Hello there!

Need Help? We are right here!

Support Icon
miniOrange Email Support
success

Thanks for your Enquiry. Our team will soon reach out to you.

If you don't hear from us within 24 hours, please feel free to send a follow-up email to info@xecurify.com

Search Results:

×

Configure Zoho as SAML IDP for SSO


miniOrange Identity Broker service solution enables cross protocol authentication. You can configure Zoho as an IDP for Single Sign-On (SSO) into your applications/websites. Here, Zoho will act as an Identity Provider (IDP) and miniOrange will act as a broker.

We offer a pre-built solution for integrating with Zoho, making it easier and quick to implement. Our team can also help you set up Zoho as SAML IDP to login into your applications.

Connect with External Source of Users


miniOrange provides user authentication from various external sources, which can be Directories (like ADFS, Microsoft Active Directory, OpenLDAP, AWS etc), Identity Providers (like Microsoft Entra ID, Okta, AWS), and many more. You can configure your existing directory/user store or add users in miniOrange.



Prerequisite:

  • To get started you need to have an active Zoho account with administrator rights for your organization.
  • Go to miniOrange Admin console and navigate to Identity Providers in the left navigation menu. Then, click on Add Identity Provider button.
  • Zoho as IDP :  Add Identity Provider

  • In Choose Identity Provider, select SAML from the dropdown.
  • Zoho as IDP :  Select SAML from dropdown

  • Search for Zoho in the list. If you don’t find it, search for SAML Provider and set up your application there.
  • Zoho as IDP :  Search Entra ID

  • Now click on the Click here link to get miniOrange metadata as shown in Screen below.
  • Zoho as IDP : Get metadetails to configure salesforce SAML IDP

  • For SP -INITIATED SSO section, select Show Metadata Details.
  • Zoho as ID: SP intiated Metadata

  • Keep ACS URL, Single Logout URL and Entity ID or Issuer which you will require in Zoho console in Step 1.
  • Configure Zoho Single Sign-On (SSO)

  • To setup branding, go to the Customization section from the left navigation bar.
  • In Basic Settings, set the Organization Name of your choice.
  • Click Save. Once that is set, the branded login URL would be of the format https://<custom_domain>.xecurify.com/moas/login
  • 2FA Two-Factor authentication for Fortinet Fortigate : setting up branding

Steps to setup Zoho as an IDP and miniOrange as a Service Provider (SP) for SSO login

1. Configure miniOrange as Service Provider (SP) in Zoho

  • Login to your Zoho domain as an Account Administrator.
  • Go to the Applications tab from the left navigation bar.
  • Click on Add application button on the top right corner.
  • Zoho Single Sign On (SSO) authentication

  • On the top right corner, click on Create Custom App.
  • Zoho Single Sign On (SSO) select saml

  • Enter Display Name.
  • From SSO Mode, select SAML from the dropdown.
  • Zoho Single Sign On (SSO) select saml

  • Enter the SP metadata details that you saved from miniOrange:
  • Sign-In URL Paste the SSO Login URL that you copied from the miniOrange SP metadata section
    Sign-Out URL Paste the SSO Logout URL that you copied from the miniOrange SP metadata section
    Assertion Consumer Service URL Paste the ACS URL that you copied from the miniOrange SP metadata section
    Issuer Paste the EntityID that you copied from the miniOrange SP metadata section
  • Click on the Done button. miniOrange is successfully saved as a SP in Zoho.
  • Zoho Single Sign On (SSO) select saml

  • Now click on the application that you created. Go to the Single Sign-On tab >> Identity Provider Details. Click on the Download IDP Metadata. This you will require while configuring Zoho as an IDP in the miniOrange console.
  • Zoho Single Sign on (SSO) configured settings

2. Configure Zoho as Identity Provider (IDP) in miniOrange

  • Go to miniOrange Admin console and navigate to Identity Providers in the left navigation menu. Then, click on Add Identity Provider button.
  • Zoho as IDP :  Add Identity Provider

  • In Choose Identity Provider, select SAML from the dropdown.
  • Zoho as IDP :  Select SAML from dropdown

  • Search for SAML Provider.
  • Zoho as IDP :  Search SAML

  • Click on Import IDP metadata.
  • OneLogin as IDP: Select SAML and Import IDP Metadata

  • Enter Zoho as IDP name. Browse and upload the file downloaded from Zoho.
  • Click on Import.
  • Zoho SSO

  • As shown in the below screen the IDP Entity ID, SAML SSO Login URL and x.509 Certificate will be filled from the Metadata file we just imported.
  • Zoho SSO

  • Click Save.
  • Enable the toggle button Enable for Enduser Login.
  • Configure Zoho Single Sign-On (SSO)

  • Click on Save.

3. Test SSO Configuration

Test SSO login to your miniOrange account with Zoho IDP:

    Using SP-Initiated Login

    • Go to your miniOrange branded login URL. Here you will be either asked to enter the username or click on the SSO link (Login with Zoho) which will redirect you to the Zoho IdP Sign-On Page.
    • Zoho Single Sign-On (SSO): SP-Initiated login

    • Enter your miniOrange login credentials and login. You will be automatically logged in to your miniOrange dashboard.
    • Zoho Single Sign-On (SSO): SP-Initiated login

    Using IDP Initiated Login

    • For IDP-initiated login, you need to have IDP-initiated metadata values from the miniOrange. For this, go back to the miniOrange dashboard >> Identity Providers >> Select Metadata against your IDP.
    • Zoho Single Sign-On (SSO) verify configuration

    • Click on Show Metadata details in FOR IDP - INITIATED SSO section and copy the ACS URL. This you will require in Zoho console.
    • Zoho Single Sign-On (SSO) verify configuration

    • Go back to the Zoho admin console and then Applications tab from the left navigation bar.
    • Click on the application that you created (In our case: miniOrange), to verify the SSO configuration.
    • Click on Single Sign-On tab >> Service Provider.
    • Paste the ACS URL in the Assertion Consumer Service URL field that you copied from the miniOrange in the previous step and save the settings.
    • Zoho Single Sign-On (SSO) verify configuration

    • Go to the User Home from the left navigation bar and click on miniOrange app.
    • Zoho Single Sign-On (SSO) login

    • You will be successfully logged into the miniOrange dashboard.

    Not able to configure or test SSO?

    Contact us or email us at idpsupport@xecurify.com and we'll help you setting it up in no time.



Configure Attribute Mapping

  • Go to Identity Providers.
  • Click the three dots in the Actions menu, and select Attribute Mapping against the Identity Provider (IDP) you configured.
  • Zoho Single Sign-On SSO Select and Configure Attribute Mapping


Maps information, such as email and username, during Just-In-Time (JIT) user creation. Email and Username attributes are necessary to create the user profile.

  • Click on the + Add Attribute button to add the attribute fields.
  • Zoho Single Sign-On SSO Map USER Attribute

  • Check the attributes in the Test Connection window from the previous step. Choose any attribute names you want to send to your application under Attribute Name sent to SP.
  • Enter the values of the attributes coming from IdP into the Attribute Name from IdP field on the Xecurify side.

EXTERNAL mappings help alter incoming attribute names before sending them to apps, ensuring that the data is in the correct format.

  • Click on the + Add Attribute button to add the attribute fields.
  • Zoho Single Sign-On SSO Map EXTERNAL Attribute

  • Check attributes in test connection window from last step. Enter the attribute names (any name) that you want to send to your application under Attribute Name sent to SP.
  • Enter the value of attributes that are coming from IdP into the Attribute Name from IdP field on the Xecurify side.

Configure Multiple IDPs:

You can follow this guide, if you want to configure multiple IDPs (Identity Providers) and give users the option to select the IDP of their choice to authenticate with.


External References

Want To Schedule A Demo?

Request a Demo
  



Our Other Identity & Access Management Products