ツール一覧 › Sansan
Sansan のアクセス管理機能(SSO・MFA・IP制限・監査ログ)
公式資料によると、Sansan は MFA・SSO・2FA・IP制限・監査ログ に対応しています。(資料の取得日 2026-10-04)
判定(かんたん基準)
Step1:MFA(0.97) / SSO(1.00) + 監査ログ(0.98)|許可 最終|許可
かんたん基準:Step1 は「MFA か SSO」に対応し、かつ監査ログを取得できれば許可。Step2 は「2FA か IP制限」に対応し、かつ監査ログを取得できれば許可。どちらも満たさなければ、個人情報・取引情報・財務情報・機密情報を扱うかどうかで決まります。括弧内は「対応している」確率です。
項目ごとの読み取り
| 項目 | 公式資料の記載 | 確率 | 根拠 |
|---|---|---|---|
| MFA | 対応と記載 | 0.97 | Making two-factor authentication mandatory (security settings) |
| SSO | 対応と記載 | 1.00 | Setting up SAML Authentication |
| 2FA | 対応と記載 | 1.00 | Log in using two-factor authentication (via email) |
| IP制限 | 対応と記載 | 1.00 | IPアドレスによるアクセス制限をする (PC・スマートフォン) [セキュリティ設定] |
| 監査ログ | 対応と記載 | 0.98 | What the Usage log is |
「公式資料に記載なし」は、その要素の公式ページを読んだが記載がなかったもの。「未収集」は、公式ページをまだ見つけられていないもの(機能がないという意味ではありません)。
根拠(公式資料の原文)
SSO:Setting up SAML Authentication – Sansan Support Center
https://jp-help.sansan.com/hc/en-us/articles/900001551383-Setting-up-SAML-Authentication
Setting up SAML Authentication – Sansan Support Center
This feature is a paid option. Please contact our sales team or Sansan Support Center if you would like to use it.
Sansan can work with various IdPs (identity providers) by using external authentication via the SAML 2.0 protocol. This enables login to Sansan with IDs and passwords managed by the IdP.
続きを読む(ほか 60 段落)
IdP setup manuals
You cannot use the Web App for normal login and the Mobile App for SAML authentication. Certificates issued by IdP must be renewed before they expire. Be sure to actively manage them.
SAML authentication integrates authentication information on the IdP with Sansan for login. There is no function to automatically reflect user additions, changes, and deletions on the IdP in Sansan.
Users with SAML authentication enabled will be forcibly logged out of the Mobile App. Consider informing your users of the change in authentication method, and making the change at a suitable time. Note that the Web App does not force a logout because of SAML authentication activation.
IdP-issued certificates must be renewed before they expire. Please be sure to keep track of them.
After completing the operational test in the procedures, the IdP setting can be selected as available for authentication.
The operational test in the procedures is for the Web App only. For testing the Mobile App, try logging in with SAML authentication enabled only for the user who will perform the verification as in "Settings (user-specific)".
A SAML Name ID must be set for each user. See here for how to change user information.
System administrator privileges are required to enable SAML authentication.
Add a new setting from "Admin settings" > "Security settings" > "SAML Authentication" > "Add new IdP setting".
Set a name for your IdP.
Choose the IdP from the "Select IdP" pulldown. If it's not visible, choose "Other". Read about selectable IdPs.
When choosing "Other", select "Single" or "Multiple" Entity ID based on the specifications of the IdP to be used. If you have any questions, please contact the IdP provider.
To use MDM, check "Use".
*If you use Microsoft Intune, etc. device management or access control, place a check here.
Default browser for iOS devices
If you choose to use MDM, you’ll see an option for the default browser on the iOS device.
The default browser will be used to exchange certificates from MDM to IdP. To use another browser, you need to change to ① use a browser other than Safari before you can log in.
If you’re not using Safari, click the ② Back to Sansan button shown after authentication, and return to the app.
Enter the IdP settings.
Check with your IdP provider if you are unsure what to enter. Be sure to enter the settings exactly and without adding extra spaces.
Upload the SAML signing certificate.
The extension will be .cer.
Enter the following settings for IdP side for the signature on the SAML response.
Digest algorithm: either sha-256 or sha-512
Signature algorithm: either rsa-sha-256 or rsa-sha-512
3.Verifying settings
"Start" the test.
Clicking "Start" will automatically redirect to the IdP login screen. Enter your IdP ID and password to authenticate.
If there are no problems with the test, you're good to go.
Please note that saving does not activate the settings.
An IdP setting will be added.
Status shown in the list
The status depends on the IdP configuration when it is saved. Details are as follows.
Setup not completed
The IdP configuration has been completed up to the operational test and is ready for use.
If the test results in an error, the actual SAML response will be displayed on the screen along with an error message instructing you how to modify the Sansan or IdP settings accordingly.
Issues that may arise
IdP identification name is incorrect.
If the IdP name set on the Sansan screen does not match that of the actual SAML response, be sure to correct one of them so they match.
SAML certificate is incorrect.
If there is a problem with the certificate, reissue it and try again.
SAML Name ID is not registered correctly.
The SAML Name ID set in Sansan's user management screen does not match the Name ID in the actual SAML response. Correct one of them so they match.
Cached information may also remain. This can be resolved by deleting the cache or using incognito mode in your browser.
No value has been entered for Audience.
For the IdP Audience value set the identifier as the entity ID.
An unsupported signature algorithm has been specified.
Please specify RSA-SHA-256 or RSA-SHA-512.
In the Sansan SAML authentication settings screen, make sure the information set for the IdP is correct. Also, check that the settings and certificates on the IdP that are set in Sansan are correct. The response URL differs between the Sansan web and app versions. If multiple response URLs can’t be set for an IdP, please contact the respective IdP for the registration method.
When a user cannot log in from the IdP (such as when SAML authentication is mistakenly set), the system admin can log in without transitioning to the IdP and recover their account.
The recovery procedure if SAML authentication becomes unavailable is as follows.
② Enter your Sansan ID and password to log in.
③ After logging in, review the SAML authentication settings or re-upload the certificate.
Q: What can I do if I want to use Microsoft Intune and log in using device certificates, etc.?
A: In Sansan’s IdP settings check the box to use MDM. Device certificate authentication will be enabled, and Safari for iPhone and Google Chrome for Android will be launched. Check the relevant box if you want to use a default browser other than Safari.
Q: What can I do if I get the following message? “Login failed. The information does not match what's registered in Sansan or service may be restricted. SSO may also not be configured. Please contact your system admin with any questions.”
A: Please check for the following likely causes.
1) The email address is incorrect.
Go to “Admin Settings” “Manage users” and check the user’s email address.
MFA:Making two-factor authentication mandatory (security settings) – Sansan Support Center
Making two-factor authentication mandatory (security settings) – Sansan Support Center
Administrators can require all users to use two-factor authentication for added security.
- Two-factor authentication can be setup from the Web App only. Users won't be able to use the Mobile App until they have set up two-factor authentication on the Web App.
続きを読む(ほか 22 段落)
- Admins should notify users prior to requiring two-factor authentication. Any users who haven't set up two-factor authentication will receive an email notification when it becomes effective.
- If SAML authentication is enabled, the screen prompting for two-factor authentication will not show when logging in, because the two types of authentication cannot be used together.
1. Click your name/icon the top right of the Web App. Click Admin Settings then Security settings.
2. Go to Two-factor authentication tab
3. Put a check in Require two-factor authentication. If you want to enable a grace period (so that users are not forcibly logged out immediately), you can do so.
4. Click on OK button to confirm the setting
5. If a grace period is set, an expiration date will be displayed. Once the deadline has expired, all users will be required to set up two-factor authentication.
If use of two-factor authentication is disabled, any newly registered users will be able to log in with only their email and password. Users who have already set up two-factor authentication will be able to disable it from their settings.
Resetting a user's two-factor authentication settings will forcibly log them out of Sansan. For users to disable two-factor authentication, admins must first turn two-factor authentication off.
Was this article helpful?
AIチャットでもサポートさせていただきます
List of categories
Sansan Guide (for general users)
Sansan Guide (for administrator)
Trouble Shootings and Tips for Advanced Usage
Related articles
Log in using two-factor authentication (via an authenticator app)
Logging in to the Sansan Web App; when you have difficulty logging in using SSO (single sign-on)
Processing in and digitizing business card images from Eight
Integration with other systems by using APIs
Using Contact Inbox
If you cannot get the answer to your question from the help site, use the form below to contact us.
2FA:Log in using two-factor authentication (via email) – Sansan Support Center
Log in using two-factor authentication (via email) – Sansan Support Center
You can use two-factor authentication for logging into Sansan to strengthen the account security. Even if the password to the account has been leaked or stolen, unauthorized entrance by third parties can be prevented with two-factor authentication.
If you enable two-factor authentication, when you log in to the following services, in addition to your ID and password, you will be asked for your authentication code.
続きを読む(ほか 59 段落)
Sansan Web App (when using from web browser)
Sansan Smartphone App (iOS/Android)
This page explains two-factor authentication (2FA) using email.
For 2FA using an authenticator app, see the page below.
・ Log in using two-factor authentication (via an authenticator app)
Usage requirements
How to do the settings
Logging in using two-factor authentication
For system administrators: Force disable of two-factor authentication
Troubleshooting
An authentication code will be sent by email. You must be able to receive email at your login email (or secondary email).
As a rule, initial setup can only be done from the Sansan Web App (accessed via a browser). You can also access the Web App from a smartphone, but please note that usability is significantly reduced.
1. Click "Settings", then "Two-factor authentication".
2. Under "Authentication method", click "Email".
3. Send an authentication code.
When you click the "Send authentication code" button, an authentication code will be sent by email. The email will be sent to your login email and, if set up, your secondary email.
4. Confirm the authentication code.
The email sent to your login email contains a 6-digit authentication code.
Return to the Sansan settings page, enter this code in the “2. Confirm authentication code” field, and click the "OK" button.
Please note that the authentication code expires 10 minutes after it is issued.
The settings for two-factor authentication are complete.
When two-factor authentication is enabled, after ID and password authentication in Sansan, you'll be prompted to enter an authentication code.
The code will be sent to your login email (and, if set up, your secondary email). Enter the authentication code shown in the received email.
In the Web App, saving information about the environment in use allows authentication code entry to be bypassed upon the next login (the account remains securely protected).
For system administrators: Force disable of two-factor authentication.
If a user cannot obtain the authentication code for any reason, such as not receiving the email containing the authentication code, the Sansan system administrator can disable two-factor authentication for that user.
Force disabling of two-factor authentication can be done from first going to "Security settings" and then to "Two-factor authentication" from the administrator settings.
If two-factor authentication is made to be required, the button will say "Reset" instead of "Undo".
Please be aware that if an administrator forcibly disables the two-factor authentication of a user, the two-factor authentication for this user will be disabled until the user redoes the authentication settings.
Q: What if I didn't receive the email containing the authentication code?
A: The email is sent to your Sansan login email (and, if set up, your secondary email). The following are possible reasons for not receiving the email.
It was sorted into the spam folder.
Check your email service's spam folder.
Receiving is blocked.
Allow emails from “@sansan.com” and re-send the authentication code.
There's a temporary issue with the mail server or network.
Wait a little while and re-send the authentication code.
If the issue is still not resolved, ask your system administrator to disable two-factor authentication, then log in. You can also try changing the email address used to receive the authentication code. Ask your system administrator to change your login email or secondary email (non-admin users can also change the secondary email).
Q: What should I do if I entered the authentication code, but I cannot proceed because I get the error “Authentication failed. Please confirm the authentication code and re-enter it.”?
A: The following are possible reasons.
The authentication code was entered incorrectly.
The authentication code expired (10 minutes after issuing).
Please check the following in order.
Confirm that the authentication code is entered correctly.
Click "Send authentication code" or "Resend code", then enter the code shown in the email.
Q: What should I do if, after entering the authentication code, I get the error “Use is temporarily restricted because the authentication code was incorrectly entered multiple times. Please try again later.”?
A: This error message is shown when the authentication code is entered incorrectly more than a certain number of times. Wait a little while, then click the "Resend code" button, then try authenticating again using the code received by email.
Q: What if I checked the box to save the currently used device but I'm asked to enter the code every time?
A: You'll be asked to re-enter the code in the following cases:
You've deleted your cache, cookies, history, etc. If your security is set to delete cookies when you close your browser, you’ll be asked each time.
You're logging in with an incognito browser.
You're logging in with a different browser.
Q: Why am I suddenly being asked to do two-factor authentication?
A: Your company may have made this mandatory. For details, see, "Making two-factor authentication mandatory (security settings)".
* iPhone is a trademark of Apple Inc., registered in the U.S. and other countries and regions.
* IOS is a trademark or registered trademark of Cisco in the U.S. and other countries and is used under license.
* Android is a trademark of Google LLC.
Related articles
Log in using two-factor authentication (via an authenticator app)
IP制限:IPアドレスによるアクセス制限をする (PC・スマートフォン) [セキュリティ設定] – Sansanサポートセンター
IPアドレスによるアクセス制限をする (PC・スマートフォン) [セキュリティ設定] – Sansanサポートセンター
ここではIPアドレスによるアクセス制限の設定方法についてご案内します。Sansan は、PC、スマートフォンアプリともにIPアドレス (グローバルIPアドレス) によるアクセス制限を行っていただくことが可能です。
利用には、システム管理者権限が必要になります。
続きを読む(ほか 23 段落)
1. 画面右上 [管理者設定] > その他 [セキュリティ設定] から [IPアドレス制限] のタブをクリックします。
2. [制限する] のチェックボックスを選択します。
3. [アクセスを制限する環境] にて制限したい端末のチェックボックスを選択します。
4. 許可していないIPアドレスからアクセスがあった場合に管理者にメールで通知したい時は、[許可していないIPアドレスからアクセスがあった場合] の [管理者にメールで通知する] のチェックボックスを選択します。
5. 確認メッセージが表示されるので、内容を確認のうえ [OK] をクリックします。
6. [許可するIPアドレス] 欄上の [許可するIPアドレスを追加] をクリックします。
アクセスを許可するIPアドレス帯を編集したい場合は、IPアドレス欄の左側の[編集]から、削除したい場合は右側の [削除] から行ってください。
7. [開始IPアドレス] [終了IPアドレス]、必要に応じて [メモ] を入力し、[保存] をクリックします。
スマートフォンでIPアドレス制限をご利用いただく場合、インターネット環境について条件がございます。詳細につきましては関連ページの箇所よりご確認ください。
許可していないIPアドレスからアクセスがあった場合、以下の件名のメールがシステム管理者に届きます。
件名:【重要】【Sansan】 許可していないIPアドレスからアクセスがありました。
許可していないIPアドレスからアクセスした場合「現在ご利用の環境からのアクセスは許可されていません。」という案内が表示されます。
スマートフォンでIPアドレス制限をご利用いただく場合は[こちら]
AIチャットでもサポートさせていただきます
機能別ガイド(一般ユーザ向け)
トラブルシューティング・便利な使い方 etc...
Scanner App / スキャナー設定
IPアドレス制限をご利用いただく前提について[スマートフォンアプリ]
スマートフォンアプリを利用できる端末を制限する[セキュリティ設定]
スマートフォンアプリのアクセスを制限する[セキュリティ設定]
二要素認証を利用してログインする(認証アプリによる二要素認証)
SAML認証の新規IdP設定の追加[セキュリティ設定]
AIチャットから受け付けています。
監査ログ:What the Usage log is
https://jp-help.sansan.com/hc/en-us/articles/115003828914-What-the-Usage-log-is
What the Usage log is – Sansan Support Center
This feature is a paid option. Please contact our sales team or Sansan Support Center if you would like to use it.
With this function, you can check the operation log of users. This can be used for tasks such as supervision.
続きを読む(ほか 27 段落)
・To use this, it is necessary to have permission to "View Usage Record".
・The log will be recorded from the first day of the contract for this option. Logs from before the current contract period cannot be generated.
・Logs of the current month and the last 12 months can be outputted.
・Logs of more than 14 months ago cannot be output. If you think a log may be necessary, please download it in advance.
・From when the download button is pressed until the file is generated, in some cases it may take more than one day.
・The output format is CSV.
・Time is based on Japan Standard Time (GMT +9 hours).
1. Click on "Admin settings" in the upper right of the screen, then on "Others", "Usage records".
2. Select the "Usage log" tab, then click on "Srart creating log" of the month you wish to output.
3. After the file creation is complete, a notification email will be sent.
Email subject:Creation of the Sansan usage log is complete.
4. After file creation is complete, click on "Download".
For how to give permissions, please see here.
For details of the contents of the file and the event items, please see here.
Was this article helpful?
AIチャットでもサポートさせていただきます
List of categories
Sansan Guide (for general users)
Sansan Guide (for administrator)
Trouble Shootings and Tips for Advanced Usage
Related articles
About each item in the file (Usage log)
Authorizing devices that can use the Mobile App
Processing in and digitizing business card images from Eight
Changing access privileges among departments using a file (access control)
Bulk set up users' Virtual Cards
If you cannot get the answer to your question from the help site, use the form below to contact us.