{"templateId":"markdown","sharedDataIds":{"sidebar":"sidebar-@l10n/ja/sidebars.yaml"},"props":{"metadata":{"markdoc":{"tagList":["admonition"]},"type":"markdown"},"seo":{"title":"シングルサインオン","description":"SSO機能をIDプロバイダーと併用することで、Treasure アカウントのユーザーが単一のIDで複数のTreasure アカウントにログインできるようになります。","siteUrl":"https://docs.treasure.ai","lang":"en-US","jsonLd":{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://www.treasure.ai/","name":"Treasure AI","url":"https://www.treasure.ai/","logo":"https://www.treasure.ai/hubfs/assets/images/logos/primary-logo.svg"},{"@type":"WebSite","@id":"https://docs.treasure.ai/#website","name":"Treasure AI Documentation","url":"https://docs.treasure.ai/","inLanguage":["en","ja"],"publisher":{"@id":"https://www.treasure.ai/"}}]},"llmstxt":{"hide":false,"sections":[{"title":"Table of contents","includeFiles":["**/*"],"excludeFiles":[]}],"excludeFiles":[]}},"dynamicMarkdocComponents":[],"compilationErrors":[],"ast":{"$$mdtype":"Tag","name":"article","attributes":{},"children":[{"$$mdtype":"Tag","name":"Heading","attributes":{"level":1,"id":"シングルサインオン","__idx":0},"children":["シングルサインオン"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["SSO機能をIDプロバイダーと併用することで、Treasure アカウントのユーザーが単一のIDで複数のTreasure アカウントにログインできるようになります。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["フェデレーションIDとは、1つのID管理システムに保存され、複数のシステムへのアクセス検証に使用される個人の電子IDおよび属性として定義されます。Treasure Dataでは、フェデレーションIDはTreasure コンソールへの安全なアクセスに使用されます。Treasure Dataは、IDフェデレーションを使用してシステム間をシームレスに移動できるようにすることで、お客様のアカウント情報のセキュリティを確保します。さらに、IP許可リストを使用して、特定のTreasure アカウントへのアクセスを制限することもできます。"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"sso設定","__idx":1},"children":["SSO設定"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["各Treasure アカウントには、固有のデータセットとそのアカウントに関連付けられたユーザーセットがあります。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["例えば、開発アカウント、テストアカウント、本番アカウントのように、3つのTreasure アカウントを持っている場合があります。複数のフェデレーションIDを使用するか、すべてのTreasure アカウントに1つのIDとパスワードのみを使用するかを選択できますが、ログインポリシーが遵守されていることも確認する必要があります。IdPは、ユーザー認証のセキュアなアクセスポリシーを実施します。IdPでユーザーを定義し、Treasure Dataを認可されたターゲットアプリケーションとして定義します。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Treasure Dataユーザーを認証し、ユーザーのサインインポリシーを制御するために複数のIDプロバイダー（IdP）を設定するオプションがありますが、1つのIdPがプライマリとなります。"]},{"$$mdtype":"Tag","name":"Admonition","attributes":{"type":"info"},"children":[{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["複数のIdPを有効にするには、カスタマーサクセス担当者にお問い合わせください。"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["Treasure アカウントでSSO設定が有効になると、Google SSOログイン方法は無効になります。"]}]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/idp.21463a128a07a18261eff9510af57fd7eb14c12683dde0309ad1b947059ad899.f0cddcd7.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["SSOは、オンプレミスとクラウドの両方のアプリケーションに対して、セキュリティの強化と厳格な認証を提供します。企業のディレクトリサービスを通じて、すべてのユーザーとそれぞれの権限を一元管理できます。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["SSOは、Azure Active DirectoryなどのSAML 2.0プロトコルを使用するIdPをサポートしています。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["アカウントでSSO機能を有効にする場合は、カスタマーサクセス担当者にお問い合わせください。"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"シングルサインオンの設定","__idx":2},"children":["シングルサインオンの設定"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["SSOの設定には、以下の領域での作業が必要です。"]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Identity Provider（IdP）環境での設定（IdP管理者が実施）"]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Treasure コンソールでの設定（Treasure アカウントオーナーまたは管理者が実施）"]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"identity-provider管理者","__idx":3},"children":["Identity Provider管理者"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["IdP環境で、承認されたアプリケーションのリストにTreasure Dataを追加します。複数のIdPとサインイン方式を表示および設定できます。IdPでは、各Treasure アカウントが個別のアプリケーションとして追加されます。必要に応じて、Treasure Dataアプリケーションにユーザーを割り当てます。"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"treasure-アカウントオーナーまたは管理者","__idx":4},"children":["Treasure アカウントオーナーまたは管理者"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Treasure アカウントオーナーまたは管理者として、信頼設定を構成し、ユーザーにSSOアクセスを割り当てます。各Treasure アカウントで信頼設定を構成します。信頼設定は、Treasure コンソールまたはTreasure APIを使用して構成できます。Treasure APIのサポートについては、カスタマーサクセス担当者にお問い合わせください。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["SSOが有効になっている各Treasure アカウントには、Treasure Data内で一意の名前が割り当てられます。割り当てられた名前は、IdP構成で使用されます。このIDは編集できません。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/image2023-8-3_12-27-56.ad8173c48bcf6b8000012599d509fd040ed382e79c619f9dca8a9f62925d6069.f0cddcd7.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["詳細な設定手順については、",{"$$mdtype":"Tag","name":"MarkdownLink","attributes":{"href":"/ja/products/control-panel/security/sign-in-settings/configuring-sso-in-td-console"},"children":["Treasure コンソールでのSSO設定"]},"を参照してください。"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":2,"id":"よくある質問","__idx":5},"children":["よくある質問"]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"ssoで設定された両方のアカウントで同じ会社のメールアドレスを使用できますか","__idx":6},"children":["SSOで設定された両方のアカウントで同じ会社のメールアドレスを使用できますか？"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["はい。SSOで設定された複数のアカウントに単一のメールアドレスを使用するには、以下の2つの条件を満たす必要があります。"]},{"$$mdtype":"Tag","name":"ol","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["サポートは、顧客がConsole URLに添付するAWSアカウント名を共有できます"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["aws:1XXX9 - ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["abcde12345abcde12345"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["https://console.us01.treasuredata.com/users/initiate_sso?account_name=abcde12345abcde12345"]}]}]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":[{"$$mdtype":"Tag","name":"p","attributes":{},"children":["aws:1XXX2 - ",{"$$mdtype":"Tag","name":"strong","attributes":{},"children":["11aa22bb33cc44dd55ee"]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["https://console.us01.treasuredata.com/users/initiate_sso?account_name=11aa22bb33cc44dd55ee"]}]},{"$$mdtype":"Tag","name":"ol","attributes":{"start":2},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["IdPアカウント名はアカウントごとに異なる必要があります。その場合、顧客は両方のアカウントに同じメールアドレスを使用できます。"]}]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":[{"$$mdtype":"Tag","name":"img","attributes":{"src":"/assets/single-sign-on-configuration-overview-2024-05-23.4c91da2fc53a15b3c8a4b7d9d6170f820b1702202317de00a8af03921bc3d1d0.f0cddcd7.png","alt":""},"children":[]}]},{"$$mdtype":"Tag","name":"ul","attributes":{},"children":[{"$$mdtype":"Tag","name":"li","attributes":{},"children":["このルートを選択しない場合、2つの異なるアカウントに対して異なるメールアドレスで同じユーザーを作成する唯一の方法は、アカウントごとにメールエイリアスを作成することです。例：tina+prod@example.com と tina+testing@example.com"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["顧客が選択するIdPは、メールアドレスの「+」記号をサポートする必要があります。"]},{"$$mdtype":"Tag","name":"li","attributes":{},"children":["メールアドレスが同じでも、user_idはユーザーごとに異なるため、監査ログには影響しません。"]}]}]}]},{"$$mdtype":"Tag","name":"Heading","attributes":{"level":3,"id":"ユーザーのssoサインイン方法を変更できるのは誰ですか","__idx":7},"children":["ユーザーのSSOサインイン方法を変更できるのは誰ですか？"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["仕様上、Administratorのサインイン方法を変更できるのはそのユーザー本人のみです。OwnerであってもほかのAdministratorのSSO設定を直接変更することはできません。"]},{"$$mdtype":"Tag","name":"p","attributes":{},"children":["Restricted Userのサインイン方法は、OwnerまたはAdministratorが制限なく変更できます。"]}]},"headings":[{"value":"シングルサインオン","id":"シングルサインオン","depth":1},{"value":"SSO設定","id":"sso設定","depth":2},{"value":"シングルサインオンの設定","id":"シングルサインオンの設定","depth":2},{"value":"Identity Provider管理者","id":"identity-provider管理者","depth":3},{"value":"Treasure アカウントオーナーまたは管理者","id":"treasure-アカウントオーナーまたは管理者","depth":3},{"value":"よくある質問","id":"よくある質問","depth":2},{"value":"SSOで設定された両方のアカウントで同じ会社のメールアドレスを使用できますか？","id":"ssoで設定された両方のアカウントで同じ会社のメールアドレスを使用できますか","depth":3},{"value":"ユーザーのSSOサインイン方法を変更できるのは誰ですか？","id":"ユーザーのssoサインイン方法を変更できるのは誰ですか","depth":3}],"frontmatter":{"seo":{"title":"シングルサインオン","description":"SSO機能をIDプロバイダーと併用することで、Treasure アカウントのユーザーが単一のIDで複数のTreasure アカウントにログインできるようになります。"}},"lastModified":"2026-06-16T07:07:05.000Z","pagePropGetterError":{"message":"","name":""}},"slug":"/ja/products/control-panel/security/sign-in-settings/single-sign-on","userData":{"isAuthenticated":false,"teams":["anonymous"]},"isPublic":true}