|
Item |
Details |
|
|---|---|---|
|
Pre-check |
|
|
|
Name ID |
〇 |
Email address |
|
Custom attribute Note: For how to configure custom attributes, see here |
||
|
SP-side Configuration |
〇 |
Configured by the administrator |
|
Request configuration from the SP |
||
|
Provisioning |
API-based Provisioning supported (account management available in GMO TrustLogin) |
|
|
SAML JIT provisioning supported (account management available in GMO TrustLogin; user deletion not supported) |
||
|
〇 |
None (accounts created in each system) |
|
|
Access Method |
〇 |
SP-Initiated SSO |
|
〇 |
IdP-Initiated SSO |
|
|
Verified Operation by Device |
〇 |
PC - Browser |
|
ー |
PC - Desktop App |
|
|
〇 |
iOS - Standard Browser (Safari) |
|
|
〇 |
iOS - TrustLogin Mobile App In-App Browser |
|
|
ー |
iOS - Native App |
|
|
〇 |
Android - Standard Browser (Chrome) |
|
|
〇 |
Android - TrustLogin Mobile App In-App Browser |
|
|
ー |
Android - Native App |
|
TrustLogin Admin Page Settings
- Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
- On the "Register Corporate App" screen, search for and select "[Expense] MAJOR FLOW Z CLOUD (SAML)".
- Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
After downloading the certificate, change its file extension to ".crt".
-
Configure each item under "Service Provider Settings" as follows.
Entity ID Any ID of your choosing (here, MAJORFLOWZ)
Note: You will enter this later in MAJOR FLOW Z. Make a note of the entity ID you entered in TrustLogin.
ACS URL for the service
Please check with your MAJOR FLOW Z service representative.
- Save the configuration by clicking the "Register" button.
Now, switch to configuring MAJOR FLOW Z.
MAJOR FLOW Z CLOUD Configuration
- Check the user information registered in MAJOR FLOW Z. Log in to the MAJOR FLOW Z admin screen and open "User Master".
- Select "Edit Various Information".
- Select the user for whom you want to configure SAML authentication, and click "Edit".
- In "Services Used", confirm that "MAJOR FLOW Z CLOUD Expense Settlement" is checked.
Confirm that the same email address as TrustLogin is registered, and that the checkbox next to the email address field is checked. Also make a note of the number of the registered email address field.
(Example: In the case of the registration field shown below, since it is registered in "e-mail1", note down 1.)
- Return to the MAJOR FLOW Z admin screen and open "Expenses > System Settings".
- Click "System Parameters".
-
From the "All" dropdown, select "SAML Authentication Settings".
- Click "Edit" in the row for "CertificationSetting".
- Enter the following information in the value field for each setting, and click the "Register" button.
SAML Authentication Enabled Enter 1 IdP Settings Enter 2
-
Click "Confirm".
- Return to the "SAML Authentication Settings" screen and click "Edit" in the row for "GsuiteSetting".
- Enter the following information for each setting item, and click the "Register" button.
SSO URL Add "?1=1" to the end of the "IdP URL" you noted from TrustLogin.
Example: https://portal.trustlogin.com/XXXX/idp/XXXX/saml/auth?1=1
Entity ID Enter the same ID as the one you entered in "Entity ID" under "Service Provider Settings" in TrustLogin.
(Here, MAJORFLOWZ)
Authentication Settings Enter 1 Response URL SamlAcs/Acs Authentication Email Address Setting Enter the email address registration number you noted in step 4 of the MAJOR FLOW Z configuration. (Here, enter 1 as an example)
- Click the "Confirm" button.
- Return to the "SAML Authentication Settings" screen and click "Edit" in the "CertificateSetting" row for the certificate header and footer fields.
- Confirm that both the "Certificate Header" and "Certificate Footer" fields contain "\n".
Note: If "\n" is not entered, refer to the image below, enter "\n" in each of the "Certificate Header" and "Certificate Footer" input fields, click the "Register" button, and then click "Confirm".
- Return to the MAJOR FLOW Z admin screen and open "Common > Certificate Settings".
- Click "Register Certificate".
- From the target app selection dropdown, select "MFZK_SAML".
- Upload the certificate downloaded from TrustLogin (with the file extension changed to .crt) using "Choose File", and click "Start Import".
- Confirm that the message "No issues were found with the certificate file." is displayed, then click "Apply Contents".
- The certificate registration is now complete.
TrustLogin User Settings
① When a User Adds the App via My Page
- Click the "Add App" button on "My Page".
- On the "Register App" screen, select "[Expense] MAJOR FLOW Z CLOUD (SAML)" and click the "Next" button at the top right of the screen.
- If you want to change the "Display Name", enter it, then click the "Register" button.
- Click the app on "My Page" or in the "browser extension" and check that login succeeds.
② When an Administrator Adds Members
- Search for and click the "[Expense] MAJOR FLOW Z CLOUD (SAML)" app in the "Admin Page > App" menu.
- Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.