Shisho Cloud SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Shisho Cloud is required.

  • For the latest setup instructions, please check the manual provided by Shisho Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Enabled only for users in domains where SAML authentication has been applied by the SP

Notes

If a failure occurs and login via SAML authentication becomes unavailable, you will need to contact GMO Flatt Security, Inc. and ask them to disable SAML authentication for Shisho Cloud. Once SAML authentication is disabled, the "users who also use ID/password login" specified in "1." of Shisho Cloud Settings (Continued) will be able to log in with a password.

Table of Contents:

TrustLogin Admin Page Settings

Shisho Cloud Settings

TrustLogin Admin Page Settings (Continued)

Shisho Cloud Settings (Continued)

TrustLogin User Settings

Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Shisho Cloud (SAML)".
    ShishoCloud07.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring Shisho Cloud.
Do not click the "Register" button yet — open Shisho Cloud in a separate window.

Shisho Cloud Settings

  1. Log in to Shisho Cloud and click "Settings" > "Single Sign-On" > "Add Single Sign-On".
    ShishoCloud04.png

  2. Configure the following, then click "Add".
    Display Name Any name of your choosing (e.g., TrustLogin)
    Email Domain The domain of the email address used to log in via SSO
    Source Select "File" and upload the metadata you saved from TrustLogin

    ShishoCloud.png

  3. After adding, click the display name you configured in step 2.
    ShishoCloud01.png

  4. Make a note of the "Callback URL".
    ShishoCloud02.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Enter the "Callback URL" you noted down from Shisho Cloud into "ACS URL to Service" under "Service Provider Settings".
    ShishoCloud03.png

  2. Save by clicking the "Register" button.

Shisho Cloud Settings (Continued)

  1. Once you have completed the steps above, share the following information with your contact at GMO Flatt Security, Inc. and request that they enable SSO.
    ・Email domain used for login
    ・Users who will also use ID/password login

  2. Once the single sign-on configuration is enabled, the icon in the "Status" column will change to a green checkmark.
    ShishoCloud05.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Shisho Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Shisho Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

① Logging in with "Shisho Cloud (SAML)"

Launching "Shisho Cloud (SAML)" from TrustLogin's My Page or the browser extension will take you to the Shisho Cloud login screen. Enter your email address and click the "Login" button to log in.ShishoCloud06.png

② Using Shisho Cloud (Password Authentication App)

Registering Shisho Cloud (Password Authentication App) allows you to skip entering your email address and clicking the "Login" button, which are described in the login steps in ①.

  1. Search on the "Register Company App" screen and select "Shisho Cloud".ShishoCloud08.png

  2. Add the app using the same steps as a standard app registration, either as an administrator or by the user.

  3. On the app edit screen, enter your email address in the "Username or Email Address" field and save.
    Note: Leave the password field blank when saving. If you have already registered the "Shisho Cloud" app and were using password authentication (i.e., you saved the app with a password entered), there is no need to delete it. You can continue using it as is.
    Note: The supplementary app can only be used in a PC browser.
    ShishoCloud09.png

Shisho Cloud SAML JIT Setup Guide

Item

Details

Prior Confirmation

  • Prior configuration in Shisho Cloud is required.

  • For the latest setup instructions, please check the manual provided by Shisho Cloud.

Name ID

Email address

Custom attribute Note: For instructions on how to configure a custom attribute, click here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Enabled only for users in domains where SAML authentication has been applied by the SP

Notes

If a failure occurs and login via SAML authentication becomes unavailable, you will need to contact GMO Flatt Security, Inc. and ask them to disable SAML authentication for Shisho Cloud. Once SAML authentication is disabled, the "users who also use ID/password login" specified in "1." of Shisho Cloud Settings (Continued) will be able to log in with a password.

Table of Contents:

TrustLogin Admin Page Settings

Shisho Cloud Settings

TrustLogin Admin Page Settings (Continued)

Shisho Cloud Settings (Continued)

TrustLogin User Settings

Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "Shisho Cloud (SAML)".
    ShishoCloud07.png

  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png

Now, switch to configuring Shisho Cloud.
Do not click the "Register" button yet — open Shisho Cloud in a separate window.

Shisho Cloud Settings

  1. Log in to Shisho Cloud and click "Settings" > "Single Sign-On" > "Add Single Sign-On".
    ShishoCloud04.png

  2. Configure the following, then click "Add".
    Display Name Any name of your choosing (e.g., TrustLogin)
    Email Domain The domain of the email address used to log in via SSO
    Source Select "File" and upload the metadata you saved from TrustLogin

    ShishoCloud.png

  3. After adding, click the display name you configured in step 2.
    ShishoCloud01.png

  4. Make a note of the "Callback URL".
    ShishoCloud02.png

Now return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Enter the "Callback URL" you noted down from Shisho Cloud into "ACS URL to Service" under "Service Provider Settings".
    ShishoCloud03.png

  2. Save by clicking the "Register" button.

Shisho Cloud Settings (Continued)

  1. Once you have completed the steps above, share the following information with your contact at GMO Flatt Security, Inc. and request that they enable SSO.
    ・Email domain used for login
    ・Users who will also use ID/password login

  2. Once the single sign-on configuration is enabled, the icon in the "Status" column will change to a green checkmark.
    ShishoCloud05.png

TrustLogin User Settings

① When a user adds the app from My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Shisho Cloud (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an administrator adds members

  1. Search for and click the "Shisho Cloud (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Login Method

① Logging in with "Shisho Cloud (SAML)"

Launching "Shisho Cloud (SAML)" from TrustLogin's My Page or the browser extension will take you to the Shisho Cloud login screen. Enter your email address and click the "Login" button to log in.ShishoCloud06.png

② Using Shisho Cloud (Password Authentication App)

Registering Shisho Cloud (Password Authentication App) allows you to skip entering your email address and clicking the "Login" button, which are described in the login steps in ①.

  1. Search on the "Register Company App" screen and select "Shisho Cloud".ShishoCloud08.png

  2. Add the app using the same steps as a standard app registration, either as an administrator or by the user.

  3. On the app edit screen, enter your email address in the "Username or Email Address" field and save.
    Note: Leave the password field blank when saving. If you have already registered the "Shisho Cloud" app and were using password authentication (i.e., you saved the app with a password entered), there is no need to delete it. You can continue using it as is.
    Note: The supplementary app can only be used in a PC browser.
    ShishoCloud09.png