Note: Advance configuration is required on the Sansan side.
Note: For the latest configuration steps, please refer to the manual provided by Sansan.
|
Configure SAML Authentication |
Preparation
You need to set the email address registered in your TrustLogin member information as the "SAML Name ID" in each user's information in Sansan.
For instructions on how to change user information in Sansan, please see here.
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Corporate App Registration" screen and select "Sansan (SAML)".
- Note down the "Identity Provider URL" and "Issuer/Entity ID" under "Identity Provider Information", and download the "Certificate".
- Convert the file extension of the downloaded certificate to [.cer].
Now, switch to the configuration on the Sansan side.
Do not click the "Register" button yet — log in to Sansan with a system administrator account in a separate tab.
Sansan Configuration
- Open "Administrator Settings > Security Settings > SAML Authentication" and click "Add New IdP Configuration".
- Configure the "Configuration Name" and "1. IdP Side" as follows.
Configuration Name Set any name. In this example, "TrustLogin" is used.
IdP Used Select "Other" from the drop-down list EntityId Single
- Click "Display" under "Information to Configure in the IdP" and note down the "Identifier" and "Response URL" information shown.
- Configure "2. Sansan Side".
Note 1: If you are using the client authentication option, we have confirmed that unless "Use" is checked under "MDM", the certificate selection dialog will not appear in the Sansan mobile app.MDM Check this according to your MDM usage status (Note 1) IdP Identifier Name The "Issuer/Entity ID" noted down from TrustLogin Login URL The "Identity Provider URL" noted down from TrustLogin SAML Signing Certificate The certificate downloaded from TrustLogin, converted to .cer format
Return to the TrustLogin side configuration again.
TrustLogin Admin Page Configuration (Continued)
-
Enter the information you noted down from Sansan into "Service Provider Settings", then click "Register" to save the settings.
Entity ID The "Identifier" noted down from Sansan ACS URL to Service The "Response URL" noted down from Sansan
(enter separately for PC and smartphone app)Note: Please register the PC version URL in the top row.
Note: There are 3 rows, but the bottom row may be left blank.
- To perform a functional test, add the administrator as a member of the app you created.
(For instructions on how to add a member, see here)
Once the above configuration is complete, perform a functional test in Sansan.
Sansan Configuration (Functional Test and Activation)
- Click the "Run" button under "3. Validate Configuration".
- You will be redirected to the TrustLogin login screen, where you should authenticate with TrustLogin.
(If you are already logged in to TrustLogin, simply proceed to the next step.)
- If a message indicating that the functional test is complete appears, the test was successful. If the test is not successful, please check the configuration so far for any errors.
- Click "Save" and a message will appear; select "OK".
- Once you have added members to the created SAML app and completed preparations for internal announcement, enable SAML authentication. Under "Company-wide Settings > Usage Settings", change to "Use SAML Authentication" and select the IdP configuration you created from the drop-down list. Click the "Save" button to save.
Note: Once SAML authentication is enabled, please note that you will no longer be able to log in with your previous login ID and password.
TrustLogin User Configuration
① When a User Adds It from My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "Sansan (SAML) " and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app on "My Page" or in the "Browser Extension" and confirm that login is successful.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for and click the "Sansan (SAML)" app.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.
How to Log In to Sansan
① Logging In to the PC Version
Log in by selecting the "Sansan (SAML)" app from TrustLogin's My Page or the Browser Extension.
② Logging In to the Smartphone App Version
Open the Sansan mobile app and click the "Login" button. On the next screen, enter only your email address and click the login button. The TrustLogin login screen will open, and once you log in, you will be logged in to the Sansan mobile app. (If you are already logged in to TrustLogin, you will be logged in automatically.)
Note: The smartphone web version service ended on May 31, 2021.