> For the complete documentation index, see [llms.txt](https://help.impact.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.impact.com/brand/ja/what-would-you-like-to-learn-about/account-administration/account-settings/invite-and-manage-users/enable-saml-single-sign-on.md).

# SAMLシングルサインオンを有効にする

アカウント管理者は有効にできます [SAMLシングルサインオン（SSO）](https://en.wikipedia.org/wiki/Security_Assertion_Markup_Language) アカウントユーザーが、サポートされているアイデンティティプロバイダー（IDP）または一意のサインインリンクを介して、ブランドの impact.com アカウントにアクセスできるようにします。お好みの方法を選択してください。

SAML SSO は、impact.com とお使いのアイデンティティプロバイダーとの接続を使用します。impact.com は現在、次のプロバイダーをサポートしています:

* AD FS
* Okta
* OneLogin
* Microsoft Entra ID

#### SAML SSO を有効にする

{% hint style="warning" %}
**警告:** すでに SAML SSO が有効になっていてプロバイダーを切り替えたい場合は、テクニカルサービスチームのサポートが必要です。 [チケットを起票する](https://impact.atlassian.net/servicedesk/customer/portal/6/group/1088)前に、既存の IDP メタデータファイルをローカルデバイスに保存し、移行が必要なユーザー名の一覧を準備してください。
{% endhint %}

{% stepper %}
{% step %}

#### **ステップ 1: IDP メタデータファイルをアップロード**

開始する前に、 **IDP メタデータファイル** の .XML 形式のものを用意してください。このファイルを impact.com にアップロードする必要があります。

1. 上部のナビゲーションバーから、 ![](/files/173ecabf39fd91e83f3ac16fba44d8e9c845708d) **\[ユーザープロフィール] → \[設定]**.
2. 左側の列で、 *一般、* 次を選択します **アカウントユーザー認証**.
3. の横にある *認証タイプ* 項目で、 ![](/files/fd83586f9930f6bcc6498179e6d7ed9571e7b572) **\[チェックボックス] SAML** を選択し、 ![](/files/cc0e0c914e83aa8f319848b79c16bfc4d16c9e94) **\[ドロップダウンメニュー]** を使用してアイデンティティプロバイダーを選択します。
4. ファイルピッカーを使用して見つけ、 **.XML メタデータファイルをアップロードします**.
5. 画面下部で、 **保存**.

<div data-with-frame="true"><figure><img src="/files/d665cea290070ed6adabaea6c6ad1ac487bdae9a" alt="" width="563"><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

#### **ステップ 2: アカウントユーザー向けに SAML SSO を有効化**

SAML SSO を使用する各ユーザーについて、次の手順を完了する必要があります:

1. 上部のナビゲーションバーから、 ![](/files/173ecabf39fd91e83f3ac16fba44d8e9c845708d) **\[ユーザープロフィール] → \[設定]**.
2. 左側の列で、 *一般* を選択し **アカウントユーザー**.
3. ユーザーにカーソルを合わせて、 **\[詳細] → アクセス権を編集**
4. 〜で *ユーザー登録方法* セクションで、選択します **SAML**.
5. スライドアウトの下部で、 **保存**.

<div data-with-frame="true"><figure><img src="/files/85848564089c9dff07c6119befce8b6adcfa52a4" alt=""><figcaption></figcaption></figure></div>
{% endstep %}

{% step %}

#### **ステップ 3: SAML SSO を介したユーザーサインインを設定**

ユーザーが SAML SSO で impact.com にアクセスする方法は 2 つあります:

* **アイデンティティプロバイダー（IDP）経由** — IDP で接続／コネクタを設定し、それを使用してユーザーをサインインさせます。
* **ブランド独自のログインリンク経由** — IDP 接続経由でサインインしないユーザー向けです。

**オプション A: アイデンティティプロバイダーでのサインイン**

* **OneLogin** — OneLogin で、 *Impact Partnership Cloud* 接続を *OneLogin アプリカタログ* で見つけ、画面の指示に従ってアプリを有効化および設定します。
* **ADFS、Okta、Microsoft Entra ID** — 次の正確な値を指定して新しいカスタム接続を作成します:

  | 項目                                  | 入力する値                             |
  | ----------------------------------- | --------------------------------- |
  | シングルサインオン URL / Reply URL / ACS URL | <https://app.impact.com/saml/SSO> |
  | Recipient URL                       | <https://app.impact.com/saml/SSO> |
  | Destination URL                     | <https://app.impact.com/saml/SSO> |
  | Audience Restriction                | <https://app.impact.com>          |
  | Name ID 形式                          | EmailAddress                      |
  | 応答                                  | 署名済み                              |
  | アサーション署名                            | 署名済み                              |
  | 署名アルゴリズム                            | RSA\_SHA1                         |
  | ダイジェスト署名                            | SHA1                              |
  | アサーション暗号化                           | 暗号化なし                             |
  | SAML シングルログアウト                      | 無効                                |
  | AuthnContextClassRef                | PasswordProtectedTransport        |
* **Microsoft Entra ID** — 次の正確な値を指定して新しいカスタム接続を作成します:

  | 項目                                                      | 入力する値                             |
  | ------------------------------------------------------- | --------------------------------- |
  | Reply URL（アサーション消費者サービス URL）                            | <https://app.impact.com/saml/SSO> |
  | Reply URL（暗黙的）                                          | <https://app.impact.com/saml/SSO> |
  | 識別子（エンティティ ID）                                          | <https://app.impact.com>          |
  | Name identifier format（詳細設定 → 「Name identifier format」） | EmailAddress                      |
  | 応答署名オプション（SAML 応答に署名）                                   | 署名済み                              |
  | SAML アサーションに署名（オプション）                                   | 署名済み                              |
  | 署名アルゴリズム                                                | RSA\_SHA1                         |
  | ダイジェストアルゴリズム                                            | SHA1                              |
  | 暗号化証明書（オプション）                                           | 暗号化なし                             |
  | シングルログアウト URL                                           | 無効                                |
  | デフォルトの AuthnContextClassRef（直接は表示されません）                 | PasswordProtectedTransport        |

入力する値は、上記で指定された値と完全に一致している必要があります。たとえば、末尾にスラッシュを追加しないでください。 *シングルサインオン URL / Reply URL / ACS URL* このフィールドでは次のようにします: `https://app.impact.com/saml/SSO`**`/`**&#x8907;数の URL 値を入力しないでください。また、IDP のユーザーのメールアドレスが impact.com のユーザーのメールアドレスと完全に一致していることも確認してください。

**オプション B: ブランドリンクでのサインイン**

ユーザーが IDP 経由でサインインしない場合は、一意のブランド付きログインリンクを使用して impact.com アカウントにアクセスできます。このログインリンクを取得するには:

1. 上部のナビゲーションバーから、 ![](/files/173ecabf39fd91e83f3ac16fba44d8e9c845708d) **\[ユーザープロフィール] → \[設定]**.
2. 左側の列で、 *ブランディング*、選択します **広告主ログインのブランディング**.
   * ブランド付きリンクは次のようになります: `https://app.impact.com/abe/Stark-Industries12345678912345/login.user?preview=t`
3. 〜から *ログインリンク* フィールドの内容をコピーして保存し、 *ログインリンク* impact.com アカウントのメンバーに配布してください。

{% hint style="warning" %}
**重要:** このブランド付きログインリンクの用途は、ユーザーが IDP を使用していないときに impact.com に直接サインインできるようにすることだけです。このリンクを IDP の *Single Sign-On URL / Reply URL / ACS URL* フィールド。
{% endhint %}
{% endstep %}
{% endstepper %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.impact.com/brand/ja/what-would-you-like-to-learn-about/account-administration/account-settings/invite-and-manage-users/enable-saml-single-sign-on.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
