the manual provided by ArcGIS Online.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

 

Request configuration from the SP

Provisioning

 

Provisioning via API supported (account management possible in TrustLogin)

 

SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported)

None (accounts are created in each system)
Note: For setup instructions when provisioning is required, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for members invited as SAML members (SAML authentication only)

Notes

  • Members are distinguished by login type: ArcGIS and SAML. Therefore, in order for an existing member to use SAML SSO, they must be invited again as a SAML member.
  • When a new SAML member is invited, the user type, role, group, etc. configured under "Organization > Settings > Default settings for new members" will be applied.

 

Table of Contents:

TrustLogin Admin Page Settings

ArcGIS Online Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Invite SAML Members

Native App Login Method

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "ArcGIS Online (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png


Now, switch to configuring ArcGIS Online.
Do not click the "Register" button yet — open ArcGIS Online in a separate window.

ArcGIS Online Settings

  1. Log in with an administrator account and open "Organization" > "Settings".
    04.png

  2. Open "Security" in the left menu, and click "New SAML Login" under the "Login" section.
    05.png

  3. Select "Single Identity Provider" and proceed by clicking "Next".
    06.png

  4. Configure each item as follows and click the "Save" button.
    Name Any name you choose (e.g., TrustLogin)
    Note: This will be used as the label for the SAML SSO login button on the login page.
    Users can join under the following condition Select "When invited by an administrator"
    Enterprise identity provider metadata source Select "File" and upload the metadata obtained from TrustLogin

    07.png

  5. Click the download icon button to the left of "Configure Login" for the SAML login to obtain the SP metadata.
    08.png

 

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from ArcGIS Online to "Metadata" under "Service Provider Settings".
    10.png

  2. Save by clicking the "Register" button.

 

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "ArcGIS Online (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "ArcGIS Online (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

 

How to Invite SAML Members

To use SAML SSO, members must be invited as SAML members.

Note: The "email address" of the member you invite must match their TrustLogin email address.
Note: When inviting a member, select either "Add member using an organization-specific ID, without sending an invitation email" or "Invite the member to join using an organization-specific login".

"Add member using an organization-specific ID, without sending an invitation email"
→ The invited member can immediately log in from the SAML app in TrustLogin, or from the SAML SSO button on the ArcGIS Online login page.

"Invite the member to join using an organization-specific login"
→ The invited member completes the invitation by clicking the URL in the invitation email and authenticating with TrustLogin. After that, they can log in from the SAML app in TrustLogin, or from the SAML SSO button on the ArcGIS Online login page.

11.png


Native App Login Method

Note: This was verified using "ArcGIS Navigator".

  1. Open the app and click "Sign in with ArcGIS Online".
    Image.png

  2. Click "ArcGIS Organization Site URL" and enter your organization's subdomain.
    12.png
  3. Click the SAML SSO login button.
    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen. Login will be completed after authentication.
    13.png