This article explains how to use the Identity Provisioning feature to manage users and groups for a connected SaaS (service).
|
Table of Contents: Initial Setup 1. Connect TrustLogin to the Service 4-1. Prerequisite: Change Sync Settings 5-1. About the 'Sync Status' Values 5-2. How to Check Sync Status Details Operations After Sync Begins 6. Update User/Group Information in the Destination Service 6-1. List of Member Sync Behaviors 6-2. Updating Member Information 6-3. Updating Group Information 7. Delete Members/Groups in the Destination Service Reference Information |
Prerequisites
Before configuring user and group sync settings, please review the precautions here.
1. Connect TrustLogin to the Service
Check the setup instructions for each service, then create the Identity Provisioning configuration and connect it to the service.
You can find the setup manuals here.
2. Assign Members and Groups
Note: During initial setup, information is not synced simply by assigning members and groups.
Sync begins once you enable the sync setting after assignment.
Steps to Assign Members and Groups
- Go to the Identity Provisioning settings screen > select the target service.
-
From 'Add Member' or 'Add Group', select the members/groups you want to give access, then click the 'Add' button.
Note: For services that do not support group-based provisioning,
the group-related menu will not be displayed.
In this case, please assign users individually.
- The assigned members and groups are displayed on the 'Members' and 'Groups' tabs, respectively.
Note: For group assignment, the assignment operation alone does not make the group a sync target.
To enable group creation/updates, select the target group and click 'Set as Sync Target'.
When the 'Sync Target' column changes to 'Yes', group sync becomes available.
3. Customize Sync Settings
The Identity Provisioning feature allows you to configure settings such as attribute mapping and scheduled sync processing.
Please configure the following settings according to your operational needs.
- Attribute Mapping Settings
- Scheduled Processing for Joining/Leaving Employees
- Email Notifications for API Errors
- Automatic SAML App Assignment
4. Enable Sync
After you finish assigning members and groups, sync begins once you enable the sync setting.
4-1. Prerequisite: Change Sync Settings
The scope of information synced from TrustLogin to the service can be configured in the 'Sync Settings' menu on the settings page.
-
Turn Sync On:
Toggles provisioning on/off.
When off, provisioning is not performed.
-
Default Setting:
Specifies the default action to take when a member/group is assigned to
or unassigned from the Identity Provisioning configuration.-
When on: Sync is performed when a member/group is assigned,
or when unassigned (removed). -
When off: Sync is performed only for members/groups whose individual sync is on.
Note: For details on the behavior depending on whether this checkbox is on or off, see here.
Note: In addition to the default setting, you can also control this individually using the steps below.
-
Steps to Control Sync Individually:
- Select the target user/group and click the 'Turn On Sync Behavior' button.
- This is complete once the 'Sync Behavior' field changes to 'Individual Sync On'.
4-2. Enable Sync
- Click the 'Edit' button to the right of the service icon.
- Turn on the 'Turn Sync On' toggle and click 'Save' to start sync.
5. Check Sync Status
After enabling the sync setting, check the 'Sync Status' tab to confirm that sync completed successfully.
The items you can check on each tab are as follows.
| Tab Name | What You Can Check |
| Member Sync Status | Sync status of all members assigned individually or via groups |
| Group Sync Status | Sync status of groups that have been assigned and set as sync targets |
| Group/Member Sync Status | Sync status of members within a group |
5-1. About the 'Sync Status' Values
Below is the list of statuses shown in 'Sync Status'.
| Status | Description |
| Sync Failed | Sync failed for an unexpected reason |
| Sync Complete | Sync finished and was completed successfully on the service side |
| Error Ignored | The administrator performed the 'Ignore Error' action after a sync failure |
| Scheduled (shown only on the 'Member Sync Status' tab) |
Sync is scheduled |
Note: If 'Sync Status' shows 'Sync Complete' or 'Sync Failed',
you can click the button to view details (the API response from the connected service).
Example: Details screen for Sync Complete
Example: Details screen for Sync Failed
Note: About 'Ignore Error'
This feature prevents an error notification email from being sent when sync fails for a target member/group.
(For example, when you do not want to sync some users within an assigned group.)
Select the target member or group, then choose 'Ignore Error'.
5-2. How to Check Sync Status Details
On each 'Sync Status' tab, click a member name or group name to view its sync status details.
Example: Member sync status details
Example: Group sync status details
6. Update User/Group Information in the Destination Service
When you update synced attribute information on the TrustLogin side, the information is also synced to the service.
6-1. List of Member Sync Behaviors
| Action on TrustLogin Side | Behavior on Service Side |
| Change member attribute information |
User information is updated Note: Information is updated based on the attribute mapping settings. |
| Suspend member status | The user status is deactivated |
| Activate member status | The user status is activated |
6-2. Updating Member Information
When you update member information on the TrustLogin side, the 'Last Sync Date/Time' is updated in the following two places.
・The 'Member Sync Status' tab page
・The 'Member Sync Status' details page
6-3. Updating Group Information
When you update the 'Group Name' or 'Group Description' on the TrustLogin side, the information is also synced to the service.
When you update member information on the TrustLogin side, the 'Last Sync Date/Time' is updated in the following two places.
・The 'Group Sync Status' tab page
・The 'Last Sync Date/Time' is updated on both the tab page and the 'Group Sync Status' page.
7. Delete Members/Groups in the Destination Service
7-1. Deleting a User
This is the procedure for deleting a user in the destination service.
- On the 'Members' tab, select the target member and click the 'Remove Selected Members' button.
- A confirmation message appears; click 'Yes'.
- The member is removed from sync targets, and the status is updated on the 'Member Sync Status' tab.
Deletion is successful when the sync type shows 'Delete' and the sync status shows 'Sync Complete'.
Confirm that the target user has been deleted on the service side.
7-2. Deleting a Group
This is the procedure for deleting a group in the destination service. There are two methods, as follows.
7-2-1. To Delete Both the Group and Its Members on the Service Side
- On the 'Groups' tab, select the target group and click 'Remove Selected Group'.
- A confirmation message appears; click 'Yes'.
- The group is removed from sync targets, and the status is updated on the 'Group Sync Status' tab.
Deletion is successful when the sync type shows 'Delete' and the sync status shows 'Sync Complete'.
7-2-2. To Delete Only the Group on the Service Side
- On the 'Groups' tab, select the target group and click 'Remove from Sync Targets'.
- When the target group's 'Sync Target' setting changes to 'No', sync to the service stops.
Note: With this method, only the group is deleted; the status of members within the group is not affected.
Reference: Behavior of Sync Settings On/Off
| Item | Toggle/Checkbox | Action on TrustLogin Side | Behavior on Service Side | ||
| Group | User | ||||
| ① Turn Sync On | ON |
Enable provisioning | Syncs according to settings ②-⑤ | Syncs according to settings ②-⑤ | |
| OFF | Do not perform provisioning | ‐ | ‐ | ||
| ② Create/Update Members by Default |
ON | Assign a member | ‐ | The user is synced | |
| OFF | Assign a member | ‐ | Only users with individual sync on are synced |
||
| ③ Create/Update Groups by Default |
ON | Assign a group | The group is synced | Group users are synced |
|
| OFF | Assign a group | Only groups with individual sync on are synced |
Group users are synced |
||
| ④ Delete Members by Default |
ON | Delete a member/unassign | ‐ | The user is deleted | |
| Suspend member status | ‐ | The user is deactivated | |||
| OFF | Delete a member/unassign | ‐ | No change to user status (not deleted) |
||
| Suspend member status | ‐ | The user is deactivated | |||
| ⑤ Delete Groups by Default |
ON | ④ is ON |
Unassign the group | The group is deleted | Group users are deleted |
| Remove from sync targets | The group is deleted | No effect on group users Note: Users are removed from the group |
|||
| Delete the group | The group is deleted | Group users are deleted |
|||
| Remove a member from the group | No effect on the group | The removed user is deleted | |||
| ON | ④ is OFF |
Unassign the group | The group is deleted | No effect on group users Note: Users are removed from the group |
|
| Remove from sync targets | The group is deleted | No effect on group users Note: Users are removed from the group |
|||
| Delete the group | The group is deleted | No effect on group users Note: Users are removed from the group |
|||
| Remove a member from the group | No effect on the group | No effect on group users Note: Users are removed from the group |
|||
| OFF | ④ is ON |
Unassign the group | No effect on the group | Group users are deleted |
|
| Remove from sync targets | No effect on the group | No effect on group users | |||
| Delete the group | No effect on the group | Group users are deleted |
|||
| Remove a member from the group | No effect on the group | The removed user is deleted | |||
| OFF | ④ is OFF |
Unassign the group | No effect on the group | No effect on group users | |
| Remove from sync targets | No effect on the group | No effect on group users | |||
| Delete the group | No effect on the group | No effect on group users Note: Users are removed from the group |
|||
| Remove a member from the group | No effect on the group | No effect on group users Note: Users are removed from the group |
|||