How to Configure SAML Authentication for Netskope (Admin Page)

Item

Details

Prerequisites

  • Prior configuration in Netskope is required.

  • You must create an account in Netskope using the same email address as your TrustLogin account.
  • For the latest configuration steps, please refer to the manual provided by Netskope.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible in GMO TrustLogin)

SAML JIT provisioning supported (account management possible in GMO TrustLogin; user deletion not supported)

None (accounts created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop App

iOS - Standard browser (Safari)

×

iOS - TrustLogin mobile app in-app browser

iOS - Native app

Android - Standard browser (Chrome)

×

Android - TrustLogin mobile app in-app browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Netskope (Admin Page) (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate from "Get Certificate".
    03.png

Now, switch to configuring the Netskope side.
Do not click the "Register" button yet — open Netskope in a separate window.

Netskope Settings

  1. Log in with administrator privileges, and open "Settings" from the left-hand menu.
    04.png

  2. Open "Administration > SSO".
    05.png

  3. Under "Netskope Settings", note down the values of "Assertion Consumer Service URL" and "Service Provider Entity Id".
    06.png

  4. Click "EDIT SETTINGS" under "SSO/SLO Settings".
    07.png

  5. Configure each item on the "Settings" screen as follows, and click "SUBMIT".
    Enable SSO Check the box
    Sign SSO Authentication Request Check the box
    IDP URL The "Identity Provider URL" you noted from TrustLogin
    IDP ENTITY ID The "Issuer / Entity ID" you noted from TrustLogin
    IDP CERTIFICATE Open the "Certificate" you downloaded from TrustLogin and paste its contents

    08.png
    09.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure each item under "Service Provider Settings" as follows.
    Entity ID The "Service Provider Entity Id" you noted from Netskope
    ACS URL for the Service The "Assertion Consumer Service URL" you noted from Netskope

    10.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Netskope (Admin Page) (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and check whether login succeeds.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Netskope (Admin Page) (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for Netskope (Admin Page)

Item

Details

Prerequisites

  • Prior configuration in Netskope is required.

  • You must create an account in Netskope using the same email address as your TrustLogin account.
  • For the latest configuration steps, please refer to the manual provided by Netskope.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-side configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based provisioning supported (account management possible in GMO TrustLogin)

SAML JIT provisioning supported (account management possible in GMO TrustLogin; user deletion not supported)

None (accounts created in each system)

Access method

SP-Initiated SSO

IdP-Initiated SSO

Verified operation by device

PC - Browser

PC - Desktop App

iOS - Standard browser (Safari)

×

iOS - TrustLogin mobile app in-app browser

iOS - Native app

Android - Standard browser (Chrome)

×

Android - TrustLogin mobile app in-app browser

Android - Native app

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search and select "Netskope (Admin Page) (SAML)".
    02.png

  3. Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate from "Get Certificate".
    03.png

Now, switch to configuring the Netskope side.
Do not click the "Register" button yet — open Netskope in a separate window.

Netskope Settings

  1. Log in with administrator privileges, and open "Settings" from the left-hand menu.
    04.png

  2. Open "Administration > SSO".
    05.png

  3. Under "Netskope Settings", note down the values of "Assertion Consumer Service URL" and "Service Provider Entity Id".
    06.png

  4. Click "EDIT SETTINGS" under "SSO/SLO Settings".
    07.png

  5. Configure each item on the "Settings" screen as follows, and click "SUBMIT".
    Enable SSO Check the box
    Sign SSO Authentication Request Check the box
    IDP URL The "Identity Provider URL" you noted from TrustLogin
    IDP ENTITY ID The "Issuer / Entity ID" you noted from TrustLogin
    IDP CERTIFICATE Open the "Certificate" you downloaded from TrustLogin and paste its contents

    08.png
    09.png

Return to the TrustLogin Admin Page again.

TrustLogin Admin Page Settings (Continued)

  1. Configure each item under "Service Provider Settings" as follows.
    Entity ID The "Service Provider Entity Id" you noted from Netskope
    ACS URL for the Service The "Assertion Consumer Service URL" you noted from Netskope

    10.png

  2. Click the "Register" button to save.

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "Netskope (Admin Page) (SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and check whether login succeeds.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "Netskope (Admin Page) (SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.