Item |
Details |
|
|---|---|---|
Pre-check |
|
|
| Name ID | Email address | |
| 〇 | Custom attribute Note: For how to configure custom attributes, seehere | |
| SP Configuration | 〇 | Configured by the Administrator |
| Request SP to configure | ||
| Provisioning | API-based Provisioning supported (Account management available in TrustLogin) | |
| SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available) | ||
| 〇 | None (accounts created in each system) | |
| Access Method | 〇 | SP-Initiated SSO |
| 〇 | IdP-Initiated SSO | |
| Device Compatibility | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Default Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App In-App Browser | |
| ー | iOS - Native App | |
| 〇 | Android - Default Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App In-App Browser | |
| ー | Android - Native App | |
| SAML Authentication Scope | ー | Enabled for all users (SAML authentication only) |
| 〇 | Other: Enabled for all users (both SAML authentication and password authentication available) | |
Notes |
None | |
|
Table of Contents: TrustLogin Admin Page Settings |
Preparation
Add a Custom Attribute to User Information
Add the ExchangeUSE ZERO "Login ID" information to the TrustLogin member information as a custom attribute.
[ExchangeUSE ZERO User Information Screen]
[TrustLogin Custom Attribute Configuration Example]
Please refer to the following pages for instructions on how to configure custom attributes. The attribute name for the custom attribute can be anything you like.
Custom Attribute Setup (Individual Registration)
Custom Attribute Setup (Bulk Registration)
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Company App" screen, search and select "ExchangeUSE ZERO (SAML)".
- Under "Identity Provider Information", note down the value of "Identity Provider URL", and download the certificate using the "Get Certificate" button.
- Change the file extension of the downloaded certificate to ".crt" to convert it to CRT format.
At this point, move on to configuring ExchangeUSE ZERO.
Do not click the "Register" button yet — open ExchangeUSE ZERO in a separate window.
ExchangeUSE ZERO Settings
- Log in with an administrator account and open "System Settings > System Preferences > Single Sign-On Settings".
-
Configure each item as follows, and save by clicking the "Save" button.
IdP Endpoint URL The "Identity Provider URL" obtained from TrustLogin IdP Token Signing Certificate Upload the "Certificate" obtained from TrustLogin (converted to CRT format) using the "Import" button Identifier Set any string of your choice ExchangeUSE Response Receiving URL Obtain the value using the "Copy" button
Now, return to the TrustLogin Admin Page.
TrustLogin Admin Page Settings (Continued)
-
Configure the "Service Provider Settings" as follows.
Entity ID The string you set for "Identifier" in ExchangeUSE ZERO Value for Name ID Select the custom attribute configured in Preparation ACS URL to Service The "ExchangeUSE Response Receiving URL" obtained from ExchangeUSE ZERO - Save by clicking the "Register" button.
TrustLogin User Settings
① When a User Adds the App from My Page
Note: The SAML app must be configured by the Administrator in advance.
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "ExchangeUSE ZERO (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Save" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for and click the "ExchangeUSE ZERO (SAML)" app.
-
Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.
How to Log In
① When Logging In via SP-Initiated SSO
You can log in via SP-initiated SSO by accessing the "SAML Login URL (PC Site)" URL on the ExchangeUSE ZERO SAML authentication settings screen.
② When Using the Mobile Site
Logging in to "ExchangeUSE ZERO (SAML)" via the TrustLogin mobile app will display the PC site, so if you want to use the mobile site, you will need to create a separate bookmark app.
Obtain the "SAML Login URL (Mobile Site)" URL from the ExchangeUSE ZERO SAML authentication settings screen, and create and use a bookmark app with it.
Please refer to the manual below for how to use the bookmark app.
How to Configure the Bookmark Template
Note: Accessing the mobile site via the bookmark app may require you to re-authenticate with TrustLogin. After authentication, you will be logged in to the mobile site.