How to Configure SAML Authentication for MotionBoard

Item

Details

Pre-check

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)
Note: For how to configure this when provisioning is required, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


This manual explains the setup procedure for single sign-on via SAML integration when creating a SAML authentication domain in MotionBoard.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "MotionBoard (SAML)".
    02.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    04.png

  4. Set each item in "Service Provider Settings" as follows. Note that the configuration differs between the Cloud edition and the On-Premises edition.

    [For customers using the Cloud edition]
    Login URL

    https://cloud.motionboard.jp/motionboard/sso/saml?tenant=[Tenant ID]

    Entity ID

    https://cloud.motionboard.jp/motionboard/

    ACS URL for Service

    https://cloud.motionboard.jp/motionboard/sso/saml/callback


    [For customers using the On-Premises edition]
    Login URL

    ・If you do not have a multi-tenant license
    http://[Web server name or IP address]:8787/motionboard/sso/saml

    ・If you have a multi-tenant license
    http://[Web server name or IP address]:8787/motionboard/sso/saml?tenant=[Tenant ID]

    Entity ID http://[Web server name or IP address]:8787/motionboard/
    ACS URL for Service http://[Web server name or IP address]:8787/motionboard/sso/saml/callback

    03.png

  5. Save by clicking the "Register" button.

MotionBoard Configuration

  1. Log in to MotionBoard with an administrator account and open "System Settings > Connection/Authentication > Authentication".
    06.png

  2. Click "New".
    07.png

  3. Enter any name for the external authentication name, set the authentication destination type to "SAML", and click "New".
    08.png

  4. Click "New" under Domain Settings.
    09.png

  5. Confirm that "saml" is displayed as the domain ID, and click "New".
    10.png

  6. Confirm that "saml" has been added to the domain ID, and click "Save".
    11.png

  7. Open "Connection/Authentication > Single Sign-On".
    12.png

  8. Configure the following items and click "Save".
    SAML Integration Select the checkbox
    Target URL The "IdP URL" you noted from TrustLogin
    Certificate

    Convert the file extension of the "Certificate" downloaded from TrustLogin to .crt and upload it


    13.png

  9. Open "User > User".
    15.png

  10. Select the domain "saml", click "New", and add a SAML authentication user. You must set the TrustLogin email address in "User ID". Configure the other items as needed, then click "Add" at the end.
    16.png

  11. Open "User > Named Users".
    14.png

  12. Select the domain "saml" and drag and drop the users you want to allow SAML authentication for from the user list on the left to the named user list on the right.
    17.png

  13. Confirm that the user has been added to the named user list on the right in the format "UserID@saml", then click "Save".18.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "MotionBoard (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. Search for and click the "MotionBoard (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.

How to Configure SAML Authentication for MotionBoard

Item

Details

Pre-check

Name ID

Email address

Custom attribute Note: For how to configure custom attributes, see here

SP-side Configuration

Configured by the administrator

Request configuration from the SP

Provisioning

API-based Provisioning supported (account management available in TrustLogin)

SAML JIT provisioning supported (account management available in TrustLogin; user deletion not supported)

None (accounts created in each system)
Note: For how to configure this when provisioning is required, see here

Access Method

SP-Initiated SSO

IdP-Initiated SSO

Verified Operation by Device

PC - Browser

PC - Desktop App

iOS - Standard Browser (Safari)

iOS - TrustLogin Mobile App In-App Browser

iOS - Native App

Android - Standard Browser (Chrome)

Android - TrustLogin Mobile App In-App Browser

Android - Native App


This manual explains the setup procedure for single sign-on via SAML integration when creating a SAML authentication domain in MotionBoard.

TrustLogin Admin Page Settings

  1. Log in to TrustLogin, open the "Admin Page > App" menu, and click the "Register App" button at the top right of the screen.
    01.png

  2. On the "Register Corporate App" screen, search for and select "MotionBoard (SAML)".
    02.png

  3. Note the "IdP URL" in the "Identity Provider Information" section, and download the certificate using the "Get Certificate" button.
    04.png

  4. Set each item in "Service Provider Settings" as follows. Note that the configuration differs between the Cloud edition and the On-Premises edition.

    [For customers using the Cloud edition]
    Login URL

    https://cloud.motionboard.jp/motionboard/sso/saml?tenant=[Tenant ID]

    Entity ID

    https://cloud.motionboard.jp/motionboard/

    ACS URL for Service

    https://cloud.motionboard.jp/motionboard/sso/saml/callback


    [For customers using the On-Premises edition]
    Login URL

    ・If you do not have a multi-tenant license
    http://[Web server name or IP address]:8787/motionboard/sso/saml

    ・If you have a multi-tenant license
    http://[Web server name or IP address]:8787/motionboard/sso/saml?tenant=[Tenant ID]

    Entity ID http://[Web server name or IP address]:8787/motionboard/
    ACS URL for Service http://[Web server name or IP address]:8787/motionboard/sso/saml/callback

    03.png

  5. Save by clicking the "Register" button.

MotionBoard Configuration

  1. Log in to MotionBoard with an administrator account and open "System Settings > Connection/Authentication > Authentication".
    06.png

  2. Click "New".
    07.png

  3. Enter any name for the external authentication name, set the authentication destination type to "SAML", and click "New".
    08.png

  4. Click "New" under Domain Settings.
    09.png

  5. Confirm that "saml" is displayed as the domain ID, and click "New".
    10.png

  6. Confirm that "saml" has been added to the domain ID, and click "Save".
    11.png

  7. Open "Connection/Authentication > Single Sign-On".
    12.png

  8. Configure the following items and click "Save".
    SAML Integration Select the checkbox
    Target URL The "IdP URL" you noted from TrustLogin
    Certificate

    Convert the file extension of the "Certificate" downloaded from TrustLogin to .crt and upload it


    13.png

  9. Open "User > User".
    15.png

  10. Select the domain "saml", click "New", and add a SAML authentication user. You must set the TrustLogin email address in "User ID". Configure the other items as needed, then click "Add" at the end.
    16.png

  11. Open "User > Named Users".
    14.png

  12. Select the domain "saml" and drag and drop the users you want to allow SAML authentication for from the user list on the left to the named user list on the right.
    17.png

  13. Confirm that the user has been added to the named user list on the right in the format "UserID@saml", then click "Save".18.png

TrustLogin User Settings

① When a User Adds the App via My Page

  1. Click the "Add App" button on "My Page".
  2. On the "App Registration" screen, select "MotionBoard (SAML)" and click the "Next" button at the top right of the screen.
  3. If you want to change the "Display Name", enter it, then click the "Register" button.
  4. Click the app on "My Page" or in the browser extension, and confirm that login is successful.

② When an Administrator Adds Members

  1. Search for and click the "MotionBoard (SAML)" app in the "Admin Page > App" menu.
  2. Click "Add Member", select the user to add from the member list, and click the "Register" button to add them.