How to Configure SAML Authentication for HRMOS Attendance by IEYASU

Item

Details

Prerequisites

  • Prior setup in HRMOS Attendance is required.

  • You must create an account in HRMOS Attendance using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by HRMOS Attendance.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports API-based provisioning (accounts can be managed via GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed via GMO TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Corporate App Registration" screen and select "HRMOS Attendance by IEYASU (SAML)".
    HRMOS_02.jpg

  3. Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate from "Get Certificate."HRMOS_03.jpg
  4. Fill in the three blank fields under "Service Provider Settings" — "Login URL," "Entity ID," and "ACS URL for the Service" — by extracting the company-specific string portion of your HRMOS Attendance URL and pasting it in. (Example) https://ieyasu.co/xxxx HRMOS_08.jpg
  5. Click the "Register" button to save.

Now let's move on to the configuration in HRMOS Attendance. Please open HRMOS Attendance in a separate window.

HRMOS Attendance Configuration

  1. Log in with an administrator account, open "System Administration > System Settings," and click Edit.HRMOS_004.jpg
  2. In "SAML Authentication Settings," register the information you noted in step 3 of "TrustLogin Admin Page Configuration" above, as follows, then click "Register."
    SAML Authentication Configuration Name Any name (in this example, "TrustLogin")
    Login Settings

    Check "Log in using SAML authentication account"

    SSO URL The "IdP URL" you noted from TrustLogin
    Entity ID The "Issuer/Entity ID" you noted from TrustLogin
    Certificate

    The certificate file downloaded from TrustLogin (Browse)

    HRMOS Attendance Login

    Check this if you want to disable the login feature for "HRMOS Attendance by IEYASU."

    Note: If you check this, when general employees attempt to log in to HRMOS Attendance by IEYASU with an ID and password, an error message "Login with account ID and password is not allowed" will be displayed.


       HRMOS_05.jpg
  3. Click "Register."

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "App Registration" screen, select "HRMOS Attendance by IEYASU (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or via the "browser extension" to confirm that login is successful.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "HRMOS Attendance by IEYASU (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for HRMOS Attendance by IEYASU

Item

Details

Prerequisites

  • Prior setup in HRMOS Attendance is required.

  • You must create an account in HRMOS Attendance using the same email address as your TrustLogin account.

  • For the latest configuration steps, please refer to the manual provided by HRMOS Attendance.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, see here

SP-Side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

Supports API-based provisioning (accounts can be managed via GMO TrustLogin)

Supports SAML JIT provisioning (accounts can be managed via GMO TrustLogin; user deletion not supported)

None (accounts are created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation Status by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Configuration

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. Search on the "Corporate App Registration" screen and select "HRMOS Attendance by IEYASU (SAML)".
    HRMOS_02.jpg

  3. Note down the "IdP URL" and "Issuer/Entity ID" under "Identity Provider Information," and download the certificate from "Get Certificate."HRMOS_03.jpg
  4. Fill in the three blank fields under "Service Provider Settings" — "Login URL," "Entity ID," and "ACS URL for the Service" — by extracting the company-specific string portion of your HRMOS Attendance URL and pasting it in. (Example) https://ieyasu.co/xxxx HRMOS_08.jpg
  5. Click the "Register" button to save.

Now let's move on to the configuration in HRMOS Attendance. Please open HRMOS Attendance in a separate window.

HRMOS Attendance Configuration

  1. Log in with an administrator account, open "System Administration > System Settings," and click Edit.HRMOS_004.jpg
  2. In "SAML Authentication Settings," register the information you noted in step 3 of "TrustLogin Admin Page Configuration" above, as follows, then click "Register."
    SAML Authentication Configuration Name Any name (in this example, "TrustLogin")
    Login Settings

    Check "Log in using SAML authentication account"

    SSO URL The "IdP URL" you noted from TrustLogin
    Entity ID The "Issuer/Entity ID" you noted from TrustLogin
    Certificate

    The certificate file downloaded from TrustLogin (Browse)

    HRMOS Attendance Login

    Check this if you want to disable the login feature for "HRMOS Attendance by IEYASU."

    Note: If you check this, when general employees attempt to log in to HRMOS Attendance by IEYASU with an ID and password, an error message "Login with account ID and password is not allowed" will be displayed.


       HRMOS_05.jpg
  3. Click "Register."

TrustLogin User Configuration

① When a User Adds the App from My Page

  1. Click the "Add App" button on "My Page."
  2. On the "App Registration" screen, select "HRMOS Attendance by IEYASU (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name," enter it, then click the "Register" button.
  4. Click the app on "My Page" or via the "browser extension" to confirm that login is successful.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "HRMOS Attendance by IEYASU (SAML)" app.
  2. Click "Add Member," select the users to add from the member list, and click the "Register" button to add them.