How to Configure SAML Authentication for GitHub Enterprise Managed Users

Item

Details

Pre-check

  • Pre-configuration is required in GitHub Enterprise Managed Users.
  • For the latest configuration steps, please refer to the manual provided by GitHub Enterprise Managed Users.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
Request SP to configure
Provisioning API-based Provisioning supported (Account management available in TrustLogin)
SAML JITProvisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Users (SAML authentication only); Administrators (password authentication only)

Notes

  • In GitHub Enterprise Managed Users, both user management via ID provisioning and SAML authentication configuration are required. For details, seehere.
  • For instructions on setting up the GitHub Enterprise Managed Users environment, please follow the manual provided by GitHub.
  • This manual explains the steps for configuring SAML authentication in a GitHub Enterprise Managed Users environment.
  • Reference:Getting started with Enterprise Managed Users

Table of Contents:

TrustLogin Admin Page Settings

GitHub Enterprise Managed Users Settings

GitHub Enterprise Managed Users Provisioning Settings

TrustLogin User Settings

SP-Initiated Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
  2. On the "Register Company App" screen, search and select "GitHub Enterprise Managed Users (SAML)".
    2026-03-04_17-44-24.png
  3. Under "Identity Provider Information", note down the values of "Identity Provider URL" and "Issuer / Entity ID", and download the certificate using the "Get Certificate" button.03.png
  4. In "Service Provider Settings", enter your GitHub "Enterprise Name" into the blank fields for "Entity ID" and "Service ACS URL".
    2026-03-05_10-38-25.png
  5. Save by clicking the "Save" button.
  6. Add the user who is currently performing the SAML configuration to the "GitHub Enterprise Managed Users (SAML)" app. Please add the user using "Add Member".

Next, switch to configuring the GitHub Enterprise Managed Users side.

GitHub Enterprise Managed Users Settings

  1. From "Overview", click "Enable single sign-on".
    2026-03-03_17-50-20.png
  2. Click "Add SAML configuration".
    2026-03-06_13-30-50.png
  3. Configure "SAML single sign-on" as follows. After configuring, click "Test SAML configuration" to run a connection test.

    Sign on URL The "Identity Provider URL" noted down from TrustLogin
    Issuer The "Issuer / Entity ID" noted down from TrustLogin
    Public certificate Paste the contents of the "Certificate" noted down from TrustLogin
    2026-03-03_17-54-17.png
  4. If "Passed: Successfully authenticated your SAML SSO identity." is displayed, the connection test was successful.
    Save the configuration by clicking "Save SAML settings".

    2026-03-03_17-54-40.png
  5. Note down the recovery codes under "Single sign-on recovery codes", then click "Enable SAML authentication" to activate SSO.

    2026-03-03_17-55-28.png

GitHub Enterprise Managed Users Provisioning Settings

  1. Please configure provisioning by following "Initial Setup Procedure for GitHub ID Provisioning".

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "GitHub Enterprise Managed Users (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "GitHub Enterprise Managed Users (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

SP-Initiated Login Method

  1. If you want to log in via SP-initiated login, access "https://github.com/enterprises/{Enterprise Name}/sso".
  2. Clicking "Continue" starts the SSO login.

    スクリーンショット 2026-03-05 115515.png

How to Configure SAML Authentication for GitHub Enterprise Managed Users

Item

Details

Pre-check

  • Pre-configuration is required in GitHub Enterprise Managed Users.
  • For the latest configuration steps, please refer to the manual provided by GitHub Enterprise Managed Users.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
Request SP to configure
Provisioning API-based Provisioning supported (Account management available in TrustLogin)
SAML JITProvisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Users (SAML authentication only); Administrators (password authentication only)

Notes

  • In GitHub Enterprise Managed Users, both user management via ID provisioning and SAML authentication configuration are required. For details, seehere.
  • For instructions on setting up the GitHub Enterprise Managed Users environment, please follow the manual provided by GitHub.
  • This manual explains the steps for configuring SAML authentication in a GitHub Enterprise Managed Users environment.
  • Reference:Getting started with Enterprise Managed Users

Table of Contents:

TrustLogin Admin Page Settings

GitHub Enterprise Managed Users Settings

GitHub Enterprise Managed Users Provisioning Settings

TrustLogin User Settings

SP-Initiated Login Method

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
  2. On the "Register Company App" screen, search and select "GitHub Enterprise Managed Users (SAML)".
    2026-03-04_17-44-24.png
  3. Under "Identity Provider Information", note down the values of "Identity Provider URL" and "Issuer / Entity ID", and download the certificate using the "Get Certificate" button.03.png
  4. In "Service Provider Settings", enter your GitHub "Enterprise Name" into the blank fields for "Entity ID" and "Service ACS URL".
    2026-03-05_10-38-25.png
  5. Save by clicking the "Save" button.
  6. Add the user who is currently performing the SAML configuration to the "GitHub Enterprise Managed Users (SAML)" app. Please add the user using "Add Member".

Next, switch to configuring the GitHub Enterprise Managed Users side.

GitHub Enterprise Managed Users Settings

  1. From "Overview", click "Enable single sign-on".
    2026-03-03_17-50-20.png
  2. Click "Add SAML configuration".
    2026-03-06_13-30-50.png
  3. Configure "SAML single sign-on" as follows. After configuring, click "Test SAML configuration" to run a connection test.

    Sign on URL The "Identity Provider URL" noted down from TrustLogin
    Issuer The "Issuer / Entity ID" noted down from TrustLogin
    Public certificate Paste the contents of the "Certificate" noted down from TrustLogin
    2026-03-03_17-54-17.png
  4. If "Passed: Successfully authenticated your SAML SSO identity." is displayed, the connection test was successful.
    Save the configuration by clicking "Save SAML settings".

    2026-03-03_17-54-40.png
  5. Note down the recovery codes under "Single sign-on recovery codes", then click "Enable SAML authentication" to activate SSO.

    2026-03-03_17-55-28.png

GitHub Enterprise Managed Users Provisioning Settings

  1. Please configure provisioning by following "Initial Setup Procedure for GitHub ID Provisioning".

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "GitHub Enterprise Managed Users (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "GitHub Enterprise Managed Users (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

SP-Initiated Login Method

  1. If you want to log in via SP-initiated login, access "https://github.com/enterprises/{Enterprise Name}/sso".
  2. Clicking "Continue" starts the SSO login.

    スクリーンショット 2026-03-05 115515.png