Accessing Zoho via Okta using SAML

Accessing Zoho via Okta using SAML

You can configure SAML-based SSO with Okta as your identity provider (IdP) to let your users sign in to Zoho.

Required items from Okta

You will need the following items from Okta to configure SAML in Zoho. You can follow the configuration steps to get these from Okta.
  1. Identity Provider Single Sign-On URL
  2. X.509 Certificate

Steps to configure SAML

  1. Sign in to your Okta Admin Console.
  2. Click Applications in the left menu, then click Applications.
  3. Click Create App Integration, select SAML 2.0, then click Next.
  4. Enter a name for the app in the App Name field, then click Next.
  5. In the Single sign on URL field and the Audience URI field, enter the following dummy values. You can replace these with the actual values later.
    Single sign on URL
    Audience URI
    zylker.com

  6. In the Name ID Format field, select EmailAddress.
  7. Scroll down and click Next.
  8. Select I'm an Okta customer adding an internal app, then click Finish.
  9. In the next page, go to the Sign On tab.
  10. Under Settings, click View Setup Instructions. A new page containing the IdP information will open.
  11. Copy the Identity Provider Single Sign-On URL and download the X.509 Certificate.
  12. Sign in to your Zoho account at accounts.zoho.com.
  13. Configure SAML in your Zoho account using the downloaded certificate and copied URLs from Okta.
    1. Paste the Identity Provider Single Sign-On URL in the Sign-in URL field.
    2. Upload the certificate in the X.509 Certificate field.
  14. After configuring SAML in your Zoho account, download the metadata file and open it using your browser or a text editor.
  15. From the metadata file, copy and save the Entity ID and ACS URL.
  16. Return to Okta Admin Console and go to the General tab.
  17. Click Edit next to SAML Settings, then click Next.
  18. Replace the dummy values from step 5 with these copied values:
    1. Paste the ACS URL in the Single sign on URL field.
    2. Paste the Entity ID in the Audience URI field.
  19. Scroll down and click Next, then click Finish.

Assign users to the app in Okta

Your users in Okta can use this newly configured Zoho app to sign in to Zoho. However, before that, you need to assign your users to this app. You can follow the instructions in the following Okta article to assign your users to the app.

Test the SAML configuration

You can test if the configuration is working properly using the following steps. You will need to test these steps as a user in Okta.

SP-initiated flow:
  1. Go to your Zoho sign-in page.
  2. Enter your email address, then click Next. You will be redirected to Azure for authentication.
  3. If you are not signed in to Okta already, enter your Okta credentials to sign in. You will now be redirected back to Zoho and will be signed in.
IdP-initiated flow:
  1. Sign in to Okta end-user dashboard.
  2. Click on the SAML app you have configured for Zoho. You will be redirected to Zoho and will be signed in.

Enable single logout (SLO)

Okta supports only SP-initiated single logout, i.e., when your users sign out from Zoho, they will be automatically signed out from Okta as well. But not the other way around. To learn more about how Okta SLO works, refer to this article.

Steps to enable Single log-out:
  1. Go to SAML Authentication at accounts.zoho.com, then click Edit.
  2. Copy the Sign-in URL, replace the "sso" part of the URL with "slo", then enter it in the Sign-out URL field.
    Example:
    1. Sign-in URL:
      https://zylker.okta.com/app/zylker_app_1/exkewk79Kq4696/sso/saml
    2. Sign-out URL:
      https://zylker.okta.com/app/zylker_app_1/exkewk79Kq4696/slo/saml
  3. Select Do you need a sign-out response?.
  4. Click Configure. You may need to re-enter the X.509 certificate before this.
  5. Click under Sign-out URL. A file named "logoutcertificate.pem" will be downloaded.
  6. Click Downlaod Metadata and open the file "zohometadata.xml" using a browser or text editor. From the metadata file, copy the Single logout URL and the Entity ID.
  7. Go to the Okta admin console, then go to the application you have configured.
  8. Go to the General tab.
  9. Click Edit next to SAML settings.
  10. Click Next to move to Step 2: Configure SAML.
  11. Click Shown Advanced Settings below the General fields.
  12. Select the checkbox Allow application to enable Single Logout.
  13. Enter the copied SLO URL in the Single Logout URL field.
  14. Enter the entity ID in the SP Issuer field.
  15. Click Browse next to Signature Certificate, then browse for and select the previously downloaded "logoutcertificate.pem" file.
  16. Click Upload Certificate.
  17. Click Next, then click Finish.

If you encounter any errors while signing in using SAML, refer to our troubleshooting guide.



    Redefine the way you work
    with Zoho Workplace

      Zoho DataPrep Personalized Demo

      If you'd like a personalized walk-through of our data preparation tool, please request a demo and we'll be happy to show you how to get the best out of Zoho DataPrep.

      Zoho CRM Training

        Create, share, and deliver

        beautiful slides from anywhere.

        Get Started Now


          Get started with Zoho Sign

          in a few quick steps!

          Download Help Guide





                    Secure your business
                    communication with Zoho Mail


                    Mail on the move with
                    Zoho Mail mobile application

                      Stay on top of your schedule
                      at all times


                      Carry your calendar with you
                      Anytime, anywhere




                              Zoho Sign Resources

                                Sign, Paperless!

                                Sign and send business documents on the go!

                                Get Started Now


                                    Zoho SalesIQ Resources



                                        Zoho TeamInbox Resources



                                                Zoho DataPrep Resources



                                                  Zoho DataPrep Demo

                                                  Get a personalized demo or POC

                                                  REGISTER NOW


                                                    Design. Discuss. Deliver.

                                                    Create visually engaging stories with Zoho Show.

                                                    Get Started Now











                                                                          • Related Articles

                                                                          • Accessing Zoho via Google using SAML

                                                                            You can use Google as an identity provider (IdP) to access Zoho applications. Google IdP is a user management platform for Google Apps and services. Required items from Google You will need the following items from Google to configure SAML in Zoho. ...
                                                                          • Accessing Zoho via Auth0 using SAML

                                                                            By configuring SAML based SSO with Azure, you can let your users sign in to Zoho using their Azure credentials. Required items from Auth0 You will need the following items from Auth0 to configure SAML in Zoho. You can follow the configuration steps ...
                                                                          • Accessing Zoho via Azure using SAML

                                                                            By configuring SAML based SSO with Azure, you can let your users sign in to Zoho using their Azure credentials. Required items from Azure You will need the following items from Azure to configure SAML in Zoho. You can follow the configuration steps ...
                                                                          • Configure SAML in Zoho Accounts

                                                                            Note: If you want to configure SAML for Zoho One/ Zoho Directory, you can refer to their respective help documents: Zoho One | Zoho Directory Prerequisites Your Zoho account must be an organization account and not a personal account. You can create ...
                                                                          • Accessing Zoho via OneLogin using SAML

                                                                            OneLogin uses IAM to secure user access to applications and devices and increases end-user productivity through SSO. You must obtain the login URL, logout URL, and the certificate from OneLogin. You can do this in two ways: Either use the SAML Test ...
                                                                          Wherever you are is as good as
                                                                          your workplace

                                                                            Resources

                                                                            Videos

                                                                            Watch comprehensive videos on features and other important topics that will help you master Zoho CRM.



                                                                            eBooks

                                                                            Download free eBooks and access a range of topics to get deeper insight on successfully using Zoho CRM.



                                                                            Webinars

                                                                            Sign up for our webinars and learn the Zoho CRM basics, from customization to sales force automation and more.



                                                                            CRM Tips

                                                                            Make the most of Zoho CRM with these useful tips.



                                                                              Zoho Show Resources