[New Version] How to Configure SAML Authentication for Rakuraku Kintai

 Item

Details 

Pre-check

    • Prior configuration in Rakuraku Kintai is required.
    • You must register the same email address used for TrustLogin in the "Single Sign-On ID" field in Rakuraku Kintai.
    • For the latest configuration steps, please refer to the manual provided by Rakuraku Kintai.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

 

Configured by the administrator

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Enabled for all users (SAML authentication and password authentication can be used together)

Notes

  • This manual covers the latest configuration steps for Rakuraku Kintai. For the previous configuration method, please see here.
  • Before configuring SSO, you must first apply for the "SSO Option" in Rakuraku Kintai.
    If this option has not been enabled, you will not be able to configure SSO.
    If you have not yet applied, please contact your representative at RAKUS Co., Ltd.

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings 

TrustLogin User Settings


Preparation

In Rakuraku Kintai, go to "Settings > Employee Settings", select an employee, and click "Edit" at the bottom left of the screen.
On the "Edit Employee" screen that appears, click the "▽" at the bottom right of "Basic Information".
Enter your TrustLogin email address in "Single Sign-On ID" and click "Save".

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png
     
  2. Search on the "Register Company App" screen and select "[New] Rakuraku Kintai (SAML)".
    Rakuraku Kintai02.png
     
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png
     
  4. Enter the Rakuraku Kintai "Customer ID" in the blank field under "Service Provider Settings".Rakuraku Kintai03.png
     
  5. Click the "Register" button to save.
     
  6. Send the obtained metadata to your representative at RAKUS Co., Ltd. and request that they complete the configuration.
     
  7. Once your representative at RAKUS Co., Ltd. confirms that the metadata has been registered, assign users to "[New] Rakuraku Kintai (SAML)" and try the SSO connection.
     

 

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by an administrator in advance.
 

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "[New] Rakuraku Kintai (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

     

② When an administrator adds members

  1. Search for and click the "[New] Rakuraku Kintai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

 

[New Version] How to Configure SAML Authentication for Rakuraku Kintai

 Item

Details 

Pre-check

    • Prior configuration in Rakuraku Kintai is required.
    • You must register the same email address used for TrustLogin in the "Single Sign-On ID" field in Rakuraku Kintai.
    • For the latest configuration steps, please refer to the manual provided by Rakuraku Kintai.

Name ID

Email address

 

Custom attribute Note: For how to configure custom attributes, see here

SP Configuration

 

Configured by the administrator

Request configuration from the SP

Provisioning

 

API-based Provisioning supported (account management available in TrustLogin)

 

SAML JIT Provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Device Compatibility

PC - Browser

PC - Desktop App

iOS - Default Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Default Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Enabled for all users (SAML authentication and password authentication can be used together)

Notes

  • This manual covers the latest configuration steps for Rakuraku Kintai. For the previous configuration method, please see here.
  • Before configuring SSO, you must first apply for the "SSO Option" in Rakuraku Kintai.
    If this option has not been enabled, you will not be able to configure SSO.
    If you have not yet applied, please contact your representative at RAKUS Co., Ltd.

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings 

TrustLogin User Settings


Preparation

In Rakuraku Kintai, go to "Settings > Employee Settings", select an employee, and click "Edit" at the bottom left of the screen.
On the "Edit Employee" screen that appears, click the "▽" at the bottom right of "Basic Information".
Enter your TrustLogin email address in "Single Sign-On ID" and click "Save".

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
    01.png
     
  2. Search on the "Register Company App" screen and select "[New] Rakuraku Kintai (SAML)".
    Rakuraku Kintai02.png
     
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".03.png
     
  4. Enter the Rakuraku Kintai "Customer ID" in the blank field under "Service Provider Settings".Rakuraku Kintai03.png
     
  5. Click the "Register" button to save.
     
  6. Send the obtained metadata to your representative at RAKUS Co., Ltd. and request that they complete the configuration.
     
  7. Once your representative at RAKUS Co., Ltd. confirms that the metadata has been registered, assign users to "[New] Rakuraku Kintai (SAML)" and try the SSO connection.
     

 

TrustLogin User Settings

① When a user adds the app from My Page

Note: The SAML app must be configured by an administrator in advance.
 

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "[New] Rakuraku Kintai (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Register" button.

     

② When an administrator adds members

  1. Search for and click the "[New] Rakuraku Kintai (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.