How to Configure SAML Authentication for FUJIFILM IWpro

Item

Details

Pre-check

  • This app is for "IT Expertservices ID Management".
  • Pre-configuration is required in FUJIFILM IWpro.
  • You must create an account in FUJIFILM IWpro using the same email address as your TrustLogin account.
  • Configuring SAML for FUJIFILM IWpro requires an account with system administrator privileges for the tenant to which FUJIFILM IWpro belongs on FUJIFILM BI Direct.
Name ID Email address
  Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
  Request SP to configure
Provisioning   API-based Provisioning supported (Account management available in TrustLogin)
  SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

None

 

Table of Contents:

TrustLogin Admin Page Settings

FUJIFILM IWpro Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Log In

① First Login via SAML Authentication

② How to Log In via SP-Initiated SSO

 ③ How to Log In via the Native App

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
     
  2. On the "Register Company App" screen, search and select "FUJIFILM IWpro (SAML)".
    02_2.png
     
  3. Under "Identity Provider Information", note down the value of "Identity Provider URL", and download the certificate using the "Get Certificate" button.
    03.png
     

Now, switch to configuring the FUJIFILM IWpro side.
Without clicking the "Save" button, open FUJIFILM BI Direct in a separate window.

 

FUJIFILM IWpro Settings

  1. Log in to FUJIFILM BI Direct with an account that has system administrator privileges, and open "Tenant Management".
    04.png
     
  2. Click the tenant name of the target tenant.
    05.png

  3. Open "External Authentication Integration Management" and click "Add Authentication Provider".
    06.png

  4. For the authentication provider, select "ITExpertServicesID" and click "Add".
    07.png
     
  5. Configure "ITExpertServicesID Settings" as follows, and click "Next".

    Tenant ID Copy the value and note it down
    Single Sign-On Service URL The "Identity Provider URL" obtained from TrustLogin
    X.509 Certificate for Verification The contents of the "Certificate" obtained from TrustLogin
    Note: Remove the first line "-----BEGIN CERTIFICATE-----" and the last line "-----END CERTIFICATE-----"
     
    Identity Provider Code Copy the value and note it down


    08.png
     

  6. If you want to set a "Domain Restriction for Registered User IDs", configure it (optional), and click "Confirm Entries".
    09.png
     
  7. Click "Configure" to save.
    10.png

 

Return to the TrustLogin Admin Page again.

 

TrustLogin Admin Page Settings (Continued)

  1. Configure the fields under "SAML Attribute Settings" as follows.

    Attribute Name Attribute Value
    tenant_id Delete {Tenant ID} and overwrite it with the "Tenant ID" obtained from FUJIFILM BI Direct
    id_provider_cd Delete {Identity Provider Code} and overwrite it with the "Identity Provider Code" obtained from FUJIFILM BI Direct
    client_id osscomagent1
    Note: No change needed; leave as the default value
    relay_state https://fbiwpro.fujifilm.com/
    Note: No change needed; leave as the default value


    11.png
     

  2. Click the "Register" button to save.

 

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "FUJIFILM IWpro (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

 

How to Log In

① First Login via SAML Authentication

  1. When you click the app from My Page, the following screen is displayed, and you will receive an email titled "Notice of FUJIFILM BI Direct External Authentication Integration Settings".
    12.png

     
  2. Open the link in the received email (【External Authentication Integration Setting Confirmation URL】).

     
  3. Click "Accept" to complete the login.
    13.png

Note: The above steps are not required for subsequent logins.

 

② How to Log In via SP-Initiated SSO

You can also log in from the FUJIFILM IWpro login screen by following the steps below.

  1. On the FUJIFILM IWpro login screen, enter your "User ID (email address)" and proceed by clicking the "Next" button.
    17.png

  2. Under "Log in with a Linked Account", click "ITExpertServicesID".
    18.png

  3. If you are already logged in to TrustLogin, you will be logged in to FUJIFILM IWpro immediately.
    If you are not logged in to TrustLogin, the TrustLogin login screen will be displayed, and after authentication, you will be logged in to FUJIFILM IWpro.

     

③ How to Log In via the Native App

  1. Open the native app and go to the login screen.
    Tap "Log in with a Linked Account > ITExpertServicesID".
     
  2. Enter your "User ID (email address)" and tap "Next".
     
  3. The TrustLogin login screen will be displayed, and after authentication, you will be logged in to FUJIFILM IWpro.

How to Configure SAML Authentication for FUJIFILM IWpro

Item

Details

Pre-check

  • This app is for "IT Expertservices ID Management".
  • Pre-configuration is required in FUJIFILM IWpro.
  • You must create an account in FUJIFILM IWpro using the same email address as your TrustLogin account.
  • Configuring SAML for FUJIFILM IWpro requires an account with system administrator privileges for the tenant to which FUJIFILM IWpro belongs on FUJIFILM BI Direct.
Name ID Email address
  Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
  Request SP to configure
Provisioning   API-based Provisioning supported (Account management available in TrustLogin)
  SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

None

 

Table of Contents:

TrustLogin Admin Page Settings

FUJIFILM IWpro Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Log In

① First Login via SAML Authentication

② How to Log In via SP-Initiated SSO

 ③ How to Log In via the Native App

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
     
  2. On the "Register Company App" screen, search and select "FUJIFILM IWpro (SAML)".
    02_2.png
     
  3. Under "Identity Provider Information", note down the value of "Identity Provider URL", and download the certificate using the "Get Certificate" button.
    03.png
     

Now, switch to configuring the FUJIFILM IWpro side.
Without clicking the "Save" button, open FUJIFILM BI Direct in a separate window.

 

FUJIFILM IWpro Settings

  1. Log in to FUJIFILM BI Direct with an account that has system administrator privileges, and open "Tenant Management".
    04.png
     
  2. Click the tenant name of the target tenant.
    05.png

  3. Open "External Authentication Integration Management" and click "Add Authentication Provider".
    06.png

  4. For the authentication provider, select "ITExpertServicesID" and click "Add".
    07.png
     
  5. Configure "ITExpertServicesID Settings" as follows, and click "Next".

    Tenant ID Copy the value and note it down
    Single Sign-On Service URL The "Identity Provider URL" obtained from TrustLogin
    X.509 Certificate for Verification The contents of the "Certificate" obtained from TrustLogin
    Note: Remove the first line "-----BEGIN CERTIFICATE-----" and the last line "-----END CERTIFICATE-----"
     
    Identity Provider Code Copy the value and note it down


    08.png
     

  6. If you want to set a "Domain Restriction for Registered User IDs", configure it (optional), and click "Confirm Entries".
    09.png
     
  7. Click "Configure" to save.
    10.png

 

Return to the TrustLogin Admin Page again.

 

TrustLogin Admin Page Settings (Continued)

  1. Configure the fields under "SAML Attribute Settings" as follows.

    Attribute Name Attribute Value
    tenant_id Delete {Tenant ID} and overwrite it with the "Tenant ID" obtained from FUJIFILM BI Direct
    id_provider_cd Delete {Identity Provider Code} and overwrite it with the "Identity Provider Code" obtained from FUJIFILM BI Direct
    client_id osscomagent1
    Note: No change needed; leave as the default value
    relay_state https://fbiwpro.fujifilm.com/
    Note: No change needed; leave as the default value


    11.png
     

  2. Click the "Register" button to save.

 

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "", and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "FUJIFILM IWpro (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

 

How to Log In

① First Login via SAML Authentication

  1. When you click the app from My Page, the following screen is displayed, and you will receive an email titled "Notice of FUJIFILM BI Direct External Authentication Integration Settings".
    12.png

     
  2. Open the link in the received email (【External Authentication Integration Setting Confirmation URL】).

     
  3. Click "Accept" to complete the login.
    13.png

Note: The above steps are not required for subsequent logins.

 

② How to Log In via SP-Initiated SSO

You can also log in from the FUJIFILM IWpro login screen by following the steps below.

  1. On the FUJIFILM IWpro login screen, enter your "User ID (email address)" and proceed by clicking the "Next" button.
    17.png

  2. Under "Log in with a Linked Account", click "ITExpertServicesID".
    18.png

  3. If you are already logged in to TrustLogin, you will be logged in to FUJIFILM IWpro immediately.
    If you are not logged in to TrustLogin, the TrustLogin login screen will be displayed, and after authentication, you will be logged in to FUJIFILM IWpro.

     

③ How to Log In via the Native App

  1. Open the native app and go to the login screen.
    Tap "Log in with a Linked Account > ITExpertServicesID".
     
  2. Enter your "User ID (email address)" and tap "Next".
     
  3. The TrustLogin login screen will be displayed, and after authentication, you will be logged in to FUJIFILM IWpro.