How to Configure SAML Authentication for MAJOR FLOW Z CLOUD (Expense Management)

Item

Details

Pre-check

  • Prior configuration in MAJOR FLOW Z CLOUD is required.

  • You must have already created an account in MAJOR FLOW Z CLOUD using the same email address as your TrustLogin account.

  • Please refer to the manual provided by MAJOR FLOW Z CLOUD for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in GMO TrustLogin)

SAML JIT provisioning supported (account management available in GMO TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "[Expense] MAJOR FLOW Z CLOUD (SAML)".
    MFZK.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    After downloading the certificate, change its file extension to ".crt".
    MFZC01.png

  4. Configure each item under "Service Provider Settings" as follows.
    Entity ID

    Any ID of your choosing (here, MAJORFLOWZ)

    Note: You will enter this later in MAJOR FLOW Z. Make a note of the entity ID you entered in TrustLogin.

    ACS URL for the service

    Please check with your MAJOR FLOW Z service representative.


    MFZ02.png

  5. Save the configuration by clicking the "Register" button.

Now, switch to configuring MAJOR FLOW Z.

MAJOR FLOW Z CLOUD Configuration

  1. Check the user information registered in MAJOR FLOW Z. Log in to the MAJOR FLOW Z admin screen and open "User Master".
    MFZ11.png

  2. Select "Edit Various Information".
    MFZ12.png

  3. Select the user for whom you want to configure SAML authentication, and click "Edit".
    MFZ13.png

  4. In "Services Used", confirm that "MAJOR FLOW Z CLOUD Expense Settlement" is checked.
    Confirm that the same email address as TrustLogin is registered, and that the checkbox next to the email address field is checked. Also make a note of the number of the registered email address field.
    (Example: In the case of the registration field shown below, since it is registered in "e-mail1", note down 1.)
    MFZK02.png

  5. Return to the MAJOR FLOW Z admin screen and open "Expenses > System Settings".MFZK_01.png

  6. Click "System Parameters".MFZK03.png

  7. From the "All" dropdown, select "SAML Authentication Settings".
    MFZK04.png 
             
  8. Click "Edit" in the row for "CertificationSetting".MFZK05.png

  9. Enter the following information in the value field for each setting, and click the "Register" button.
    SAML Authentication Enabled Enter 1
    IdP Settings Enter 2

    MFZK06.png

  10. Click "Confirm".MFZK17.png

  11. Return to the "SAML Authentication Settings" screen and click "Edit" in the row for "GsuiteSetting".MFZK07.png

  12. Enter the following information for each setting item, and click the "Register" button.
    SSO URL

    Add "?1=1" to the end of the "IdP URL" you noted from TrustLogin.

    Example: https://portal.trustlogin.com/XXXX/idp/XXXX/saml/auth?1=1

    Entity ID

    Enter the same ID as the one you entered in "Entity ID" under "Service Provider Settings" in TrustLogin.

    (Here, MAJORFLOWZ)

    Authentication Settings Enter 1
    Response URL SamlAcs/Acs
    Authentication Email Address Setting

    Enter the email address registration number you noted in step 4 of the MAJOR FLOW Z configuration. (Here, enter 1 as an example)


    Expense_MAJOR_FLOW_Z.png


  13. Click the "Confirm" button.MFZK10.png

  14. Return to the "SAML Authentication Settings" screen and click "Edit" in the "CertificateSetting" row for the certificate header and footer fields.
    MFZ21.png

  15. Confirm that both the "Certificate Header" and "Certificate Footer" fields contain "\n".
    Note: If "\n" is not entered, refer to the image below, enter "\n" in each of the "Certificate Header" and "Certificate Footer" input fields, click the "Register" button, and then click "Confirm".
    MFZK11.png

  16. Return to the MAJOR FLOW Z admin screen and open "Common > Certificate Settings".
    MFZ16.png

  17. Click "Register Certificate".
    MFZ17.png

  18. From the target app selection dropdown, select "MFZK_SAML".MFZK12.png

  19. Upload the certificate downloaded from TrustLogin (with the file extension changed to .crt) using "Choose File", and click "Start Import".
    MFZK13.png

  20. Confirm that the message "No issues were found with the certificate file." is displayed, then click "Apply Contents".
    MFZ19.png

  21. The certificate registration is now complete.
    MFZ20.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "[Expense] MAJOR FLOW Z CLOUD (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "[Expense] MAJOR FLOW Z CLOUD (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for MAJOR FLOW Z CLOUD (Expense Management)

Item

Details

Pre-check

  • Prior configuration in MAJOR FLOW Z CLOUD is required.

  • You must have already created an account in MAJOR FLOW Z CLOUD using the same email address as your TrustLogin account.

  • Please refer to the manual provided by MAJOR FLOW Z CLOUD for the latest configuration steps.

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in GMO TrustLogin)

SAML JIT provisioning supported (account management available in GMO TrustLogin; user deletion not supported)

None (accounts created in each system)

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "[Expense] MAJOR FLOW Z CLOUD (SAML)".
    MFZK.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    After downloading the certificate, change its file extension to ".crt".
    MFZC01.png

  4. Configure each item under "Service Provider Settings" as follows.
    Entity ID

    Any ID of your choosing (here, MAJORFLOWZ)

    Note: You will enter this later in MAJOR FLOW Z. Make a note of the entity ID you entered in TrustLogin.

    ACS URL for the service

    Please check with your MAJOR FLOW Z service representative.


    MFZ02.png

  5. Save the configuration by clicking the "Register" button.

Now, switch to configuring MAJOR FLOW Z.

MAJOR FLOW Z CLOUD Configuration

  1. Check the user information registered in MAJOR FLOW Z. Log in to the MAJOR FLOW Z admin screen and open "User Master".
    MFZ11.png

  2. Select "Edit Various Information".
    MFZ12.png

  3. Select the user for whom you want to configure SAML authentication, and click "Edit".
    MFZ13.png

  4. In "Services Used", confirm that "MAJOR FLOW Z CLOUD Expense Settlement" is checked.
    Confirm that the same email address as TrustLogin is registered, and that the checkbox next to the email address field is checked. Also make a note of the number of the registered email address field.
    (Example: In the case of the registration field shown below, since it is registered in "e-mail1", note down 1.)
    MFZK02.png

  5. Return to the MAJOR FLOW Z admin screen and open "Expenses > System Settings".MFZK_01.png

  6. Click "System Parameters".MFZK03.png

  7. From the "All" dropdown, select "SAML Authentication Settings".
    MFZK04.png 
             
  8. Click "Edit" in the row for "CertificationSetting".MFZK05.png

  9. Enter the following information in the value field for each setting, and click the "Register" button.
    SAML Authentication Enabled Enter 1
    IdP Settings Enter 2

    MFZK06.png

  10. Click "Confirm".MFZK17.png

  11. Return to the "SAML Authentication Settings" screen and click "Edit" in the row for "GsuiteSetting".MFZK07.png

  12. Enter the following information for each setting item, and click the "Register" button.
    SSO URL

    Add "?1=1" to the end of the "IdP URL" you noted from TrustLogin.

    Example: https://portal.trustlogin.com/XXXX/idp/XXXX/saml/auth?1=1

    Entity ID

    Enter the same ID as the one you entered in "Entity ID" under "Service Provider Settings" in TrustLogin.

    (Here, MAJORFLOWZ)

    Authentication Settings Enter 1
    Response URL SamlAcs/Acs
    Authentication Email Address Setting

    Enter the email address registration number you noted in step 4 of the MAJOR FLOW Z configuration. (Here, enter 1 as an example)


    Expense_MAJOR_FLOW_Z.png


  13. Click the "Confirm" button.MFZK10.png

  14. Return to the "SAML Authentication Settings" screen and click "Edit" in the "CertificateSetting" row for the certificate header and footer fields.
    MFZ21.png

  15. Confirm that both the "Certificate Header" and "Certificate Footer" fields contain "\n".
    Note: If "\n" is not entered, refer to the image below, enter "\n" in each of the "Certificate Header" and "Certificate Footer" input fields, click the "Register" button, and then click "Confirm".
    MFZK11.png

  16. Return to the MAJOR FLOW Z admin screen and open "Common > Certificate Settings".
    MFZ16.png

  17. Click "Register Certificate".
    MFZ17.png

  18. From the target app selection dropdown, select "MFZK_SAML".MFZK12.png

  19. Upload the certificate downloaded from TrustLogin (with the file extension changed to .crt) using "Choose File", and click "Start Import".
    MFZK13.png

  20. Confirm that the message "No issues were found with the certificate file." is displayed, then click "Apply Contents".
    MFZ19.png

  21. The certificate registration is now complete.
    MFZ20.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "Register App" screen, select "[Expense] MAJOR FLOW Z CLOUD (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the "browser extension" and check that login succeeds.

② When an Administrator Adds Members

  1. Search for and click the "[Expense] MAJOR FLOW Z CLOUD (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.