How to Configure SAML Authentication for e-Sales Manager

Item

Details

Pre-check

  • Pre-configuration is required in e-Sales Manager.
  • the "User ID (email address)" in e-Sales Manager matching the email address in TrustLogin is required.
  • For the latest configuration steps, please refer to the manual provided by e-Sales Manager.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
Request SP to configure
Provisioning API-based Provisioning supported (Account management available in TrustLogin)
SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:

Notes

Regarding the environment query parameter included in the SP's ACS URL configured on the TrustLogin side, please check with e-Sales Manager support in advance and have it ready.

Table of Contents:

TrustLogin Admin Page Settings

e-Sales Manager Settings

TrustLogin User Settings

How to Log In via the Mobile App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
  2. On the "Register Company App" screen, search and select "e-Sales Manager (SAML)".
    02.png
  3. Under "Identity Provider Information", note down the values of "Identity Provider URL" and "Issuer / Entity ID", and download the certificate using the "Get Certificate" button.
    03.png
  4. Convert the file extension of the downloaded certificate to ".cer".
  5. Configure each field under "Service Provider Settings" as follows.

    Redirect URL after SP authentication success The unique portion of your e-Sales Manager environment URL ※1
    Entity ID The unique portion of your e-Sales Manager environment URL
    ACS URL for the Service ① The unique portion of your e-Sales Manager environment URL
    ② The environment query parameter ※2

    ※1 (Example) If your e-Sales Manager environment URL is https://esm.softbrain.com/xxxxxx12345/,
    enter [xxxxxx12345].
    ※2 The environment query parameter varies by customer, so please check with e-Sales Manager support.

    04.png

  6. Save by clicking the "Save" button.

e-Sales Manager Settings

  1. Log in with an administrator account and open "System Settings > SAML Settings".
    Configure each item as follows and save by clicking the "Save Settings" button.
    Note: Please note that once you save the settings, login via password will no longer be possible.

    Login method for SAML authentication Enable SAML authentication login by setting it to "Enable" separately for browser and mobile app
    Field linked with SAML authentication "User ID (email address)"
    Select "Found in the NameIdentifier element of the Subject statement"
    Issuer (Entity ID) The "Issuer / Entity ID" obtained from TrustLogin
    Identity Provider Certificate Upload the "Certificate" obtained from TrustLogin after converting it to a .cer file
    Identity Provider Login URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Logout URL https://portal.trustlogin.com/
    Note: Single logout is not currently supported
    05.png

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "e-Sales Manager (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "e-Sales Manager (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In via the Mobile App

  1. Open "Select Connection Destination" and configure your e-Sales Manager environment.
    06.PNG
  2. Tap "SAML Login" to log in via SAML SSO.
    07.png

How to Configure SAML Authentication for e-Sales Manager

Item

Details

Pre-check

  • Pre-configuration is required in e-Sales Manager.
  • the "User ID (email address)" in e-Sales Manager matching the email address in TrustLogin is required.
  • For the latest configuration steps, please refer to the manual provided by e-Sales Manager.
Name ID Email address
Custom attribute Note: For how to configure custom attributes, seehere
SP Configuration Configured by the Administrator
Request SP to configure
Provisioning API-based Provisioning supported (Account management available in TrustLogin)
SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available)
None (accounts created in each system)
Access Method SP-Initiated SSO
IdP-Initiated SSO
Device Compatibility PC - Browser
PC - Desktop App
iOS - Default Browser (Safari)
iOS - TrustLogin Mobile App In-App Browser
iOS - Native App
Android - Default Browser (Chrome)
Android - TrustLogin Mobile App In-App Browser
Android - Native App
SAML Authentication Scope Enabled for all users (SAML authentication only)
Other:

Notes

Regarding the environment query parameter included in the SP's ACS URL configured on the TrustLogin side, please check with e-Sales Manager support in advance and have it ready.

Table of Contents:

TrustLogin Admin Page Settings

e-Sales Manager Settings

TrustLogin User Settings

How to Log In via the Mobile App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png
  2. On the "Register Company App" screen, search and select "e-Sales Manager (SAML)".
    02.png
  3. Under "Identity Provider Information", note down the values of "Identity Provider URL" and "Issuer / Entity ID", and download the certificate using the "Get Certificate" button.
    03.png
  4. Convert the file extension of the downloaded certificate to ".cer".
  5. Configure each field under "Service Provider Settings" as follows.

    Redirect URL after SP authentication success The unique portion of your e-Sales Manager environment URL ※1
    Entity ID The unique portion of your e-Sales Manager environment URL
    ACS URL for the Service ① The unique portion of your e-Sales Manager environment URL
    ② The environment query parameter ※2

    ※1 (Example) If your e-Sales Manager environment URL is https://esm.softbrain.com/xxxxxx12345/,
    enter [xxxxxx12345].
    ※2 The environment query parameter varies by customer, so please check with e-Sales Manager support.

    04.png

  6. Save by clicking the "Save" button.

e-Sales Manager Settings

  1. Log in with an administrator account and open "System Settings > SAML Settings".
    Configure each item as follows and save by clicking the "Save Settings" button.
    Note: Please note that once you save the settings, login via password will no longer be possible.

    Login method for SAML authentication Enable SAML authentication login by setting it to "Enable" separately for browser and mobile app
    Field linked with SAML authentication "User ID (email address)"
    Select "Found in the NameIdentifier element of the Subject statement"
    Issuer (Entity ID) The "Issuer / Entity ID" obtained from TrustLogin
    Identity Provider Certificate Upload the "Certificate" obtained from TrustLogin after converting it to a .cer file
    Identity Provider Login URL The "Identity Provider URL" obtained from TrustLogin
    Identity Provider Logout URL https://portal.trustlogin.com/
    Note: Single logout is not currently supported
    05.png

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The SAML app must be configured by the Administrator in advance.

  1. On "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "e-Sales Manager (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it and click the "Save" button.

② When an Administrator Adds Members

  1. In the "Admin Page > App" menu, search for and click the "e-Sales Manager (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.

How to Log In via the Mobile App

  1. Open "Select Connection Destination" and configure your e-Sales Manager environment.
    06.PNG
  2. Tap "SAML Login" to log in via SAML SSO.
    07.png