Okta

How to Configure SAML 2.0 for Zoho One

Contents


Supported Features

The Okta/Zoho One SAML integration currently supports the following features:


Configuration Steps

  1. Download and save the following certificate as okta.cert:

    Sign into the Okta Admin Dashboard to generate this variable.

  2. Login to Zoho Accounts at https://accounts.zoho.com/ as a user with administrative rights.

  3. Select Preferences:

    zoho1.png

  4. Select SAML authentication, then click Setup Now:

    zoho2.png

  5. Enter the following (see screenshot at end of step for reference):

    • Login URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Logout URL: Copy and paste the following:

      Sign into the Okta Admin Dashboard to generate this variable.

    • Do you need Logout Response?: Check this box.

    • Change Password URL: Leave this blank.

    • Public Key: Click Get Key from file link, then use the Choose File button to locate and upload the okta.cert file you saved in step 1.

    • Algorithm: Leave RSA in this field.

    • Just In Time Provisioning: Uncheck this box. Just In Time Provisioning is currently not supported by Zoho One.

    • Zoho Service: Leave Accounts in this field.

    • Click Add.

    zoho3.png

  6. Click Download to save the Logout Certificate.

  7. Click Download to save the Metadata file.

  8. zoho4.png

  9. Open the Metadata file you just downloaded (step 7) in a text editor.

    • Search for the AssertionConsumerService parameter.

    • Save the last part of the URL in the Location attribute. This is your Domain value.

      For example, if your AssertionConsumerService URL is is https://accounts.zoho.com/samlresponse/123456, then your Domain value is 123456.

    zoho5.png

  10. In Okta, select the General tab for the Zoho One app, then click Edit.

    • Enter your Domain value (step 8) into the corresponding field.

    • Click Save.

    zoho6.png

  11. Still in Okta, select the Sign On tab for the Zoho One app, then click Edit.

    • Default Relay State: Enter https://one.zoho.com.

    • Enable Single Logout: Check this box.

    • Signature Certificate: Click Browse to locate the Logout Certificate you downloaded in step 6, then click Upload.

    • Click Save.

    zoho7.png

  12. Done!


Notes

SP-initiated SSO

  1. Open the following URL: https://www.zoho.com/one/.

  2. Click Login.

  3. Enter a valid Email ID and a dummy password.

  4. Click Sign in.

  5. zoho8.png