> For the complete documentation index, see [llms.txt](https://help.impact.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.impact.com/brand/ja/what-would-you-like-to-learn-about/account-administration/account-settings/invite-and-manage-users/enable-saml-single-sign-on.md).

# SAML シングルサインオンを有効化する

アカウント管理者は有効にできます [SAMLシングルサインオン（SSO）](https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language) アカウントユーザーが、対応しているIDプロバイダー（IDP）または固有のサインインリンクを通じて、あなたのブランドのimpact.comアカウントにアクセスできるようにします。お好みの方法を選択してください。

SAML SSOでは、impact.comとIDプロバイダーを接続します。impact.comは現在、以下のプロバイダーをサポートしています：

* AD FS
* Okta
* OneLogin
* Microsoft Entra ID

#### SAML SSOを有効にする

{% hint style="warning" %}
**警告：** すでにSAML SSOを有効にしていてプロバイダーを切り替えたい場合は、テクニカルサービスチームの支援が必要です。その前に [チケットを起票する](https://impact.atlassian.net/servicedesk/customer/portal/6/group/1088)、既存のIDPメタデータファイルをローカルデバイスに保存し、移行が必要なユーザー名の一覧を準備してください。
{% endhint %}

{% stepper %}
{% step %}

#### **ステップ1：IDPメタデータファイルをアップロード**

開始する前に、次のものを用意してください： **IDPメタデータファイル** を.XML形式で手元に用意してください。このファイルをimpact.comにアップロードする必要があります。

1. 上部のナビゲーションバーから ![](https://1458456015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2F210dEQa93qyQgoJDkieL%2FUser%20profile.svg?alt=media\&token=f84c5b17-fae4-4a30-990a-9de5e57a150b) **\[ユーザープロフィール] → 設定**.
2. 左側の列の *一般、* 選択 **アカウントユーザー認証**.
3. の横にある *認証タイプ* の項目で、次を選択します： ![](https://1458456015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-b5e1740618ed6571d97b8fed7c25a7678f85d375%2F299632fb6f4f91fbf9847471754cc6180e4284a65b4960af4c4ea472a159f552.svg?alt=media) **\[チェックボックス] SAML** であるかを指定し、 ![](https://1458456015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2Fgit-blob-df93ac0f80fc5cece7983980a5ce3fbcf19aabce%2F3ef9d737089bc07dbb7e4fd41a97edfbaec261e4f55ab3a1666f3daf957f69c3.svg?alt=media) **\[ドロップダウンメニュー]** を選択して、IDプロバイダーを指定します。
4. ファイルピッカーを使用して見つけ、 **XMLメタデータファイルをアップロードします**.
5. 画面下部で、次を選択してください **保存**.

<div data-with-frame="true"><figure><img src="https://1458456015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2FxmP4vAfVX0qeE1RNgLUv%2FScreenshot%202026-04-16%20at%2010.52.21.png?alt=media&amp;token=cb6aa481-a1cd-4d11-8d00-30ca4d1dc5d7" alt="" width="563"><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

#### **ステップ2：アカウントユーザーのSAML SSOを有効にする**

以下の手順は、SAML SSOを使用する各ユーザーごとに完了する必要があります：

1. 上部のナビゲーションバーから ![](https://1458456015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2F210dEQa93qyQgoJDkieL%2FUser%20profile.svg?alt=media\&token=f84c5b17-fae4-4a30-990a-9de5e57a150b) **\[ユーザープロフィール] → 設定**.
2. 左側の列で、次へ移動します： *全般* を選択し **アカウントユーザー**.
3. ユーザーにカーソルを合わせて、次を選択します： **\[詳細] → アクセス権を編集**
4. の中で *ユーザー登録方法* セクションで、 **SAML**.
5. スライドアウトの下部で、次を選択します： **保存**.

<div data-with-frame="true"><figure><img src="https://1458456015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2FsnYUet3HzxHTSStNVDx9%2FScreenshot%202026-04-16%20at%2011.03.26.png?alt=media&amp;token=087a8479-7021-4f86-94ca-037090e216b0" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

#### **ステップ3：SAML SSOによるユーザーサインインを設定する**

ユーザーがSAML SSOでimpact.comにアクセスする方法は2通りあります：

* **IDプロバイダー（IDP）経由** — IDPで接続/コネクタを設定し、それを使ってユーザーをサインインさせます。
* **ブランド固有のログインリンク経由** — IDP接続経由でサインインしないユーザー向けです。

**オプションA：IDプロバイダーによるサインイン**

* **OneLogin** — OneLoginで次を見つけます： *Impact Partnership Cloud* 接続を *OneLoginアプリカタログ* を開き、画面の指示に従ってアプリを有効化して設定します。
* **ADFS、Okta、Microsoft Entra ID** — 次の値をそのまま使用して、新しいカスタム接続を作成します：

  | 項目                             | 入力する値                             |
  | ------------------------------ | --------------------------------- |
  | シングルサインオンURL / 応答URL / ACS URL | <https://app.impact.com/saml/SSO> |
  | 受信者URL                         | <https://app.impact.com/saml/SSO> |
  | 送信先URL                         | <https://app.impact.com/saml/SSO> |
  | 対象者制限                          | <https://app.impact.com>          |
  | Name ID形式                      | EmailAddress                      |
  | Response                       | 署名あり                              |
  | アサーション署名                       | 署名あり                              |
  | 署名アルゴリズム                       | RSA\_SHA1                         |
  | ダイジェスト署名                       | SHA1                              |
  | アサーション暗号化                      | 暗号化なし                             |
  | SAMLシングルログアウト                  | 無効                                |
  | AuthnContextClassRef           | PasswordProtectedTransport        |
* **Microsoft Entra ID** — 次の値をそのまま使用して、新しいカスタム接続を作成します：

  | 項目                                    | 入力する値                             |
  | ------------------------------------- | --------------------------------- |
  | 応答URL（アサーションコンシューマサービスURL）            | <https://app.impact.com/saml/SSO> |
  | 応答URL（暗黙的）                            | <https://app.impact.com/saml/SSO> |
  | 識別子（Entity ID）                        | <https://app.impact.com>          |
  | 名前識別子の形式（詳細設定 → 「名前識別子の形式」）           | EmailAddress                      |
  | 応答の署名オプション（SAML応答に署名する）               | 署名あり                              |
  | SAMLアサーションに署名（オプション）                  | 署名あり                              |
  | 署名アルゴリズム                              | RSA\_SHA1                         |
  | ダイジェストアルゴリズム                          | SHA1                              |
  | 暗号化証明書（任意）                            | 暗号化なし                             |
  | シングルログアウトURL                          | 無効                                |
  | デフォルトのAuthnContextClassRef（直接表示されません） | PasswordProtectedTransport        |

入力する値は、上記の値と完全に一致している必要があります。たとえば、末尾にスラッシュを追加しないでください。 *シングルサインオンURL / 応答URL / ACS URL* このようにフィールドに入力します： `https://app.impact.com/saml/SSO`**`/`**&#x307E;た、複数のURL値を入力しないでください。さらに、IDP内のユーザーのメールアドレスが、impact.com上のユーザーのメールアドレスと完全に一致していることを確認してください。

**オプションB：ブランドリンクによるサインイン**

ユーザーがIDP経由でサインインしない場合は、固有のブランドログインリンクを使ってimpact.comアカウントにアクセスできます。このログインリンクを取得するには：

1. 上部のナビゲーションバーから ![](https://1458456015-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FwMLlMoFBtKJa8ptd3zaw%2Fuploads%2F210dEQa93qyQgoJDkieL%2FUser%20profile.svg?alt=media\&token=f84c5b17-fae4-4a30-990a-9de5e57a150b) **\[ユーザープロフィール] → 設定**.
2. 左側の列の *ブランディング*、次を選択します **広告主ログインのブランディング**.
   * ブランドリンクは次のような形式になります： `https://app.impact.com/abe/Stark-Industries12345678912345/login.user?preview=t`
3. 〜から *ログインリンク* フィールドをコピーして保存します： *ログインリンク* をimpact.comアカウントのメンバーに配布します。

{% hint style="warning" %}
**重要：** このブランドログインリンクは、IDPを使用していないときにユーザーがimpact.comへ直接サインインできるようにするためだけに使用します。このリンクをIDPの *シングルサインオンURL / 応答URL / ACS URL* フィールドに含めてください。
{% endhint %}
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.impact.com/brand/ja/what-would-you-like-to-learn-about/account-administration/account-settings/invite-and-manage-users/enable-saml-single-sign-on.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
