[New Platform] How to Configure SAML Authentication for InsuiteX

Item

Details

Pre-check

  • Pre-configuration is required in InsuiteX.

  • You must create an account in InsuiteX using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by InsuiteX.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the Administrator

Request SP to configure

Provisioning

API-based Provisioning supported (Account management available in TrustLogin)

SAML JITProvisioning supported (Account management available in TrustLogin; user deletion not available)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users with SAML authentication applied on the SP side; password authentication can be used concurrently

Notes

A new SAML authentication platform was released for InsuiteX in 2024. Customers who have been using the service since before this release are using the old specification, so please refer to "How to Configure SAML Authentication for InsuiteX".

Please check the authentication settings screen to determine which version (new or old) applies to you.

[How to Check Your Version]

After logging in to InsuiteX, you can check this from "System Administration > System Information".

If "Version > Authentication Platform" is v3: New Platform
If "Version > Authentication Platform" is v1 or v2: Old Platform

Table of Contents:

TrustLogin Admin Page Settings

InsuiteX Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Company App Registration" screen, search for and select "[New Platform] InsuiteX (SAML)".
    02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, proceed to the InsuiteX settings.
Do not click the "Register" button yet; open InsuiteX in a separate window.

InsuiteX Settings

  1. Log in with an administrator account and open "System Administration > Authentication Settings" from the icon in the top right.
    04.png

  2. Open "Edit" for "SAML".
    05.png

    Note: You can also configure multiple SAML settings. To add a second or subsequent SAML setting, click the "Register" button.
    11.png

  3. Configure each item as follows.
    Button name displayed on the login page (Optional) If you want to change the label of the SSO login button on the login page, you can change it to any text you like. (Note)
    SAML Sign-on Endpoint URL The "Identity Provider URL" obtained from TrustLogin
    X.509 Certificate The content of the "Certificate" obtained from TrustLogin
    Name ID Select "Email Address (EMAIL)"

    06.png

    (Note:) On the InsuiteX login page, the SSO login button will be displayed using the label set in "Button name displayed on the login page", as shown below. You can also log in via SP-initiated SSO using this button.
    10.png

  4. Click "Metadata" and use the "Copy" button to get and note down the displayed "Identifier (Entity ID)" and "Response URL (ACS URL)".
    07.png

  5. Open "IP Address Control" and configure the availability of SAML SSO by selecting either an IP address block list or an allow list.
    Finally, save by clicking the "Save" button.
    08.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Response URL (ACS URL)" obtained from InsuiteX
    Entity ID The "Identifier (Entity ID)" obtained from InsuiteX
    ACS URL to the Service The "Response URL (ACS URL)" obtained from InsuiteX

    09.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "[New Platform] InsuiteX (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for the "[New Platform] InsuiteX (SAML)" app and click it.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

[New Platform] How to Configure SAML Authentication for InsuiteX

Item

Details

Pre-check

  • Pre-configuration is required in InsuiteX.

  • You must create an account in InsuiteX using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by InsuiteX.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

Configured by the Administrator

Request SP to configure

Provisioning

API-based Provisioning supported (Account management available in TrustLogin)

SAML JITProvisioning supported (Account management available in TrustLogin; user deletion not available)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users with SAML authentication applied on the SP side; password authentication can be used concurrently

Notes

A new SAML authentication platform was released for InsuiteX in 2024. Customers who have been using the service since before this release are using the old specification, so please refer to "How to Configure SAML Authentication for InsuiteX".

Please check the authentication settings screen to determine which version (new or old) applies to you.

[How to Check Your Version]

After logging in to InsuiteX, you can check this from "System Administration > System Information".

If "Version > Authentication Platform" is v3: New Platform
If "Version > Authentication Platform" is v1 or v2: Old Platform

Table of Contents:

TrustLogin Admin Page Settings

InsuiteX Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings


TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Company App Registration" screen, search for and select "[New Platform] InsuiteX (SAML)".
    02.png

  3. Note down the value of "Identity Provider URL" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
    03.png

Now, proceed to the InsuiteX settings.
Do not click the "Register" button yet; open InsuiteX in a separate window.

InsuiteX Settings

  1. Log in with an administrator account and open "System Administration > Authentication Settings" from the icon in the top right.
    04.png

  2. Open "Edit" for "SAML".
    05.png

    Note: You can also configure multiple SAML settings. To add a second or subsequent SAML setting, click the "Register" button.
    11.png

  3. Configure each item as follows.
    Button name displayed on the login page (Optional) If you want to change the label of the SSO login button on the login page, you can change it to any text you like. (Note)
    SAML Sign-on Endpoint URL The "Identity Provider URL" obtained from TrustLogin
    X.509 Certificate The content of the "Certificate" obtained from TrustLogin
    Name ID Select "Email Address (EMAIL)"

    06.png

    (Note:) On the InsuiteX login page, the SSO login button will be displayed using the label set in "Button name displayed on the login page", as shown below. You can also log in via SP-initiated SSO using this button.
    10.png

  4. Click "Metadata" and use the "Copy" button to get and note down the displayed "Identifier (Entity ID)" and "Response URL (ACS URL)".
    07.png

  5. Open "IP Address Control" and configure the availability of SAML SSO by selecting either an IP address block list or an allow list.
    Finally, save by clicking the "Save" button.
    08.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.
    Login URL The "Response URL (ACS URL)" obtained from InsuiteX
    Entity ID The "Identifier (Entity ID)" obtained from InsuiteX
    ACS URL to the Service The "Response URL (ACS URL)" obtained from InsuiteX

    09.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "[New Platform] InsuiteX (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for the "[New Platform] InsuiteX (SAML)" app and click it.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.