ArcGIS Online SAML JIT Setup Guide

Item

Details

Pre-Check

  • Prior configuration in ArcGIS Online is required.

  • For the latest setup instructions, please check the manual provided by ArcGIS Online.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported(account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for members who log in via SAML SSO (SAML authentication only)

Notes

  • Members are distinguished by login type: "ArcGIS (log in with username and password)" and "SAML". Therefore, even if an existing member logs in via SAML SSO using the same email address, they will be added as a new member with a different username.
  • When a new SAML member is added, the user type, role, group, etc. configured under "Organization > Settings > Default settings for new members" will be applied.

Table of Contents:

TrustLogin Admin Page Settings

ArcGIS Online Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Native App Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "ArcGIS Online (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring ArcGIS Online.
Do not click the "Register" button yet — open ArcGIS Online in a separate window.

ArcGIS Online Settings

  1. Log in with an administrator account and open "Organization" > "Settings".
    04.png

  2. Open "Security" in the left menu, and click "New SAML Login" under the "Login" section.
    05.png

  3. Select "Single Identity Provider" and proceed by clicking "Next".
    06.png

  4. Configure each item as follows and click the "Save" button.
    Name Any name you choose (e.g., TrustLogin)
    Note: This will be used as the label for the SAML SSO login button on the login page.
    Users can join under the following condition Select "Automatic"
    Enterprise identity provider metadata source Select "File" and upload the metadata obtained from TrustLogin

    07jit.png
  5. Click the download icon button to the left of "Configure Login" for the SAML login to obtain the SP metadata.
    08.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from ArcGIS Online to "Metadata" under "Service Provider Settings".
    10.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "ArcGIS Online (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "ArcGIS Online (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Native App Login Method

Note: This was verified using "ArcGIS Navigator".

  1. Open the app and click "Sign in with ArcGIS Online".
    Image.png

  2. Click "ArcGIS Organization Site URL" and enter your organization's subdomain.
    12.png

  3. Click the SAML SSO login button.
    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen. Login will be completed after authentication.
    13.png

ArcGIS Online SAML JIT Setup Guide

Item

Details

Pre-Check

  • Prior configuration in ArcGIS Online is required.

  • For the latest setup instructions, please check the manual provided by ArcGIS Online.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Provisioning via API supported (account management possible in TrustLogin)

SAML JIT provisioning supported(account management possible in TrustLogin; user deletion not supported)
Note: For setup instructions when provisioning is not required, see here

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for members who log in via SAML SSO (SAML authentication only)

Notes

  • Members are distinguished by login type: "ArcGIS (log in with username and password)" and "SAML". Therefore, even if an existing member logs in via SAML SSO using the same email address, they will be added as a new member with a different username.
  • When a new SAML member is added, the user type, role, group, etc. configured under "Organization > Settings > Default settings for new members" will be applied.

Table of Contents:

TrustLogin Admin Page Settings

ArcGIS Online Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Native App Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "ArcGIS Online (SAML)".
    02.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, switch to configuring ArcGIS Online.
Do not click the "Register" button yet — open ArcGIS Online in a separate window.

ArcGIS Online Settings

  1. Log in with an administrator account and open "Organization" > "Settings".
    04.png

  2. Open "Security" in the left menu, and click "New SAML Login" under the "Login" section.
    05.png

  3. Select "Single Identity Provider" and proceed by clicking "Next".
    06.png

  4. Configure each item as follows and click the "Save" button.
    Name Any name you choose (e.g., TrustLogin)
    Note: This will be used as the label for the SAML SSO login button on the login page.
    Users can join under the following condition Select "Automatic"
    Enterprise identity provider metadata source Select "File" and upload the metadata obtained from TrustLogin

    07jit.png
  5. Click the download icon button to the left of "Configure Login" for the SAML login to obtain the SP metadata.
    08.png

Now return to the TrustLogin admin page again.

TrustLogin Admin Page Settings (Continued)

  1. Upload the metadata obtained from ArcGIS Online to "Metadata" under "Service Provider Settings".
    10.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "ArcGIS Online (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. Search for and click the "ArcGIS Online (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Native App Login Method

Note: This was verified using "ArcGIS Navigator".

  1. Open the app and click "Sign in with ArcGIS Online".
    Image.png

  2. Click "ArcGIS Organization Site URL" and enter your organization's subdomain.
    12.png

  3. Click the SAML SSO login button.
    If you are not logged in to TrustLogin, you will be redirected to the TrustLogin authentication screen. Login will be completed after authentication.
    13.png