Item |
Details |
|
|---|---|---|
Pre-check |
|
|
| Name ID | 〇 | Email address |
| Custom attribute Note: For how to configure custom attributes, seehere | ||
| SP Configuration | 〇 | Configured by the Administrator |
| Request SP to configure | ||
| Provisioning | API-based Provisioning supported (Account management available in TrustLogin) | |
| SAML JIT Provisioning supported (Account management available in TrustLogin; user deletion not available) | ||
| 〇 | None (accounts created in each system) | |
| Access Method | 〇 | SP-Initiated SSO |
| ー | IdP-Initiated SSO | |
| Device Compatibility | 〇 | PC - Browser |
| ー | PC - Desktop App | |
| 〇 | iOS - Default Browser (Safari) | |
| 〇 | iOS - TrustLogin Mobile App In-App Browser | |
| ー | iOS - Native App | |
| 〇 | Android - Default Browser (Chrome) | |
| 〇 | Android - TrustLogin Mobile App In-App Browser | |
| ー | Android - Native App | |
| SAML Authentication Scope | 〇 | Enabled for all users (SAML authentication only) |
| ー | Other | |
Notes |
None | |
|
Table of Contents: |
TrustLogin Admin Page Settings
-
Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Company App" screen, search and select "Tenbin AI Biz by GMO (SAML)".
- Under "Identity Provider Information", note down the values of "Identity Provider URL" and "Issuer / Entity ID", and download the certificate using the "Get Certificate" button.
- Convert the file extension of the downloaded certificate to ".cer".
- Save by clicking the "Save" button.
- In the "Tenbin AI Biz by GMO (SAML)" app, add and assign the currently logged-in user using "Add Member". Note: This will be used later for SSO testing.
Tenbin AI Biz Settings
- Log in to Tenbin AI Biz with a user who has administrator privileges, and click "Admin Menu".
- Open "Authentication Settings" and click "Organization SSO Settings > Not Configured tab > Show SSO Settings".
-
Configure "② IdP Information" as follows, and click "Test Login and Activate".
IdP Entity ID (Issuer) The "Issuer / Entity ID" noted down from TrustLogin SSO URL (Login URL) The "Identity Provider URL" noted down from TrustLogin Public Certificate (X.509) The "Certificate" noted down from TrustLogin, Note: with the extension converted to ".cer" -
Enter the email address of the user added to the app in "TrustLogin Admin Page Settings > 6.", and click "Run Test".
- When the test login succeeds, the following screen will be displayed. Clicking "Enable SSO" will switch all users to logging in via SSO.
Note: If you want to enable SSO only after notifying your organization internally about the switch to SSO login, click "Close". Your SSO settings will be retained, and you can resume from "Test Login and Activate" later.
TrustLogin User Settings
① When a User Adds the App from My Page
Note: The SAML app must be configured by the Administrator in advance.
- On "My Page", click the "Add App" button.
- On the "Register App" screen, select "Tenbin AI Biz by GMO (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it and click the "Save" button.
② When an Administrator Adds Members
- In the "Admin Page > App" menu, search for and click the "Tenbin AI Biz by GMO (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Save" button to add them.
How to Log In
① Logging in via "Tenbin AI Biz by GMO (SAML)"
When you run "Tenbin AI Biz by GMO (SAML)" from TrustLogin's My Page or the browser extension, you will be redirected to the Tenbin AI Biz login screen. Enter your email address, then click the "Next" button to complete SSO login.
② When Using the Form-Based Authentication App for "Tenbin AI Biz by GMO"
By registering the form-based authentication app for "Tenbin AI Biz by GMO" and clicking the app, you can skip entering your email address and clicking the "Next" button described in the login steps in ①.
Please add the app yourself, either as the administrator or as the user, following the same steps as a regular app registration.
Note: The form-based authentication app is intended for use on PC browsers. On mobile devices, you may be required to re-authenticate with TrustLogin or manually enter your email address.