How to Configure SAML Authentication for MAJOR FLOW Z CLOUD

Item

Details

Pre-check

  • Prior configuration in MAJOR FLOW Z CLOUD is required.

  • You must create an account in MAJOR FLOW Z CLOUD using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by MAJOR FLOW Z CLOUD.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-Side Settings

Configured by the administrator

Request the SP to configure it

Provisioning

Supports Provisioning via API (account management possible with GMO TrustLogin)

Supports SAML JIT Provisioning(account management possible with GMO TrustLogin; user deletion not supported)

None (accounts created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "MAJOR FLOW Z CLOUD(SAML)".
    MFZ01.png

  3. Make a note of the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
  4. After downloading the certificate, change its extension to ".crt".
    MFZC01.png

  5. Configure each item under "Service Provider Settings" as follows.
    Entity ID

    Any ID of your choice (here, MAJORFLOWZ)

    Note: You will enter this later in MAJOR FLOW Z. Make a note of the Entity ID you entered in TrustLogin.

    ACS URL for the Service

    Please check with your MAJOR FLOW Z service representative.


    MFZ02.png

  6. Click "Register" to save the settings.

Now switch to the MAJOR FLOW Z side settings.

MAJOR FLOW Z CLOUD Configuration

  1. Check the user information registered in MAJOR FLOW Z. Log in to the MAJOR FLOW Z admin screen and open "User Master".
    MFZ11.png

  2. Select "Edit Various Information".
    MFZ12.png

  3. Select the user for whom you want to configure SAML authentication, and click "Edit".
    MFZ13.png

  4. Confirm that the same email address as TrustLogin is registered, and that the checkbox next to the email address field is checked. Also make a note of the number of the registered email address field.
    (Example: In the registration field shown below, since it is registered in "e-mail1", note down 1.)
    MFZ14.png

  5. Return to the MAJOR FLOW Z admin screen and open "System Settings".MFZ03.png

  6. Select "System Parameters".MFZ04.png

  7. From the "All" pull-down, select "SAML Authentication Settings".
    MFZ05.png   
           
  8. "Click "Edit" in the "CertificationSetting" field.MFZ06.png

  9. Enter the following information in the value field for each setting, and click the "Register" button.
    SAML Authentication Enabled Enter 1
    IdP Settings Enter 2

    MFZ07.png

  10. Return to the "SAML Authentication Settings" screen, and click "Edit" in the "GsuiteSetting" field.MFZ08.png

  11. Enter the following information for each setting item, and click the "Register" button.
    SSO URL

    Add "?1=1" to the end of the "Identity Provider URL" you noted from TrustLogin.

    Example: https://portal.trustlogin.com/XXXX/idp/XXXX/saml/auth?1=1

    Entity ID

    Enter the same ID that you entered in the "Entity ID" field under TrustLogin's "Service Provider Settings".

    (Here, MAJORFLOWZ)

    Authentication Settings Enter 1
    Response URL SamlAcs/Acs
    Authentication Email Address Settings

    Enter the registration number of the email address field you noted in step 4 of the MAJOR FLOW Z settings. (Here, enter 1 as an example)


    MAJOR FLOW Z1.png

  12. Click the "Confirm" button.MFZ15.png

  13. Return to the "SAML Authentication Settings" screen, and click "Edit" in the certificate header/footer fields of "CertificateSetting".
    MFZ21.png

  14. Confirm that "\n" is entered in both the "Certificate Header" and "Certificate Footer" fields.
    MFZ22.png

  15. Return to the MAJOR FLOW Z admin screen and open "Certificate Settings".
    MFZ16.png

  16. Click "Register Certificate".
    MFZ17.png

  17. Select "MFZC_SAML" as the target app.
    Upload the certificate you downloaded from TrustLogin (with the extension changed to .crt) using "Choose File", and click "Start Import".
    MFZ18.png

  18. After confirming the message "No issues were found with the certificate file.", click "Apply".
    MFZ19.png

  19. Certificate registration is complete.
    MFZ20.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. In "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "MAJOR FLOW Z(SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.
  4. Click the app in "My Page" or the browser extension, and check whether login succeeds.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "MAJOR FLOW Z CLOUD(SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for MAJOR FLOW Z CLOUD

Item

Details

Pre-check

  • Prior configuration in MAJOR FLOW Z CLOUD is required.

  • You must create an account in MAJOR FLOW Z CLOUD using the same email address as TrustLogin.

  • For the latest configuration steps, please refer to the manual provided by MAJOR FLOW Z CLOUD.

Name ID

Email address

Custom attribute Note: For instructions on how to configure custom attributes, click here

SP-Side Settings

Configured by the administrator

Request the SP to configure it

Provisioning

Supports Provisioning via API (account management possible with GMO TrustLogin)

Supports SAML JIT Provisioning(account management possible with GMO TrustLogin; user deletion not supported)

None (accounts created individually in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
    01.png

  2. Search on the "Register Company App" screen and select "MAJOR FLOW Z CLOUD(SAML)".
    MFZ01.png

  3. Make a note of the "Identity Provider URL" under "Identity Provider Information", and download the certificate from "Get Certificate".
  4. After downloading the certificate, change its extension to ".crt".
    MFZC01.png

  5. Configure each item under "Service Provider Settings" as follows.
    Entity ID

    Any ID of your choice (here, MAJORFLOWZ)

    Note: You will enter this later in MAJOR FLOW Z. Make a note of the Entity ID you entered in TrustLogin.

    ACS URL for the Service

    Please check with your MAJOR FLOW Z service representative.


    MFZ02.png

  6. Click "Register" to save the settings.

Now switch to the MAJOR FLOW Z side settings.

MAJOR FLOW Z CLOUD Configuration

  1. Check the user information registered in MAJOR FLOW Z. Log in to the MAJOR FLOW Z admin screen and open "User Master".
    MFZ11.png

  2. Select "Edit Various Information".
    MFZ12.png

  3. Select the user for whom you want to configure SAML authentication, and click "Edit".
    MFZ13.png

  4. Confirm that the same email address as TrustLogin is registered, and that the checkbox next to the email address field is checked. Also make a note of the number of the registered email address field.
    (Example: In the registration field shown below, since it is registered in "e-mail1", note down 1.)
    MFZ14.png

  5. Return to the MAJOR FLOW Z admin screen and open "System Settings".MFZ03.png

  6. Select "System Parameters".MFZ04.png

  7. From the "All" pull-down, select "SAML Authentication Settings".
    MFZ05.png   
           
  8. "Click "Edit" in the "CertificationSetting" field.MFZ06.png

  9. Enter the following information in the value field for each setting, and click the "Register" button.
    SAML Authentication Enabled Enter 1
    IdP Settings Enter 2

    MFZ07.png

  10. Return to the "SAML Authentication Settings" screen, and click "Edit" in the "GsuiteSetting" field.MFZ08.png

  11. Enter the following information for each setting item, and click the "Register" button.
    SSO URL

    Add "?1=1" to the end of the "Identity Provider URL" you noted from TrustLogin.

    Example: https://portal.trustlogin.com/XXXX/idp/XXXX/saml/auth?1=1

    Entity ID

    Enter the same ID that you entered in the "Entity ID" field under TrustLogin's "Service Provider Settings".

    (Here, MAJORFLOWZ)

    Authentication Settings Enter 1
    Response URL SamlAcs/Acs
    Authentication Email Address Settings

    Enter the registration number of the email address field you noted in step 4 of the MAJOR FLOW Z settings. (Here, enter 1 as an example)


    MAJOR FLOW Z1.png

  12. Click the "Confirm" button.MFZ15.png

  13. Return to the "SAML Authentication Settings" screen, and click "Edit" in the certificate header/footer fields of "CertificateSetting".
    MFZ21.png

  14. Confirm that "\n" is entered in both the "Certificate Header" and "Certificate Footer" fields.
    MFZ22.png

  15. Return to the MAJOR FLOW Z admin screen and open "Certificate Settings".
    MFZ16.png

  16. Click "Register Certificate".
    MFZ17.png

  17. Select "MFZC_SAML" as the target app.
    Upload the certificate you downloaded from TrustLogin (with the extension changed to .crt) using "Choose File", and click "Start Import".
    MFZ18.png

  18. After confirming the message "No issues were found with the certificate file.", click "Apply".
    MFZ19.png

  19. Certificate registration is complete.
    MFZ20.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. In "My Page", click the "Add App" button.
  2. On the "Register App" screen, select "MAJOR FLOW Z(SAML)", and click the "Next" button in the upper right of the screen.
  3. If you want to change the "Display Name", enter it, and click the "Register" button.
  4. Click the app in "My Page" or the browser extension, and check whether login succeeds.

② When an Administrator Adds Members

  1. In the "Admin Page > Apps" menu, search for and click the "MAJOR FLOW Z CLOUD(SAML)" app.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.