|
Item |
Details |
|
|---|---|---|
|
Pre-Check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For instructions on how to configure a custom attribute, click here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
Provisioning via API supported (account management possible in TrustLogin) |
|
|
SAML JIT provisioning supported (account management possible in TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts are created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
〇 |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
〇 |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled only for members invited as SAML members (SAML authentication only) |
|
|
Notes |
|
|
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "ArcGIS Online (SAML)".
- Download the metadata from the "Download Metadata" button under "Identity Provider Information".
Now, switch to configuring ArcGIS Online.
Do not click the "Register" button yet — open ArcGIS Online in a separate window.
ArcGIS Online Settings
- Log in with an administrator account and open "Organization" > "Settings".
- Open "Security" in the left menu, and click "New SAML Login" under the "Login" section.
- Select "Single Identity Provider" and proceed by clicking "Next".
- Configure each item as follows and click the "Save" button.
Name Any name you choose (e.g., TrustLogin)
Note: This will be used as the label for the SAML SSO login button on the login page.Users can join under the following condition Select "When invited by an administrator" Enterprise identity provider metadata source Select "File" and upload the metadata obtained from TrustLogin
- Click the download icon button to the left of "Configure Login" for the SAML login to obtain the SP metadata.
Now return to the TrustLogin admin page again.
TrustLogin Admin Page Settings (Continued)
- Upload the metadata obtained from ArcGIS Online to "Metadata" under "Service Provider Settings".
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "ArcGIS Online (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
② When an Administrator Adds Members
- Search for and click the "ArcGIS Online (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Invite SAML Members
To use SAML SSO, members must be invited as SAML members.
Note: The "email address" of the member you invite must match their TrustLogin email address.
Note: When inviting a member, select either "Add member using an organization-specific ID, without sending an invitation email" or "Invite the member to join using an organization-specific login".
"Add member using an organization-specific ID, without sending an invitation email"
→ The invited member can immediately log in from the SAML app in TrustLogin, or from the SAML SSO button on the ArcGIS Online login page.
"Invite the member to join using an organization-specific login"
→ The invited member completes the invitation by clicking the URL in the invitation email and authenticating with TrustLogin. After that, they can log in from the SAML app in TrustLogin, or from the SAML SSO button on the ArcGIS Online login page.
Native App Login Method
Note: This was verified using "ArcGIS Navigator".
- Open the app and click "Sign in with ArcGIS Online".
- Click "ArcGIS Organization Site URL" and enter your organization's subdomain.
- Click the SAML SSO login button.
If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen. Login will be completed after authentication.