How to Configure SAML Authentication for Tableau Cloud

Item

Details

Pre-check

  • Prior configuration is required in Tableau Cloud (formerly Tableau Online).

  • You must create an account in Tableau Cloud using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Tableau Cloud.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users for whom SAML authentication has been applied on the SP side (SAML authentication only)

Notes

None in particular

Table of Contents:

TrustLogin Admin Page Settings

Tableau Cloud Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Tableau Cloud Settings (Switching User Authentication Method)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Corporate App Registration" screen, search for and select "Tableau Cloud (SAML)".
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png


At this point, switch to the configuration on the Tableau Cloud side.
Do not click the "Register" button yet; open Tableau Cloud in a separate window.


Tableau Cloud Settings

  1. Log in with a site administrator account, open "Settings > Authentication" from the menu, and click "New Configuration" under "Authentication Type".
    04.png

  2. From "Select Type" under "Authentication", select "SAML".
    05.png

  3. Configure each item as follows, and click "Save and Continue".
    Name Any name (e.g., TrustLogin)
    IdP Metadata File

    Drag and drop the "metadata" obtained from TrustLogin, or upload it using "Choose File"
    (Once the metadata loads successfully, the information will be reflected in the "IdP Entity ID" and "IdP SSO Service URL" fields below.)

    Email Address Enter "NameID"
    Note: Leave any items not listed here at their default settings.

    06.png

  4. Copy and note down the values of "Tableau Cloud Entity ID" and "Tableau Cloud ACS URL".
    07.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Tableau Cloud Entity ID" obtained from Tableau Cloud
    ACS URL for the Service The "Tableau Cloud ACS URL" obtained from Tableau Cloud

    08.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The administrator must have already configured the SAML app beforehand.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Tableau Cloud (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Tableau Cloud (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Tableau Cloud Settings (Switching User Authentication Method)

  1. Open "Users" in Tableau Cloud, and for the user you want to switch to SAML authentication, select "Actions > … > Authentication".
    11.png

  2. Select the SAML authentication configuration you set up, and click "Update".
    Note: Changing the authentication method will forcibly log out any currently logged-in user. Also, if you change the authentication method for all site administrators, you will be unable to log in if there is a problem with the SAML configuration. Therefore, we recommend keeping at least one site administrator set to Tableau password authentication.
    09.png

How to Configure SAML Authentication for Tableau Cloud

Item

Details

Pre-check

  • Prior configuration is required in Tableau Cloud (formerly Tableau Online).

  • You must create an account in Tableau Cloud using the same email address as your TrustLogin account.

  • For the latest setup instructions, please refer to the manual provided by Tableau Cloud.

Name ID

Email address

Custom attribute Note: For instructions on configuring custom attributes, see here

SP-side Settings

Configured by the administrator

Request configuration from the SP

Provisioning

Supports provisioning via API (account management possible from TrustLogin)

Supports SAML JIT provisioning (account management possible from TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Device Compatibility

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

SAML Authentication Scope

Enabled for all users (SAML authentication only)

Other: Enabled only for users for whom SAML authentication has been applied on the SP side (SAML authentication only)

Notes

None in particular

Table of Contents:

TrustLogin Admin Page Settings

Tableau Cloud Settings

TrustLogin Admin Page Settings (Continued)

TrustLogin User Settings

Tableau Cloud Settings (Switching User Authentication Method)

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Corporate App Registration" screen, search for and select "Tableau Cloud (SAML)".
    02.png

  3. Download the metadata from "Download Metadata" under "Identity Provider Information".
    03.png


At this point, switch to the configuration on the Tableau Cloud side.
Do not click the "Register" button yet; open Tableau Cloud in a separate window.


Tableau Cloud Settings

  1. Log in with a site administrator account, open "Settings > Authentication" from the menu, and click "New Configuration" under "Authentication Type".
    04.png

  2. From "Select Type" under "Authentication", select "SAML".
    05.png

  3. Configure each item as follows, and click "Save and Continue".
    Name Any name (e.g., TrustLogin)
    IdP Metadata File

    Drag and drop the "metadata" obtained from TrustLogin, or upload it using "Choose File"
    (Once the metadata loads successfully, the information will be reflected in the "IdP Entity ID" and "IdP SSO Service URL" fields below.)

    Email Address Enter "NameID"
    Note: Leave any items not listed here at their default settings.

    06.png

  4. Copy and note down the values of "Tableau Cloud Entity ID" and "Tableau Cloud ACS URL".
    07.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure "Service Provider Settings" as follows.
    Entity ID The "Tableau Cloud Entity ID" obtained from Tableau Cloud
    ACS URL for the Service The "Tableau Cloud ACS URL" obtained from Tableau Cloud

    08.png

  2. Save by clicking the "Register" button.

TrustLogin User Settings

① When a User Adds the App from My Page

Note: The administrator must have already configured the SAML app beforehand.

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "Tableau Cloud (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter a new one, then click the "Register" button.

② When an Administrator Adds a Member

  1. In the "Admin Page > Apps" menu, search for and click the "Tableau Cloud (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

Tableau Cloud Settings (Switching User Authentication Method)

  1. Open "Users" in Tableau Cloud, and for the user you want to switch to SAML authentication, select "Actions > … > Authentication".
    11.png

  2. Select the SAML authentication configuration you set up, and click "Update".
    Note: Changing the authentication method will forcibly log out any currently logged-in user. Also, if you change the authentication method for all site administrators, you will be unable to log in if there is a problem with the SAML configuration. Therefore, we recommend keeping at least one site administrator set to Tableau password authentication.
    09.png