How to Configure SAML JIT for Raksul Enterprise

Item

Details

Prior Confirmation

  • Advance configuration in Raksul Enterprise is required.
  • For the latest setup instructions, please refer to the manual provided by Raksul Enterprise.
Name ID Email address
Custom attribute Note: For instructions on how to configure custom attributes, seehere
SP-side Configuration Configured by the administrator
Request configuration from the SP
Provisioning SupportsAPI-based provisioning(account management possible in TrustLogin)
Supports SAML JITprovisioning(new registration only)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Verification Status PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:
Enabled only for users with an email address in the registered "Target Domain" (SAML authentication and password authentication can be used together)

Notes

SAML JIT supports new account registration only. Names are not synchronized.

Table of Contents:

TrustLogin Admin Page Configuration

Raksul Enterprise Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration

Login Method

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. On the "Register Corporate App" screen, search for and select "Raksul Enterprise (SAML)".
    02.png
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, move on to the configuration on the Raksul Enterprise side.
Do not click the "Register" button yet — open Raksul Enterprise in a separate window.

Raksul Enterprise Configuration

  1. Log in with an administrator account and open "Company Settings > Change Settings".
    04.png
  2. Open "Edit" for "SAML SSO Authentication".
    05.png
  3. Check "Enable" under "Enable SAML SSO" and configure each item.

    Target Domain Only users with an email address in the domain shown under Target Domain can use SAML SSO.
    To add or change a domain, please contact your Raksul representative.
    Login Method We recommend selecting "Also allow login with password" here.
    If you want to restrict the login method to SAML SSO only, make this change after you have completed testing SAML SSO and notifying your users.
    IdP Metadata Configuration Upload the metadata obtained from TrustLogin via "Choose File"
    Information to Register with the IdP Click "Download Metadata File" to download the metadata
    06-1.png

  4. Next, configure the following items, and finally save by clicking the "Save" button.

    Login Session Duration Configure according to your operational needs
    Basic Company Information The configured company information is set as account information when new users register their accounts.
    Group Settings Select the group to which users belong when they log in via SAML SSO
    Notification Recipient Settings (Optional) Set the notification recipients to receive an email when a new user registers


    06-2.png


Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Upload the metadata obtained from Raksul Enterprise to the metadata field under "Service Provider Settings".
    07.png
  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When Users Add the App from My Page

Note: The administrator must have already configured the SAML app in advance.

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Raksul Enterprise (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Raksul Enterprise (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.


Login Method

① Logging In with "Raksul Enterprise (SAML)"

When you run "Raksul Enterprise (SAML)" from TrustLogin's My Page or the browser extension, you will be redirected to Raksul's SAML SSO login screen.
Enter your email address and click the "Login" button to complete the login.
08.png

② Using the Auxiliary App

We also provide an auxiliary app that lets you skip entering your email address and clicking the login button described in the login process in ①. Register the app "[SAML Auxiliary] Raksul Enterprise" to use it.
Note: The auxiliary app is intended for use with a PC browser. On mobile devices, you may need to re-authenticate with TrustLogin or manually enter your email address.


Add the app using the same procedure as a regular app registration, either as an administrator or by the user themselves.
10.png

New User Account Registration

When a new user logs in via SAML SSO for the first time, the account registration screen is displayed.
Enter your "Name" and "Furigana," then proceed by clicking the "Proceed to Confirmation Screen" button. After confirming on the next screen, account registration and login will be completed.

(The company information at the bottom is automatically filled in based on the settings configured on the Raksul Enterprise SAML configuration screen)
09.png

How to Configure SAML JIT for Raksul Enterprise

Item

Details

Prior Confirmation

  • Advance configuration in Raksul Enterprise is required.
  • For the latest setup instructions, please refer to the manual provided by Raksul Enterprise.
Name ID Email address
Custom attribute Note: For instructions on how to configure custom attributes, seehere
SP-side Configuration Configured by the administrator
Request configuration from the SP
Provisioning SupportsAPI-based provisioning(account management possible in TrustLogin)
Supports SAML JITprovisioning(new registration only)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Verification Status PC - Browser
PC - Desktop App
iOS - Standard Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Standard Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:
Enabled only for users with an email address in the registered "Target Domain" (SAML authentication and password authentication can be used together)

Notes

SAML JIT supports new account registration only. Names are not synchronized.

Table of Contents:

TrustLogin Admin Page Configuration

Raksul Enterprise Configuration

TrustLogin Admin Page Configuration (Continued)

TrustLogin User Configuration

Login Method

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png
  2. On the "Register Corporate App" screen, search for and select "Raksul Enterprise (SAML)".
    02.png
  3. Download the metadata from the "Download Metadata" button under "Identity Provider Information".
    03.png

Now, move on to the configuration on the Raksul Enterprise side.
Do not click the "Register" button yet — open Raksul Enterprise in a separate window.

Raksul Enterprise Configuration

  1. Log in with an administrator account and open "Company Settings > Change Settings".
    04.png
  2. Open "Edit" for "SAML SSO Authentication".
    05.png
  3. Check "Enable" under "Enable SAML SSO" and configure each item.

    Target Domain Only users with an email address in the domain shown under Target Domain can use SAML SSO.
    To add or change a domain, please contact your Raksul representative.
    Login Method We recommend selecting "Also allow login with password" here.
    If you want to restrict the login method to SAML SSO only, make this change after you have completed testing SAML SSO and notifying your users.
    IdP Metadata Configuration Upload the metadata obtained from TrustLogin via "Choose File"
    Information to Register with the IdP Click "Download Metadata File" to download the metadata
    06-1.png

  4. Next, configure the following items, and finally save by clicking the "Save" button.

    Login Session Duration Configure according to your operational needs
    Basic Company Information The configured company information is set as account information when new users register their accounts.
    Group Settings Select the group to which users belong when they log in via SAML SSO
    Notification Recipient Settings (Optional) Set the notification recipients to receive an email when a new user registers


    06-2.png


Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Configuration (Continued)

  1. Upload the metadata obtained from Raksul Enterprise to the metadata field under "Service Provider Settings".
    07.png
  2. Save by clicking the "Register" button.

TrustLogin User Configuration

① When Users Add the App from My Page

Note: The administrator must have already configured the SAML app in advance.

  1. On "My Page," click the "Add App" button.
  2. On the "Register App" screen, select "Raksul Enterprise (SAML)" and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Raksul Enterprise (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.


Login Method

① Logging In with "Raksul Enterprise (SAML)"

When you run "Raksul Enterprise (SAML)" from TrustLogin's My Page or the browser extension, you will be redirected to Raksul's SAML SSO login screen.
Enter your email address and click the "Login" button to complete the login.
08.png

② Using the Auxiliary App

We also provide an auxiliary app that lets you skip entering your email address and clicking the login button described in the login process in ①. Register the app "[SAML Auxiliary] Raksul Enterprise" to use it.
Note: The auxiliary app is intended for use with a PC browser. On mobile devices, you may need to re-authenticate with TrustLogin or manually enter your email address.


Add the app using the same procedure as a regular app registration, either as an administrator or by the user themselves.
10.png

New User Account Registration

When a new user logs in via SAML SSO for the first time, the account registration screen is displayed.
Enter your "Name" and "Furigana," then proceed by clicking the "Proceed to Confirmation Screen" button. After confirming on the next screen, account registration and login will be completed.

(The company information at the bottom is automatically filled in based on the settings configured on the Raksul Enterprise SAML configuration screen)
09.png