Accessing Zoho via JumpCloud using SAML
By configuring
SAML-based SSO between Zoho and JumpCloud, you can let your users sign in to Zoho using their JumpCloud credentials.
Required items from JumpCloud
You will need the following items from JumpCloud to configure SAML in Zoho. You can follow the configuration steps to get these from JumpCloud.
- IDP URL
- IDP Certificate
- Sign in to accounts.zoho.com.
- In the left menu, under Organization, click SAML Authentication.
- Click Download Metadata. A file named "zohometadata.xml" will be downloaded.
- Sign in to the JumpCloud admin console.
- In the left menu, under USER AUTHENTICATION, click SSO.
- Click the plus icon, then click Custom SAML App.
- Enter a name for this app under Display Label.
- Go to the SSO tab.
- Click Upload Metadata.
- Browse and upload the previously downloaded file "zohometadata.xml". The required fields will be populated automatically.
- In the IdP Entity ID field, enter a unique string of characters. (Even though Zoho doesn't require the IdP's entity ID, JumpCloud requires you to enter some value)
- In the IDP URL field, enter a unique string for the last part. This will be used when configuring SAML in Zoho. (Note: This cannot be edited later)

- (optional) Enter the required relay state URL in the Default RelayState field.
- (optional) Configure the required attributes for just-in-time provisioning under the Attributes section. You can link the following Zoho attributes with the corresponding attributes of JumpCloud: First Name, Last Name, Display Name.
- Click activate, then click continue to confirm.
- Open the configured app in JumpCloud.
- Go to the SSO tab, then copy the IDP URL.
- In the left side, click IDP Certificate Valid, then click Download certificate. A file named "certificate.pem" will be downloaded.
- Return to SAML Authentication at accounts.zoho.com.
- Configure SAML in your Zoho account using the downloaded certificate and the copied IDP URL from JumpCloud.
- Paste the IDP URL in the Sign-in URL field.
- Upload the IDP certificate in the X.509 Certificate field. Make sure the certificate is in one of these formats: based-64 coded .cer, .crt, .cert, or .pem file.
- Click Configure.
Assign users to the app in JumpCloud
Your users in JumpCloud can use this newly configured Zoho app to sign in to Zoho. However, you first need to assign your users to this app. You can follow the instructions in the following JumpCloud article to do so.
- Authorize Users to an SSO Application
Test the SAML configuration
You can test if the configuration is working properly using the following steps.
SP-initiated flow:
- Go to your Zoho sign-in page.
- Enter your email address, then click Next. (If you sign in as Zoho admin, click Sign in another way, then select the SAML option) You will be redirected to JumpCloud for authentication.
- If you are not already signed in to JumpCloud, enter your JumpCloud credentials to sign in. You will now be redirected back to Zoho and will be signed in.
IdP-initiated flow:
- Go to the JumpCloud user console.
- In the Applications tab, click on the app you have configured for Zoho. You will be redirected to Zoho and will be signed in.