Custom Authentication - OneLogin | Admin Guide - Zoho Directory

Custom authentication with OneLogin

Prerequisites

Roles required to perform this action :

  • Organization Owner

  • Organization Admin

Custom authentication with OneLogin:

Custom authentication with OneLogin enables SAML-based single sign-on (SSO) from OneLogin to Zoho. With SSO, you and your employees can sign in to OneLogin and access Zoho directly, without having to sign in to Zoho.

To set up custom authentication with OneLogin:
  1. Sign in to OneLogin's admin console.
  2. Click Applications, then click Add App.
  3. Search for 'SAML Test Connector'.
  4. Choose SAML Test Connector (IdP w/ attr w/ sign response).
  5. Enter "Zoho Directory" under display name. Upload logos if needed.
  6. Click Save.
  7. Go to the SSO tab, then copy the SAML 2.0 Endpoint (HTTP) and the SLO Endpoint (HTTP). Under X.509 Certificate, click View details, then download the X.509 PEM file.
  8. Go to the Configuration tab then enter the following details:
    1. RelayState: Enter "https://directory.zoho.com".
    2. Audience: Enter "https://accounts.zoho.com".
    3. Recipient: Enter the ACS URL found in Zoho Directory's Custom Authentication page.
    4. ACS (Consumer) URL Validator: Enter the ACS URL found in Zoho Directory's Custom Authentication page.
    5. ACS (Consumer) URL: Enter the ACS URL found in Zoho Directory's Custom Authentication page.
    6. Single Logout URL: Enter "https://accounts.zoho.com/logout/samlsp/<ZOID>".
    7. Note: <ZOID> is the last part of your ACS URL.
      ZOID and ACS URL.
  9. Click Save.
  10. Use the details from Step 7 to set up SAML in Zoho Directory.
    1. Enter SAML 2.0 Endpoint (HTTP) under Sign-in URL.
    2. Enter SLO Endpoint (HTTP) under Sign-out URL.
    3. Upload the X.509 PEM file under Verification Certificate.