How to Configure SAML Authentication for ExchangeUSE ZERO

Item

Details

Pre-check

  • Pre-configuration is required in ExchangeUSE ZERO.
  • For the latest configuration steps, please refer to the manual provided by ExchangeUSE ZERO.
Name ID   Email address
Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
  Request SP to configure
Provisioning   API-based Provisioning supported (Account management available in TrustLogin)
  SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

None

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings

ExchangeUSE ZERO Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Log In

 

Preparation

Add a Custom Attribute to User Information

Add the ExchangeUSE ZERO "Login ID" information to the TrustLogin member information as a custom attribute.

[ExchangeUSE ZERO User Information Screen]
001.png

[TrustLogin Custom Attribute Configuration Example]
002.png

Please refer to the following pages for instructions on how to configure custom attributes. The attribute name for the custom attribute can be anything you like.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
     
  2. On the "Register Company App" screen, search and select "ExchangeUSE ZERO (SAML)".
    02.png
     
  3. Under "Identity Provider Information", note down the value of "Identity Provider URL", and download the certificate using the "Get Certificate" button.
    03.png
     
  4. Change the file extension of the downloaded certificate to ".crt" to convert it to CRT format.

 

At this point, move on to configuring ExchangeUSE ZERO.
Do not click the "Register" button yet — open ExchangeUSE ZERO in a separate window.

 

ExchangeUSE ZERO Settings

  1. Log in with an administrator account and open "System Settings > System Preferences > Single Sign-On Settings".
    04.png
     
  2. Configure each item as follows, and save by clicking the "Save" button.

    IdP Endpoint URL The "Identity Provider URL" obtained from TrustLogin
    IdP Token Signing Certificate Upload the "Certificate" obtained from TrustLogin (converted to CRT format) using the "Import" button
    Identifier Set any string of your choice
    ExchangeUSE Response Receiving URL Obtain the value using the "Copy" button


    05.png

 

Now, return to the TrustLogin Admin Page.

 

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.

    Entity ID The string you set for "Identifier" in ExchangeUSE ZERO
    Value for Name ID Select the custom attribute configured in Preparation
    ACS URL to Service The "ExchangeUSE Response Receiving URL" obtained from ExchangeUSE ZERO
    06.png
  2. Save by clicking the "Register" button.

 

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "ExchangeUSE ZERO (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "ExchangeUSE ZERO (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.


     

How to Log In

① When Logging In via SP-Initiated SSO

You can log in via SP-initiated SSO by accessing the "SAML Login URL (PC Site)" URL on the ExchangeUSE ZERO SAML authentication settings screen.
07.png

 

② When Using the Mobile Site

Logging in to "ExchangeUSE ZERO (SAML)" via the TrustLogin mobile app will display the PC site, so if you want to use the mobile site, you will need to create a separate bookmark app.

Obtain the "SAML Login URL (Mobile Site)" URL from the ExchangeUSE ZERO SAML authentication settings screen, and create and use a bookmark app with it.

Please refer to the manual below for how to use the bookmark app.
How to Configure the Bookmark Template

Note: Accessing the mobile site via the bookmark app may require you to re-authenticate with TrustLogin. After authentication, you will be logged in to the mobile site.

08.png

 

 

How to Configure SAML Authentication for ExchangeUSE ZERO

Item

Details

Pre-check

  • Pre-configuration is required in ExchangeUSE ZERO.
  • For the latest configuration steps, please refer to the manual provided by ExchangeUSE ZERO.
Name ID   Email address
Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
  Request SP to configure
Provisioning   API-based Provisioning supported (Account management available in TrustLogin)
  SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other: Enabled for all users (both SAML authentication and password authentication available)

Notes

None

 

Table of Contents:

Preparation

TrustLogin Admin Page Settings

ExchangeUSE ZERO Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

How to Log In

 

Preparation

Add a Custom Attribute to User Information

Add the ExchangeUSE ZERO "Login ID" information to the TrustLogin member information as a custom attribute.

[ExchangeUSE ZERO User Information Screen]
001.png

[TrustLogin Custom Attribute Configuration Example]
002.png

Please refer to the following pages for instructions on how to configure custom attributes. The attribute name for the custom attribute can be anything you like.

Custom Attribute Setup (Individual Registration)

Custom Attribute Setup (Bulk Registration)

 

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
     
  2. On the "Register Company App" screen, search and select "ExchangeUSE ZERO (SAML)".
    02.png
     
  3. Under "Identity Provider Information", note down the value of "Identity Provider URL", and download the certificate using the "Get Certificate" button.
    03.png
     
  4. Change the file extension of the downloaded certificate to ".crt" to convert it to CRT format.

 

At this point, move on to configuring ExchangeUSE ZERO.
Do not click the "Register" button yet — open ExchangeUSE ZERO in a separate window.

 

ExchangeUSE ZERO Settings

  1. Log in with an administrator account and open "System Settings > System Preferences > Single Sign-On Settings".
    04.png
     
  2. Configure each item as follows, and save by clicking the "Save" button.

    IdP Endpoint URL The "Identity Provider URL" obtained from TrustLogin
    IdP Token Signing Certificate Upload the "Certificate" obtained from TrustLogin (converted to CRT format) using the "Import" button
    Identifier Set any string of your choice
    ExchangeUSE Response Receiving URL Obtain the value using the "Copy" button


    05.png

 

Now, return to the TrustLogin Admin Page.

 

TrustLogin Admin Page Settings (Continued)

  1. Configure the "Service Provider Settings" as follows.

    Entity ID The string you set for "Identifier" in ExchangeUSE ZERO
    Value for Name ID Select the custom attribute configured in Preparation
    ACS URL to Service The "ExchangeUSE Response Receiving URL" obtained from ExchangeUSE ZERO
    06.png
  2. Save by clicking the "Register" button.

 

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "ExchangeUSE ZERO (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "ExchangeUSE ZERO (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.


     

How to Log In

① When Logging In via SP-Initiated SSO

You can log in via SP-initiated SSO by accessing the "SAML Login URL (PC Site)" URL on the ExchangeUSE ZERO SAML authentication settings screen.
07.png

 

② When Using the Mobile Site

Logging in to "ExchangeUSE ZERO (SAML)" via the TrustLogin mobile app will display the PC site, so if you want to use the mobile site, you will need to create a separate bookmark app.

Obtain the "SAML Login URL (Mobile Site)" URL from the ExchangeUSE ZERO SAML authentication settings screen, and create and use a bookmark app with it.

Please refer to the manual below for how to use the bookmark app.
How to Configure the Bookmark Template

Note: Accessing the mobile site via the bookmark app may require you to re-authenticate with TrustLogin. After authentication, you will be logged in to the mobile site.

08.png