we've gone through some back and forth while setting up SAML SSO for Zoho One with Azure AD (MS 365).
it is quite a common case that enterprises want to use their existing MS auth instead of Zoho password and I think the docs would benefit from some improvements.
- while this page is a nice and detailed guide, for One admins it's generally better to follow the second method detailed in...
- this method is more flexible as one can enable SAML for individual users or groups.
suggestions:
- the first two documentation sources should be interlinked
- it's even easy / possible to lock yourself out when following the steps in 1// as it instantly enables SAML for everyone in the org. if you want to disable SAML afterwards you'll have to go through the (new) SAML flow. if there is something incorrect in your config (e. g. SAML certificate) all users end up being locked out including the super admin which ends up in a loop if wanting to disable SAML. Zoho might want to rethink this case from a product perspective.
- the information on MS hosted docs is slightly different in creating the SSO App in Azure, any chance to unify this?
hope this helps.