Custom authentication with CyberArk enables SAML-based single sign-on (SSO) from CyberArk to Zoho Directory. Once configured, users in your organisation can access Zoho Directory from CyberArk without signing in to Zoho Directory.
This article outlines the steps to configure custom authentication in Zoho Directory using CyberArk as the Identity Provider (IdP).
Prerequisites
In Zoho Directory - Roles required to perform this action:
- Organization Owner
- Organization Admin
- Security Admin role
- Sign in to the CyberArk admin console.
- Click Web Apps under Apps & Widgets in the left panel.
- Click Add Web Apps, then search for "Zoho".
- Click Add next to the Zoho - SAML option.
- Click Yes in the pop-up window that appears, then click Close. You will be redirected to the Settings page.
- Enter the domain name in the Zoho Domain field, then type "Zoho Directory" in the Name field.
- Click Save.
- Click Trust in the left menu, then check Manual Configuration under Service Provider Configuration.
- Provide the SP Entity ID / SP Issuer / Audience and the Assertion Consumer Service (ACS) URL in their respective fields.
You can find the Issuer and ACS URL in Zoho Directory's Identity Providers page.- Select emailAddress under NameID Format.
- Check Manual Configuration under Identity Provider Configuration.
- Click Signing Certificate, then click Download.
- Copy the Single Sign On URL and Single Logout URL. You'll need to submit these URLs and the downloaded Signing Certificate to add CyberArk as an IdP in Zoho Directory.
- Click Save.
In CuberArk: Deploy the app to users
- Sign in to the CyberArk admin console.
- Click Web Apps under Apps in the left pane.
- Click Zoho Directory, then click Permissions in the left menu.
- Click Add, then search for specific users or groups you want to enforce SSO for.
- Select the users, then click Add.
- Click Save.
In Zoho Directory: Add CyberArk as an IdP
- Sign in to Zoho Directory, then click Admin Panel.
- Click Security in the left menu.
- Select Routing Policies, then go to the Identity Providers tab.
- Click Add identity Provider.
Choose SAML as the SSO Protocol, then enter the name of your IdP in the IdP name field.
- Under Sign-in URL, paste the Single Sign On URL copied from CyberArk.
- Under Sign-out URL, paste the Single Logout URL copied from CyberArk.
Upload the Signing Certificate downloaded from CyberArk under X509 certificate field.
- Click Add. CyberArk will be added as an Identity Provider in Zoho Directory.
In Zoho Directory: Add Routing Policy to enable Custom Authentication
On the same page, go to Routing Policies tab and click Add Policy.
- Enter a name for the policy, then select the members you want to apply the policy to.
- Select if any groups whose users should be excluded from the policy, even if they are part of the selected groups.
Click Next.
- Under Authentication Modes, enable the Identity providers toggle, then select the IdP you added from the list.
Click Next.
- Set Session Settings if required, then click Add. A routing policy will be created and members of this policy will use this IdP to sign in.