Note: Prior configuration in SmartHR is required.
Note: For the latest setup instructions, please refer to the manual provided by SmartHR.
Reference: Configuring SAML Authentication (SSO) / Logging in Using SAML Authentication (SSO)
TrustLogin Admin Page Configuration
-
Log in to TrustLogin, open the "Admin Page > Apps" menu, and click the "Register App" button in the upper right of the screen.
- Search on the "Register Corporate App" screen and select "SmartHR (SAML)."
- Download the metadata using "Download Metadata" under "Identity Provider Information." (This will be needed later when configuring the SmartHR side.)
- Enter your SmartHR subdomain (tenant ID) in the four blank fields under "Service Provider Settings."
Reference: What is a Subdomain (Tenant ID)?
- Click the "Register" button to save.
- To perform an operation test, add the administrator as a member of the app you created.
(For instructions on how to add a member, click here.)
SmartHR Configuration
- Log in to SmartHR with an administrator account and open "Common Settings > SAML SSO Settings" at the bottom of the left menu.
- Click "Edit" for the SAML SSO settings.
- Upload the metadata downloaded from TrustLogin using "Upload Configuration File."
- Set the "Login Button Label." (Optional. You may leave it unset. If left unset, it will display as "Log in with SAML SSO.")
- Click "Check Settings" under "Check SAML SSO Settings" to test the connection.
- Open "Common Settings > SAML SSO Accounts" at the bottom of the left menu to configure SAML SSO accounts. Click the "…" menu for the employee for whom you want to enable SAML SSO, and select "Edit SAML SSO Account."
- Enter your TrustLogin email address in "Linked IdP Account," check "Enable SSO," and click the "Update" button to save the settings.
- Only accounts that have been enabled will log in via SAML SSO and will no longer be able to log in with an ID/password. Accounts marked "Disabled" will continue to log in with an ID/password.
- Open "Common Settings > SAML SSO Settings" and enable SAML SSO. Check "Enable SAML SSO" and click "Update" to save the settings.
TrustLogin User Configuration
① When a User Adds the App from My Page
- Click the "Add App" button on "My Page."
- On the "Register App" screen, select "SmartHR (SAML)" and click the "Next" button in the upper right of the screen.
- If you want to change the "Display Name," enter a new one, then click the "Register" button.
- Click the app from "My Page" or the "browser extension" and check whether login succeeds.
② When an Administrator Adds a Member
- In the "Admin Page > Apps" menu, search for and click the "SmartHR (SAML)" app.
- Click "Add Member," select the user to add from the member list, and click the "Register" button to add them.