How to Configure SAML Authentication for manage

Item

Details

Pre-check

  • Prior configuration in manage (formerly ManageOZO3) is required.

  • Please refer to the manual provided by manage for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "manage (SAML)".
    02.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring manage . Open manage in a separate window.

manage Configuration

  1. Log in with a user account that has access to "SSO Settings", and open "Admin App > SSO Settings" from the menu.
    04.png

  2. Open "Administration".
    05.png

  3. Enable "SSO Enabled/Disabled" and click "Update".
    Note: If you enable this setting, users will no longer be able to log in using regular login, so please be careful.
    06.png

  4. Click "Finish Administration Settings".
    07.png

  5. Configure each item of the authentication settings as follows.
    Sign-on URL The "IdP URL" obtained from TrustLogin
    Portal URL (optional)

    Specify the URL of the site to display after logging out of manage

    Identity Provider Certificate The contents of the "certificate" obtained from TrustLogin

    08.png

  6. After clicking the "Update" button, download the Service Provider metadata.
    09.png

  7. Open "Authentication Linked ID List", specify the affiliation, and export the user list as a CSV.
    10.png

  8. Open the exported CSV file, enter the corresponding user's TrustLogin email address in the "Linked ID" field, and overwrite the file.

  9. Open "Import CSV Data" and upload the file you created.
    11.png

  10. Confirm that the import was completed successfully, and click the "Update" button.
    12.png

Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. In "Service Provider Settings", set the "Redirect URL After Successful SP Authentication" to the URL of manage,
    and upload the metadata downloaded from manage to "Metadata".
    13.png

  2. Save the configuration by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "manage (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "manage (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for manage

Item

Details

Pre-check

  • Prior configuration in manage (formerly ManageOZO3) is required.

  • Please refer to the manual provided by manage for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "manage (SAML)".
    02.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    03.png

Now, switch to configuring manage . Open manage in a separate window.

manage Configuration

  1. Log in with a user account that has access to "SSO Settings", and open "Admin App > SSO Settings" from the menu.
    04.png

  2. Open "Administration".
    05.png

  3. Enable "SSO Enabled/Disabled" and click "Update".
    Note: If you enable this setting, users will no longer be able to log in using regular login, so please be careful.
    06.png

  4. Click "Finish Administration Settings".
    07.png

  5. Configure each item of the authentication settings as follows.
    Sign-on URL The "IdP URL" obtained from TrustLogin
    Portal URL (optional)

    Specify the URL of the site to display after logging out of manage

    Identity Provider Certificate The contents of the "certificate" obtained from TrustLogin

    08.png

  6. After clicking the "Update" button, download the Service Provider metadata.
    09.png

  7. Open "Authentication Linked ID List", specify the affiliation, and export the user list as a CSV.
    10.png

  8. Open the exported CSV file, enter the corresponding user's TrustLogin email address in the "Linked ID" field, and overwrite the file.

  9. Open "Import CSV Data" and upload the file you created.
    11.png

  10. Confirm that the import was completed successfully, and click the "Update" button.
    12.png

Now return to the TrustLogin settings again.

TrustLogin Admin Page Settings (Continued)

  1. In "Service Provider Settings", set the "Redirect URL After Successful SP Authentication" to the URL of manage,
    and upload the metadata downloaded from manage to "Metadata".
    13.png

  2. Save the configuration by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "manage (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "manage (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.