This page describes Identity Provisioning, one of the main features of the SaaS Management functionality.
What Is the Identity Provisioning Feature?
Using TrustLogin as the master,
you can synchronize user and group information to a connected service (SaaS).
By using features such as attribute mapping and scheduled processing for onboarding/offboarding,
you can achieve flexible and efficient operations.
What You Can Do with the Identity Provisioning Feature
① SaaS User and Group Management
Using TrustLogin as the master, you can create, update, suspend, and delete users and groups in the connected service.
Note: Some services may not support group provisioning. Please check each service's initial setup manual to confirm compatibility.
Key benefits:
- Significantly reduces workload by automating account creation, updates, and deletion
- Prevents human error such as input mistakes and omissions
- Keeps user information consistently up to date across multiple services
- Improves security by preventing missed actions during transfers or resignations
- Strengthens governance through unified management rules
For setup instructions and details, please see the following page.
Manage SaaS Users and Groups
② Attribute Mapping Settings
You can link any attribute on the TrustLogin side to any attribute on the connected service side.
Key benefits:
- Resolves format mismatches between different services
- Lets you extract and process only the information you need before syncing
- Enables flexible operation tailored to each service's requirements
- Eliminates the need for manual adjustments, reducing configuration errors and workload
- Supports a wide range of scenarios by configuring fixed values, dynamic attributes, and custom values
For setup instructions and details, please see the following page.
Configure the Attribute Mapping Feature
③ Scheduled User Sync Processing
By setting a user's start and end dates in advance, accounts can be automatically created or deleted at the specified time.
Key benefits:
- Prevents human error and missed actions
- Enables precise account control aligned with the start and end of employment
- Can be configured in advance, eliminating the need for same-day action
- Reduces security risks, such as access remaining after resignation
- Significantly reduces operational workload and enables planned account management
For setup instructions and details, please see the following page.
Configure Scheduled Processing for Onboarding and Offboarding
④ API Error Notifications
When a sync error occurs, an email notification is automatically sent to the administrator.
Key benefits:
- Errors can be identified immediately, enabling a swift response
- Increases the likelihood of resolving issues before users are affected
- Eliminates the need for manual reporting to system administrators
- Prevents operations from depending on specific individuals and standardizes the response workflow
For setup instructions and details, please see the following page.
Configure Email Notifications for API Errors
⑤ Automatic SAML App Assignment
You can link each service's Identity Provisioning settings to an existing SAML app.
Key benefits:
- Centralizes user assignment tasks, reducing operational workload
- Ensures consistency between authentication and user synchronization
- Reduces the risk of configuration errors and authentication mismatches
For setup instructions and details, please see the following page.
Configure Automatic SAML App Assignment
Identity Provisioning Feature Setup Flow
The steps for the initial setup are as follows.
- As the initial setup for synchronization, connect TrustLogin to the service
- Specify the members and groups to sync from TrustLogin
- Configure sync-related settings (attribute mapping, scheduled processing, API error notifications, automatic SAML app assignment) (optional)
- Enable synchronization
For the complete setup manual, please see here.
Manage SaaS Users and Groups
Important Notes
When using this feature to automatically create, update, or delete users in a connected service (SaaS),
additional charges may apply based on the connected service's contract terms as the number of users increases.
Please be careful that group-based assignment does not result in unintended synchronization.
We accept no responsibility whatsoever for any charges, fees, or other damages incurred as a result of using this feature.
Before use, please be sure to check the contract terms and billing structure of the connected service,
and, if possible, we recommend testing in a limited scope, such as with a test account.
List of Supported Services
For a list of services that support the Identity Provisioning feature, please see the link below.