1. SAML Settings
TrustLogin Admin Page Settings
Netskope Settings
TrustLogin Admin Page Settings (Continued)
TrustLogin User Settings
2. Certificate & Proxy Settings
Certificate Import
Proxy Settings
3. Verification
1. SAML Settings
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- On the "Register Corporate App" screen, search and select "Netskope (Forward Proxy) (SAML)".
- Note down the "Identity Provider URL" and "Issuer / Entity ID" values under "Identity Provider Information", and download the certificate from "Get Certificate".
Now, switch to configuring the Netskope side.
Do not click the "Register" button yet — open Netskope in a separate window.
Netskope Settings
- Log in as an administrator, and open "Settings" from the left-hand menu.
- Open "Security Cloud Platform".
- Click "Forward Proxy > SAML", and note down the values of "SAML Entity ID" and "SAML ACS URL".
- Click "NEW ACCOUNT".
- Configure each item as follows, and finally click the "Register" button.
NAME Any name of your choice (here, used as an example: TrustLogin Forward Proxy Settings) IDP SSO URL The "Identity Provider URL" you noted from TrustLogin IDP ENTITY ID The "Issuer / Entity ID" you noted from TrustLogin IDP CERTIFICATE Open the "Certificate" you downloaded from TrustLogin and paste its contents
- Confirm that the message "SAML Account updated" is displayed and that the account you created has been added and is shown, then click "Forward Proxy > Authentication".
- Click "ENABLE AUTHENTICATION".
- Turn the toggle button ON to set it to Enabled.
Also, from the "SAML ACCOUNT" dropdown, select the account with the name you configured in step 5, and save by clicking "SAVE". - Click "Bypass Settings > DOMAIN BYPASS > EDIT".
- Set "trustlogin.com" and click "SAVE".
- Confirm that the message "Authentication Info Saved" is displayed, and that the domain you configured appears in the "DOMAIN BYPASS" list.
Now return to the TrustLogin settings.
TrustLogin Admin Page Settings (Continued)
- Configure each item under "Service Provider Settings" with the information you noted from Netskope, as follows.
Login URL The "SAML ACS URL" you noted from Netskope Entity ID The "SAML Entity ID" you noted from Netskope ACS URL for the Service The "SAML ACS URL" you noted from Netskope
- Click the "Register" button to save.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Netskope (Forward Proxy) (SAML)", and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app on "My Page" or in the browser extension, and check whether login succeeds.
② When an Administrator Adds Members
- In the "Admin Page > Apps" menu, search for and click the "Netskope (Forward Proxy) (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
2. Certificate & Proxy Settings
Certificate Import
- Log in to Netskope, and open "Settings > Security Cloud Platform > TRAFIC STEERING > Explicit Proxy".
- Note down the value of "Explicit Proxy Destination > Explicit Proxy Destination", and
download the certificate from "DOWNLOAD ROOT CERTIFICATE (REMOTE USERS)".
- Change the certificate file saved in ".pem" format to ".cer" format, and double-click the certificate file. (You can change it by changing the file extension.)
- In the warning window, select "Open", and in the certificate window that appears, click "Install Certificate".
- Change the storage location to "Local Machine" and click "Next".
- Select "Place all certificates in the following store", click "Browse", specify "Trusted Root Certification Authorities", and click "Next".
- On the confirmation page, click "Finish".
- Confirm that the message window "The import was successful." is displayed, and click "OK".
Note: Also close the certificate window shown in step 4 by clicking "OK" or the "×" button in the upper right.
Note: If you are using Firefox, a separate certificate import is required for Firefox.
Proxy Settings
- Press "Start + R" to open the Run dialog, then enter "inetcpl.cpl" and click "OK".
- In the Internet Properties window, click "Connections (tab)" > "LAN settings".
- Check the box for "Use a proxy server for your LAN".
Enter the "Explicit Proxy Destination" value you noted in step 2 of "Certificate Import" as the address and port, and click "OK".
Note: If you are using Firefox, a separate proxy configuration is required for Firefox.
3. Verification
- Access any web page. (In this example, Google (https://google.co.jp) is used.)
- The Netskope Forward Proxy screen will be displayed. Enter your tenant name and click "Continue".
- You will be redirected to TrustLogin, so log in.
- You have successfully accessed the web page.
- Log in to any SaaS app and perform some operations. (In this example, Salesforce is used.)
- Log in to Netskope with an administrator account, open "Skope IT > Application Events", and confirm that you can view the login and operation history for Salesforce in the log.