SCIM IDP Integration with LOCKED DAS (Directory Auto Sync) - Setup Guide

Integrate LOCKED DAS with TrustLogin to Reduce the Effort of ID Management

Note: This feature is intended for customers with a contract for onetap Inc.'s LOCKED DAS (Directory Auto Sync).
Note: For the steps to directly integrate Microsoft 365 (Azure AD) with TrustLogin, please see here.

"SCIM IDP Integration" is a feature that uses the SCIM protocol to
synchronize ID information from LOCKED DAS to TrustLogin.

This guide explains how to configure integration with LOCKED DAS using SCIM IDP Integration.

Note: A TrustLogin Pro plan or optional contract is required to use this feature. For pricing, see here
Note: This assumes that LOCKED DAS is already integrated with some kind of ID management service (data source).
 

TrustLogin-side Configuration

Setup Steps

  1. Log in to TrustLogin, then open the "Admin Page > Settings > Optional Features" menu, and click "Settings" to the right of "SCIM IDP Integration."
    00.png

  2. Open "SCIM Source Configuration to Add."
    01.png

  3. Set any name you like and click "Save."
    02.png

  4. Open the source configuration you created.
    03.png

  5. Make a note of the "SCIM Endpoint" and the value obtained from "Generate Credentials."
    (These are used in the LOCKED DAS-side configuration.)

    04.png
    Note: If you generate credentials, the existing credentials will no longer be usable.
      If this is not a problem, proceed by clicking "Yes" on the screen below.
     05.png

LOCKED DAS (Directory Auto Sync)-side Configuration

As an example, this section introduces the steps for creating users in TrustLogin
based on Microsoft 365 user information.
When performing your actual configuration, please specify whichever ID management service you are using.

Note: For detailed configuration and operation instructions on the LOCKED DAS side,
 please check with the provider of LOCKED DAS (onetap Inc.).

Setup Steps

  1. From the LOCKED DAS admin screen, go to "Add Workflow,"
    select "GMO TrustLogin" in the "Action > App" field,
    and select "Create User" in the "Action > Action Type" field.
    Note: Event refers to the ID management service (data source) being monitored. Here, Microsoft 365 is specified.
    07.png

  2. Select "Add Connection."
    08.png

  3. TrustLogin Configuration > enter the values obtained in Setup Step 5.
    Enter the value of TrustLogin's "
    SCIM Configuration Endpoint" into the "SCIM Endpoint" field,
    and the value obtained from "Generate Credentials" into the "Token" field, then click "Integrate."

    09.png

  4. According to the conditions you want to sync, enter the required fields under "Action > Input."
    10.png

    Note: The mapping of each field can be configured freely.
     Example: Field configuration using Microsoft 365 as an example
    11______.PNG


  5. Click "Save and Activate" for the configuration. Users matching the specified conditions will be created in TrustLogin.
    Since the TrustLogin members created through this integration have LOCKED DAS (Microsoft 365)
    as their source of information, the following member operations will no longer be available on the TrustLogin side.

     ・Profile changes
     ・Member status changes
     ・Member deletionmceclip1.png

    Currently, only users are provisioned; groups are not provisioned.
    For group assignment,
    please refer to the "Register a
    Group" section, under the "Automatically Add Members to a Group Based on Conditions" item for more information.

SCIM IDP Integration with LOCKED DAS (Directory Auto Sync) - Setup Guide

Integrate LOCKED DAS with TrustLogin to Reduce the Effort of ID Management

Note: This feature is intended for customers with a contract for onetap Inc.'s LOCKED DAS (Directory Auto Sync).
Note: For the steps to directly integrate Microsoft 365 (Azure AD) with TrustLogin, please see here.

"SCIM IDP Integration" is a feature that uses the SCIM protocol to
synchronize ID information from LOCKED DAS to TrustLogin.

This guide explains how to configure integration with LOCKED DAS using SCIM IDP Integration.

Note: A TrustLogin Pro plan or optional contract is required to use this feature. For pricing, see here
Note: This assumes that LOCKED DAS is already integrated with some kind of ID management service (data source).
 

TrustLogin-side Configuration

Setup Steps

  1. Log in to TrustLogin, then open the "Admin Page > Settings > Optional Features" menu, and click "Settings" to the right of "SCIM IDP Integration."
    00.png

  2. Open "SCIM Source Configuration to Add."
    01.png

  3. Set any name you like and click "Save."
    02.png

  4. Open the source configuration you created.
    03.png

  5. Make a note of the "SCIM Endpoint" and the value obtained from "Generate Credentials."
    (These are used in the LOCKED DAS-side configuration.)

    04.png
    Note: If you generate credentials, the existing credentials will no longer be usable.
      If this is not a problem, proceed by clicking "Yes" on the screen below.
     05.png

LOCKED DAS (Directory Auto Sync)-side Configuration

As an example, this section introduces the steps for creating users in TrustLogin
based on Microsoft 365 user information.
When performing your actual configuration, please specify whichever ID management service you are using.

Note: For detailed configuration and operation instructions on the LOCKED DAS side,
 please check with the provider of LOCKED DAS (onetap Inc.).

Setup Steps

  1. From the LOCKED DAS admin screen, go to "Add Workflow,"
    select "GMO TrustLogin" in the "Action > App" field,
    and select "Create User" in the "Action > Action Type" field.
    Note: Event refers to the ID management service (data source) being monitored. Here, Microsoft 365 is specified.
    07.png

  2. Select "Add Connection."
    08.png

  3. TrustLogin Configuration > enter the values obtained in Setup Step 5.
    Enter the value of TrustLogin's "
    SCIM Configuration Endpoint" into the "SCIM Endpoint" field,
    and the value obtained from "Generate Credentials" into the "Token" field, then click "Integrate."

    09.png

  4. According to the conditions you want to sync, enter the required fields under "Action > Input."
    10.png

    Note: The mapping of each field can be configured freely.
     Example: Field configuration using Microsoft 365 as an example
    11______.PNG


  5. Click "Save and Activate" for the configuration. Users matching the specified conditions will be created in TrustLogin.
    Since the TrustLogin members created through this integration have LOCKED DAS (Microsoft 365)
    as their source of information, the following member operations will no longer be available on the TrustLogin side.

     ・Profile changes
     ・Member status changes
     ・Member deletionmceclip1.png

    Currently, only users are provisioned; groups are not provisioned.
    For group assignment,
    please refer to the "Register a
    Group" section, under the "Automatically Add Members to a Group Based on Conditions" item for more information.