Managing SaaS User and Group Accounts

This article explains how to use the Identity Provisioning feature to manage users and groups for a connected SaaS (service).

Table of Contents:

Prerequisites

Initial Setup

1. Connect TrustLogin to the Service

2. Assign Members and Groups

3. Customize Sync Settings

4. Enable Sync

  4-1. Prerequisite: Change Sync Settings

  4-2. Enable Sync

5. Check Sync Status

  5-1. About the 'Sync Status' Values

  5-2. How to Check Sync Status Details

Operations After Sync Begins

6. Update User/Group Information in the Destination Service

  6-1. List of Member Sync Behaviors

  6-2. Updating Member Information

  6-3. Updating Group Information

7. Delete Members/Groups in the Destination Service

  7-1. Deleting a User

  7-2. Deleting a Group

Reference Information

Reference: Behavior of Sync Settings On/Off

Prerequisites

Before configuring user and group sync settings, please review the precautions here.

1. Connect TrustLogin to the Service

Check the setup instructions for each service, then create the Identity Provisioning configuration and connect it to the service.

You can find the setup manuals here.

2. Assign Members and Groups

Note: During initial setup, information is not synced simply by assigning members and groups.
 Sync begins once you enable the sync setting after assignment.

Steps to Assign Members and Groups

  1. Go to the Identity Provisioning settings screen > select the target service.
    schedule04.png
  2. From 'Add Member' or 'Add Group', select the members/groups you want to give access, then click the 'Add' button.
    user-management01.png


    user-management02.png

    Note: For services that do not support group-based provisioning,
     the group-related menu will not be displayed.
     In this case, please assign users individually.
     user-management03.png


  3. The assigned members and groups are displayed on the 'Members' and 'Groups' tabs, respectively.
    box18.png

Note: For group assignment, the assignment operation alone does not make the group a sync target.
 To enable group creation/updates, select the target group and click 'Set as Sync Target'.
box36.png
 When the 'Sync Target' column changes to 'Yes', group sync becomes available.
box37.png

3. Customize Sync Settings

The Identity Provisioning feature allows you to configure settings such as attribute mapping and scheduled sync processing.
Please configure the following settings according to your operational needs.

4. Enable Sync

After you finish assigning members and groups, sync begins once you enable the sync setting.

4-1. Prerequisite: Change Sync Settings

The scope of information synced from TrustLogin to the service can be configured in the 'Sync Settings' menu on the settings page.
user-management04.png

  • Turn Sync On:
    Toggles provisioning on/off.
    When off, provisioning is not performed.
  • Default Setting:
    Specifies the default action to take when a member/group is assigned to
    or unassigned from the Identity Provisioning configuration.

    • When on: Sync is performed when a member/group is assigned,
            or when unassigned (removed).

    • When off: Sync is performed only for members/groups whose individual sync is on.

      Note: For details on the behavior depending on whether this checkbox is on or off, see here.
      Note: In addition to the default setting, you can also control this individually using the steps below.

  Steps to Control Sync Individually:

  1. Select the target user/group and click the 'Turn On Sync Behavior' button.box14.png
  2. This is complete once the 'Sync Behavior' field changes to 'Individual Sync On'.box15.png

4-2. Enable Sync

  1. Click the 'Edit' button to the right of the service icon.
    user-management07.png

  2. Turn on the 'Turn Sync On' toggle and click 'Save' to start sync.
    user-management08.png



5. Check Sync Status

After enabling the sync setting, check the 'Sync Status' tab to confirm that sync completed successfully.
user-management09.png

The items you can check on each tab are as follows.

Tab Name What You Can Check
Member Sync Status Sync status of all members assigned individually or via groups
Group Sync Status Sync status of groups that have been assigned and set as sync targets
Group/Member Sync Status Sync status of members within a group


5-1. About the 'Sync Status' Values

user-management10.png
Below is the list of statuses shown in 'Sync Status'.

Status Description
Sync Failed Sync failed for an unexpected reason
Sync Complete Sync finished and was completed successfully on the service side
Error Ignored The administrator performed the 'Ignore Error' action after a sync failure
Scheduled
(shown only on the 'Member Sync Status' tab)
Sync is scheduled


Note: If 'Sync Status' shows 'Sync Complete' or 'Sync Failed',
 you can click the button to view details (the API response from the connected service).
box20.png

 Example: Details screen for Sync Complete
box21.png
Example: Details screen for Sync Failed
box22.png

Note: About 'Ignore Error'

 This feature prevents an error notification email from being sent when sync fails for a target member/group.
 (For example, when you do not want to sync some users within an assigned group.)
 Select the target member or group, then choose 'Ignore Error'.

user-management13.png

5-2. How to Check Sync Status Details

On each 'Sync Status' tab, click a member name or group name to view its sync status details.
user-management12.png

Example: Member sync status details
box24.png

Example: Group sync status details
box43.png

6. Update User/Group Information in the Destination Service

When you update synced attribute information on the TrustLogin side, the information is also synced to the service.

6-1. List of Member Sync Behaviors

Action on TrustLogin Side Behavior on Service Side
Change member attribute information

User information is updated

Note: Information is updated based on the attribute mapping settings.

Suspend member status The user status is deactivated
Activate member status The user status is activated

6-2. Updating Member Information

When you update member information on the TrustLogin side, the 'Last Sync Date/Time' is updated in the following two places.

・The 'Member Sync Status' tab page
box29.png

・The 'Member Sync Status' details page 
box30.png

6-3. Updating Group Information

When you update the 'Group Name' or 'Group Description' on the TrustLogin side, the information is also synced to the service.
When you update member information on the TrustLogin side, the 'Last Sync Date/Time' is updated in the following two places.

・The 'Group Sync Status' tab page
box51.png

・The 'Last Sync Date/Time' is updated on both the tab page and the 'Group Sync Status' page.
box52.png

7. Delete Members/Groups in the Destination Service

7-1. Deleting a User

This is the procedure for deleting a user in the destination service.

  1. On the 'Members' tab, select the target member and click the 'Remove Selected Members' button.
    box31.png
  2. A confirmation message appears; click 'Yes'.
    box32.png

  3. The member is removed from sync targets, and the status is updated on the 'Member Sync Status' tab.
    Deletion is successful when the sync type shows 'Delete' and the sync status shows 'Sync Complete'.
    Confirm that the target user has been deleted on the service side.
    box33.png

7-2. Deleting a Group

This is the procedure for deleting a group in the destination service. There are two methods, as follows.

7-2-1. To Delete Both the Group and Its Members on the Service Side

  1. On the 'Groups' tab, select the target group and click 'Remove Selected Group'.
    box45.png

  2. A confirmation message appears; click 'Yes'.
    box46.png
  3. The group is removed from sync targets, and the status is updated on the 'Group Sync Status' tab.
    Deletion is successful when the sync type shows 'Delete' and the sync status shows 'Sync Complete'.
    box47.png

7-2-2. To Delete Only the Group on the Service Side

  1. On the 'Groups' tab, select the target group and click 'Remove from Sync Targets'.
    box48.png
  2. When the target group's 'Sync Target' setting changes to 'No', sync to the service stops.
    Note: With this method, only the group is deleted; the status of members within the group is not affected.
    box49.png

Reference: Behavior of Sync Settings On/Off

Item Toggle/Checkbox Action on TrustLogin Side Behavior on Service Side
Group User
① Turn Sync On ON
Enable provisioning Syncs according to settings ②-⑤ Syncs according to settings ②-⑤
OFF Do not perform provisioning
② Create/Update Members
by Default
ON Assign a member The user is synced
OFF Assign a member Only users with individual sync on
are synced
③ Create/Update Groups
by Default
ON Assign a group The group is synced Group users are
synced
OFF Assign a group Only groups with individual sync on
are synced
Group users are
synced
④ Delete Members
by Default
ON Delete a member/unassign The user is deleted
Suspend member status The user is deactivated
OFF Delete a member/unassign No change to user status
(not deleted)
Suspend member status The user is deactivated
⑤ Delete Groups
by Default
ON ④ is
ON
Unassign the group The group is deleted Group users are
deleted
Remove from sync targets The group is deleted No effect on group users
Note: Users are removed from the group
Delete the group The group is deleted Group users are
deleted
Remove a member from the group No effect on the group The removed user is deleted
ON ④ is
OFF
Unassign the group The group is deleted No effect on group users
Note: Users are removed from the group
Remove from sync targets The group is deleted No effect on group users
Note: Users are removed from the group
Delete the group The group is deleted No effect on group users
Note: Users are removed from the group
Remove a member from the group No effect on the group No effect on group users
Note: Users are removed from the group
OFF ④ is
ON
Unassign the group No effect on the group Group users are
deleted
Remove from sync targets No effect on the group No effect on group users
Delete the group No effect on the group Group users are
deleted
Remove a member from the group No effect on the group The removed user is deleted
OFF ④ is
OFF
Unassign the group No effect on the group No effect on group users
Remove from sync targets No effect on the group No effect on group users
Delete the group No effect on the group No effect on group users
Note: Users are removed from the group
Remove a member from the group No effect on the group No effect on group users
Note: Users are removed from the group

Managing SaaS User and Group Accounts

This article explains how to use the Identity Provisioning feature to manage users and groups for a connected SaaS (service).

Table of Contents:

Prerequisites

Initial Setup

1. Connect TrustLogin to the Service

2. Assign Members and Groups

3. Customize Sync Settings

4. Enable Sync

  4-1. Prerequisite: Change Sync Settings

  4-2. Enable Sync

5. Check Sync Status

  5-1. About the 'Sync Status' Values

  5-2. How to Check Sync Status Details

Operations After Sync Begins

6. Update User/Group Information in the Destination Service

  6-1. List of Member Sync Behaviors

  6-2. Updating Member Information

  6-3. Updating Group Information

7. Delete Members/Groups in the Destination Service

  7-1. Deleting a User

  7-2. Deleting a Group

Reference Information

Reference: Behavior of Sync Settings On/Off

Prerequisites

Before configuring user and group sync settings, please review the precautions here.

1. Connect TrustLogin to the Service

Check the setup instructions for each service, then create the Identity Provisioning configuration and connect it to the service.

You can find the setup manuals here.

2. Assign Members and Groups

Note: During initial setup, information is not synced simply by assigning members and groups.
 Sync begins once you enable the sync setting after assignment.

Steps to Assign Members and Groups

  1. Go to the Identity Provisioning settings screen > select the target service.
    schedule04.png
  2. From 'Add Member' or 'Add Group', select the members/groups you want to give access, then click the 'Add' button.
    user-management01.png


    user-management02.png

    Note: For services that do not support group-based provisioning,
     the group-related menu will not be displayed.
     In this case, please assign users individually.
     user-management03.png


  3. The assigned members and groups are displayed on the 'Members' and 'Groups' tabs, respectively.
    box18.png

Note: For group assignment, the assignment operation alone does not make the group a sync target.
 To enable group creation/updates, select the target group and click 'Set as Sync Target'.
box36.png
 When the 'Sync Target' column changes to 'Yes', group sync becomes available.
box37.png

3. Customize Sync Settings

The Identity Provisioning feature allows you to configure settings such as attribute mapping and scheduled sync processing.
Please configure the following settings according to your operational needs.

4. Enable Sync

After you finish assigning members and groups, sync begins once you enable the sync setting.

4-1. Prerequisite: Change Sync Settings

The scope of information synced from TrustLogin to the service can be configured in the 'Sync Settings' menu on the settings page.
user-management04.png

  • Turn Sync On:
    Toggles provisioning on/off.
    When off, provisioning is not performed.
  • Default Setting:
    Specifies the default action to take when a member/group is assigned to
    or unassigned from the Identity Provisioning configuration.

    • When on: Sync is performed when a member/group is assigned,
            or when unassigned (removed).

    • When off: Sync is performed only for members/groups whose individual sync is on.

      Note: For details on the behavior depending on whether this checkbox is on or off, see here.
      Note: In addition to the default setting, you can also control this individually using the steps below.

  Steps to Control Sync Individually:

  1. Select the target user/group and click the 'Turn On Sync Behavior' button.box14.png
  2. This is complete once the 'Sync Behavior' field changes to 'Individual Sync On'.box15.png

4-2. Enable Sync

  1. Click the 'Edit' button to the right of the service icon.
    user-management07.png

  2. Turn on the 'Turn Sync On' toggle and click 'Save' to start sync.
    user-management08.png



5. Check Sync Status

After enabling the sync setting, check the 'Sync Status' tab to confirm that sync completed successfully.
user-management09.png

The items you can check on each tab are as follows.

Tab Name What You Can Check
Member Sync Status Sync status of all members assigned individually or via groups
Group Sync Status Sync status of groups that have been assigned and set as sync targets
Group/Member Sync Status Sync status of members within a group


5-1. About the 'Sync Status' Values

user-management10.png
Below is the list of statuses shown in 'Sync Status'.

Status Description
Sync Failed Sync failed for an unexpected reason
Sync Complete Sync finished and was completed successfully on the service side
Error Ignored The administrator performed the 'Ignore Error' action after a sync failure
Scheduled
(shown only on the 'Member Sync Status' tab)
Sync is scheduled


Note: If 'Sync Status' shows 'Sync Complete' or 'Sync Failed',
 you can click the button to view details (the API response from the connected service).
box20.png

 Example: Details screen for Sync Complete
box21.png
Example: Details screen for Sync Failed
box22.png

Note: About 'Ignore Error'

 This feature prevents an error notification email from being sent when sync fails for a target member/group.
 (For example, when you do not want to sync some users within an assigned group.)
 Select the target member or group, then choose 'Ignore Error'.

user-management13.png

5-2. How to Check Sync Status Details

On each 'Sync Status' tab, click a member name or group name to view its sync status details.
user-management12.png

Example: Member sync status details
box24.png

Example: Group sync status details
box43.png

6. Update User/Group Information in the Destination Service

When you update synced attribute information on the TrustLogin side, the information is also synced to the service.

6-1. List of Member Sync Behaviors

Action on TrustLogin Side Behavior on Service Side
Change member attribute information

User information is updated

Note: Information is updated based on the attribute mapping settings.

Suspend member status The user status is deactivated
Activate member status The user status is activated

6-2. Updating Member Information

When you update member information on the TrustLogin side, the 'Last Sync Date/Time' is updated in the following two places.

・The 'Member Sync Status' tab page
box29.png

・The 'Member Sync Status' details page 
box30.png

6-3. Updating Group Information

When you update the 'Group Name' or 'Group Description' on the TrustLogin side, the information is also synced to the service.
When you update member information on the TrustLogin side, the 'Last Sync Date/Time' is updated in the following two places.

・The 'Group Sync Status' tab page
box51.png

・The 'Last Sync Date/Time' is updated on both the tab page and the 'Group Sync Status' page.
box52.png

7. Delete Members/Groups in the Destination Service

7-1. Deleting a User

This is the procedure for deleting a user in the destination service.

  1. On the 'Members' tab, select the target member and click the 'Remove Selected Members' button.
    box31.png
  2. A confirmation message appears; click 'Yes'.
    box32.png

  3. The member is removed from sync targets, and the status is updated on the 'Member Sync Status' tab.
    Deletion is successful when the sync type shows 'Delete' and the sync status shows 'Sync Complete'.
    Confirm that the target user has been deleted on the service side.
    box33.png

7-2. Deleting a Group

This is the procedure for deleting a group in the destination service. There are two methods, as follows.

7-2-1. To Delete Both the Group and Its Members on the Service Side

  1. On the 'Groups' tab, select the target group and click 'Remove Selected Group'.
    box45.png

  2. A confirmation message appears; click 'Yes'.
    box46.png
  3. The group is removed from sync targets, and the status is updated on the 'Group Sync Status' tab.
    Deletion is successful when the sync type shows 'Delete' and the sync status shows 'Sync Complete'.
    box47.png

7-2-2. To Delete Only the Group on the Service Side

  1. On the 'Groups' tab, select the target group and click 'Remove from Sync Targets'.
    box48.png
  2. When the target group's 'Sync Target' setting changes to 'No', sync to the service stops.
    Note: With this method, only the group is deleted; the status of members within the group is not affected.
    box49.png

Reference: Behavior of Sync Settings On/Off

Item Toggle/Checkbox Action on TrustLogin Side Behavior on Service Side
Group User
① Turn Sync On ON
Enable provisioning Syncs according to settings ②-⑤ Syncs according to settings ②-⑤
OFF Do not perform provisioning
② Create/Update Members
by Default
ON Assign a member The user is synced
OFF Assign a member Only users with individual sync on
are synced
③ Create/Update Groups
by Default
ON Assign a group The group is synced Group users are
synced
OFF Assign a group Only groups with individual sync on
are synced
Group users are
synced
④ Delete Members
by Default
ON Delete a member/unassign The user is deleted
Suspend member status The user is deactivated
OFF Delete a member/unassign No change to user status
(not deleted)
Suspend member status The user is deactivated
⑤ Delete Groups
by Default
ON ④ is
ON
Unassign the group The group is deleted Group users are
deleted
Remove from sync targets The group is deleted No effect on group users
Note: Users are removed from the group
Delete the group The group is deleted Group users are
deleted
Remove a member from the group No effect on the group The removed user is deleted
ON ④ is
OFF
Unassign the group The group is deleted No effect on group users
Note: Users are removed from the group
Remove from sync targets The group is deleted No effect on group users
Note: Users are removed from the group
Delete the group The group is deleted No effect on group users
Note: Users are removed from the group
Remove a member from the group No effect on the group No effect on group users
Note: Users are removed from the group
OFF ④ is
ON
Unassign the group No effect on the group Group users are
deleted
Remove from sync targets No effect on the group No effect on group users
Delete the group No effect on the group Group users are
deleted
Remove a member from the group No effect on the group The removed user is deleted
OFF ④ is
OFF
Unassign the group No effect on the group No effect on group users
Remove from sync targets No effect on the group No effect on group users
Delete the group No effect on the group No effect on group users
Note: Users are removed from the group
Remove a member from the group No effect on the group No effect on group users
Note: Users are removed from the group