Item |
Details |
|
|---|---|---|
Pre-check |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For instructions on how to configure a custom attribute, click here | ||
| SP-side Configuration | 〇 | Configured by the administrator |
| Request configuration from the SP | ||
| Provisioning | API-based Provisioning supported (account management available in TrustLogin) | |
| SAML JITProvisioning supported (account management available in TrustLogin; user deletion not supported) | ||
| 〇 | None (accounts created in each system) | |
| Access Method | 〇 | SP-Initiated SSO |
| 〇 | IdP-Initiated SSO | |
| Verified Operation by Device | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Standard Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App In-App Browser | |
| ー | iOS - Native App | |
| 〇 | Android - Standard Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App In-App Browser | |
| ー | Android - Native App | |
| SAML Authentication Scope | ー | Enabled for all users (SAML authentication only) |
| 〇 |
Other: Enabled for all users (users can choose to use SAML authentication together with password authentication) |
|
Notes |
None in particular | |
|
Table of Contents: TrustLogin Admin Page Settings |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Company App" screen and select "Sasuke Works (SAML)".
- Note the values of "IdP URL" and "Issuer / Entity ID" under "Identity Provider Information", and download the certificate using the "Get Certificate" button.
Now, switch to configuring Sasuke Works.
Do not click the "Register" button yet — open Sasuke Works in a separate window.
Sasuke Works Settings
- Log in to Sasuke Works and click "Contract Details" from the gear icon in the upper right.
-
Click "Security Settings > Change Settings".
-
Configure the "External Authentication Integration" section as follows and click the "Register" button.
External Authentication Integration Enabled Existing Login Feature We recommend enabling this when configuring SSO
Note: Setting this to "Disabled" will prevent logging in with an ID and password from the login screen, making SSO the only login method. If you want to disable it, we recommend doing so only after configuring SSO and confirming that it works correctly.
External Service TrustLogin ACS (Consumer) URL Copy and keep a note of this Audience (EntityID) Copy and keep a note of this IdP Entity ID The "Issuer / Entity ID" noted from TrustLogin IdP SSO URL The "IdP URL" noted from TrustLogin X.509 Certificate Paste the contents of the certificate downloaded from TrustLogin
Now return to the TrustLogin Admin Page.
TrustLogin Admin Page Settings (Continued)
-
Configure "Service Provider Settings" as follows.
Entity ID The "Audience (EntityID)" noted from Sasuke Works ACS URL to Service The "ACS (Consumer) URL" noted from Sasuke Works
- Save the settings by clicking the "Register" button.
TrustLogin User Settings
① When a user adds the app from My Page
Note: The SAML app must be configured by an administrator in advance.
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Sasuke Works (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it and click the "Register" button.
② When an administrator adds members
- Search for and click the "Sasuke Works (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
Login Method
① Logging in via SP-Initiated SSO
- Open the Sasuke Works login URL and click the "TrustLogin" button.
- You will be redirected to the TrustLogin login screen, where you can log in via SSO.