|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP Configuration |
〇 |
Configured by the Administrator |
|
Request SP to configure |
||
|
Provisioning |
API-based Provisioning supported (Account management available in TrustLogin) |
|
|
SAML JITProvisioning supported (Account management available in TrustLogin; user deletion not available) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
ー |
IdP-Initiated SSO |
|
|
Device Compatibility |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Default Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Default Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
|
SAML Authentication Scope |
ー |
Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled only for users with SAML authentication applied on the SP side; password authentication can be used concurrently |
|
|
Notes |
A new SAML authentication platform was released for InsuiteX in 2024. Customers who have been using the service since before this release are using the old specification, so please refer to "How to Configure SAML Authentication for InsuiteX". Please check the authentication settings screen to determine which version (new or old) applies to you.
[How to Check Your Version] After logging in to InsuiteX, you can check this from "System Administration > System Information". If "Version > Authentication Platform" is v3: New Platform |
|
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Company App Registration" screen, search for and select "[New Platform] InsuiteX (SAML)".
- Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, proceed to the InsuiteX settings.
Do not click the "Register" button yet; open InsuiteX in a separate window.
InsuiteX Settings
- Log in with an administrator account and open "System Administration > Authentication Settings" from the icon in the top right.
- Open "Edit" for "SAML".
Note: You can also configure multiple SAML settings. To add a second or subsequent SAML setting, click the "Register" button.
- Configure each item as follows.
Button name displayed on the login page (Optional) If you want to change the label of the SSO login button on the login page, you can change it to any text you like. (Note) SAML Sign-on Endpoint URL The "Identity Provider URL" obtained from TrustLogin X.509 Certificate The content of the "Certificate" obtained from TrustLogin Name ID Select "Email Address (EMAIL)"
(Note:) On the InsuiteX login page, the SSO login button will be displayed using the label set in "Button name displayed on the login page", as shown below. You can also log in via SP-initiated SSO using this button.
- Click "Metadata" and use the "Copy" button to get and note down the displayed "Identifier (Entity ID)" and "Response URL (ACS URL)".
- Open "IP Address Control" and configure the availability of SAML SSO by selecting either an IP address block list or an allow list.
Finally, save by clicking the "Save" button.
Return to the TrustLogin Admin Page again.
TrustLogin Admin Page Settings (Continued)
- Configure the "Service Provider Settings" as follows.
Login URL The "Response URL (ACS URL)" obtained from InsuiteX Entity ID The "Identifier (Entity ID)" obtained from InsuiteX ACS URL to the Service The "Response URL (ACS URL)" obtained from InsuiteX
- Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
Note: The SAML app must be configured by the Administrator in advance.
- Click the "Add App" button on "My Page".
- On the "App Registration" screen, select "[New Platform] InsuiteX (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for the "[New Platform] InsuiteX (SAML)" app and click it.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.